Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

kvcache-ai/ktransformers

https://github.com/kvcache-ai/ktransformers · scanned 2026-07-23 19:43 UTC (4 days, 21 hours ago)

626 raw signals (0 security + 626 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 4 days, 21 hours ago · v4 · 606 actionable findings from 1 signal source. 20 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: source: scanner × excluding tests × Reset all
Corpus Intelligence Cross-corpus context (cohort percentile, top patterns, fix plan) is shown only on repositories you own. Sign up and connect your repo to view it.
Scan summary Repository scanned at 65.6/100 with 100.0% coverage. It contains 6625 nodes across 30 cross-layer flows, written primarily in mixed languages. Engine surfaced 626 findings — concentrated in security (398), quality (108), dependencies (70). Risk profile is high: 18 critical, 143 high, 280 medium. Recommended next step: open the security layer findings first — that's where the highest-impact wins live.

Showing 579 of 606 actionable findings. 626 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

critical System graph security Trivy conf 1.00 CVE-2025-6545: pbkdf2 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
pbkdf2: pbkdf2 silently returns predictable key material Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2. Package: pbkdf2…
VulnCve 2025 6545
critical System graph security Trivy conf 1.00 CVE-2025-6545: pbkdf2 3.1.2 — archive/ktransformers/website/package-lock.json
pbkdf2: pbkdf2 silently returns predictable key material Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2. Package: pbkdf2…
VulnCve 2025 6545
critical System graph security Trivy conf 1.00 CVE-2025-6547: pbkdf2 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
pbkdf2: pbkdf2 silently returns static keys Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2. Package: pbkdf2 Installed: 3.1.2 Fixed in: 3.1.3 Severity: CRITICAL Fix: Upgrade pbkdf2 to 3.1.3
VulnCve 2025 6547
critical System graph security Trivy conf 1.00 CVE-2025-6547: pbkdf2 3.1.2 — archive/ktransformers/website/package-lock.json
pbkdf2: pbkdf2 silently returns static keys Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2. Package: pbkdf2 Installed: 3.1.2 Fixed in: 3.1.3 Severity: CRITICAL Fix: Upgrade pbkdf2 to 3.1.3
VulnCve 2025 6547
critical System graph security Trivy conf 1.00 CVE-2025-7783: form-data 4.0.0 — archive/kt-sft/ktransformers/website/package-lock.json
form-data: Unsafe random function in form-data Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3. Package:…
VulnCve 2025 7783
critical System graph security Trivy conf 1.00 CVE-2025-7783: form-data 4.0.0 — archive/ktransformers/website/package-lock.json
form-data: Unsafe random function in form-data Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3. Package:…
VulnCve 2025 7783
critical System graph security Trivy conf 1.00 CVE-2025-9287: cipher-base 1.0.4 — archive/kt-sft/ktransformers/website/package-lock.json
cipher-base: Cipher-base hash manipulation Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4. Package: cipher-base Installed: 1.0.4 Fixed in: 1.0.5 Severity: CRITICAL Fix: Upgrade cipher-base to 1.0.5
VulnCve 2025 9287
critical System graph security Trivy conf 1.00 CVE-2025-9287: cipher-base 1.0.4 — archive/ktransformers/website/package-lock.json
cipher-base: Cipher-base hash manipulation Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4. Package: cipher-base Installed: 1.0.4 Fixed in: 1.0.5 Severity: CRITICAL Fix: Upgrade cipher-base to 1.0.5
VulnCve 2025 9287
critical System graph security Trivy conf 1.00 CVE-2025-9288: sha.js 2.4.11 — archive/kt-sft/ktransformers/website/package-lock.json
sha.js: Missing type checks leading to hash rewind and passing on crafted data Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11. Package: sha.js Installed: 2.4.11 Fixed in: 2.4.12 Severity: CRITICAL Fix: Upgrade sha.js to 2…
VulnCve 2025 9288
critical System graph security Trivy conf 1.00 CVE-2025-9288: sha.js 2.4.11 — archive/ktransformers/website/package-lock.json
sha.js: Missing type checks leading to hash rewind and passing on crafted data Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11. Package: sha.js Installed: 2.4.11 Fixed in: 2.4.12 Severity: CRITICAL Fix: Upgrade sha.js to 2…
VulnCve 2025 9288
critical System graph security Trivy conf 1.00 CVE-2026-53486: decompress 4.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a direc…
VulnCve 2026 53486
critical System graph security Trivy conf 1.00 CVE-2026-53486: decompress 4.2.1 — archive/ktransformers/website/package-lock.json
decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a direc…
VulnCve 2026 53486
critical System graph security Trivy conf 1.00 CVE-2026-59873: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
tar: node-tar: Denial of Service via crafted gzip bomb node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, a…
VulnCve 2026 59873
critical System graph security Trivy conf 1.00 CVE-2026-59873: tar 6.2.1 — archive/ktransformers/website/package-lock.json
tar: node-tar: Denial of Service via crafted gzip bomb node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, a…
VulnCve 2026 59873
critical System graph security Trivy conf 1.00 CVE-2026-9277: shell-quote 1.8.1 — archive/kt-sft/ktransformers/website/package-lock.json
shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`…
VulnCve 2026 9277
critical System graph security Trivy conf 1.00 CVE-2026-9277: shell-quote 1.8.1 — archive/ktransformers/website/package-lock.json
shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`…
VulnCve 2026 9277
critical System graph security Trivy conf 1.00 GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 — archive/kt-sft/ktransformers/website/package-lock.json
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string) ### Summary Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input Note that `elliptic` by design accepts…
VulnGhsa vjh7 7g9h fjfh
critical System graph security Trivy conf 1.00 GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 — archive/ktransformers/website/package-lock.json
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string) ### Summary Private key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input Note that `elliptic` by design accepts…
VulnGhsa vjh7 7g9h fjfh
high System graph security Trivy conf 1.00 CVE-2022-25881: http-cache-semantics 3.8.1 — archive/kt-sft/ktransformers/website/package-lock.json
http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using t…
VulnCve 2022 25881
high System graph security Trivy conf 1.00 CVE-2022-25881: http-cache-semantics 3.8.1 — archive/ktransformers/website/package-lock.json
http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using t…
VulnCve 2022 25881
high System graph security Trivy conf 1.00 CVE-2022-25900: git-clone 0.1.0 — archive/kt-sft/ktransformers/website/package-lock.json
Command injection in git-clone All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git. Package: git-clone Installed: 0.1.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2022 25900
high System graph security Trivy conf 1.00 CVE-2022-25900: git-clone 0.1.0 — archive/ktransformers/website/package-lock.json
Command injection in git-clone All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git. Package: git-clone Installed: 0.1.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2022 25900
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 6.0.5 — archive/kt-sft/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 6.0.5 — archive/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 7.0.3 — archive/kt-sft/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 7.0.3 — archive/ktransformers/website/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-37890: ws 7.5.9 — archive/kt-sft/ktransformers/website/package-lock.json
nodejs-ws: denial of service when handling a request with many HTTP headers ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e…
VulnCve 2024 37890
high System graph security Trivy conf 1.00 CVE-2024-37890: ws 7.5.9 — archive/ktransformers/website/package-lock.json
nodejs-ws: denial of service when handling a request with many HTTP headers ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in [email protected] (e…
VulnCve 2024 37890
high System graph security Trivy conf 1.00 CVE-2024-39338: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: axios: Server-Side Request Forgery axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. Package: axios Installed: 1.7.0 Fixed in: 1.7.4 Severity: HIGH Fix: Upgrade axios to 1.7.4
VulnCve 2024 39338
high System graph security Trivy conf 1.00 CVE-2024-39338: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: axios: Server-Side Request Forgery axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. Package: axios Installed: 1.7.0 Fixed in: 1.7.4 Severity: HIGH Fix: Upgrade axios to 1.7.4
VulnCve 2024 39338
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 2.3.2 — archive/kt-sft/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 2.3.2 — archive/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 3.0.2 — archive/kt-sft/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4068: braces 3.0.2 — archive/ktransformers/website/package-lock.json
braces: fails to limit the number of characters it can handle The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will…
VulnCve 2024 4068
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 2.6.347 — archive/kt-sft/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 2.6.347 — archive/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 3.5.141 — archive/kt-sft/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-4367: pdfjs-dist 3.5.141 — archive/ktransformers/website/package-lock.json
Mozilla: Arbitrary JavaScript execution in PDF.js A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Package: pdfjs-dist Installed…
VulnCve 2024 4367
high System graph security Trivy conf 1.00 CVE-2024-45296: path-to-regexp 0.1.7 — archive/kt-sft/ktransformers/website/package-lock.json
path-to-regexp: Backtracking regular expressions cause ReDoS path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching run…
VulnCve 2024 45296
high System graph security Trivy conf 1.00 CVE-2024-45296: path-to-regexp 0.1.7 — archive/ktransformers/website/package-lock.json
path-to-regexp: Backtracking regular expressions cause ReDoS path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching run…
VulnCve 2024 45296
high System graph security Trivy conf 1.00 CVE-2024-45590: body-parser 1.20.2 — archive/kt-sft/ktransformers/website/package-lock.json
body-parser: Denial of Service Vulnerability in body-parser body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of request…
VulnCve 2024 45590
high System graph security Trivy conf 1.00 CVE-2024-45590: body-parser 1.20.2 — archive/ktransformers/website/package-lock.json
body-parser: Denial of Service Vulnerability in body-parser body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of request…
VulnCve 2024 45590
high System graph security Trivy conf 1.00 CVE-2024-52011: launch-editor 2.6.1 — archive/kt-sft/ktransformers/website/package-lock.json
launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, …
VulnCve 2024 52011
high System graph security Trivy conf 1.00 CVE-2024-52011: launch-editor 2.6.1 — archive/ktransformers/website/package-lock.json
launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, …
VulnCve 2024 52011
high System graph security Trivy conf 1.00 CVE-2024-52798: path-to-regexp 0.1.7 — archive/kt-sft/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to bac…
VulnCve 2024 52798
high System graph security Trivy conf 1.00 CVE-2024-52798: path-to-regexp 0.1.7 — archive/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to bac…
VulnCve 2024 52798
high System graph security Trivy conf 1.00 CVE-2025-25975: parse-git-config 3.0.0 — archive/kt-sft/ktransformers/website/package-lock.json
parse-git-config: Prototype Pollution Vulneralbility in parse-git-config An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function Package: parse-git-config Installed: 3.0.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2025 25975
high System graph security Trivy conf 1.00 CVE-2025-25975: parse-git-config 3.0.0 — archive/ktransformers/website/package-lock.json
parse-git-config: Prototype Pollution Vulneralbility in parse-git-config An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function Package: parse-git-config Installed: 3.0.0 Fixed in: — Severity: HIGH Fix: No fix version published yet
VulnCve 2025 25975
high System graph security Trivy conf 1.00 CVE-2025-27152: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specifie…
VulnCve 2025 27152
high System graph security Trivy conf 1.00 CVE-2025-27152: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specifie…
VulnCve 2025 27152
high System graph security Trivy conf 1.00 CVE-2025-27597: vue-i18n 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
Vue I18n Allows Prototype Pollution in `handleFlatJson` Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.protot…
VulnCve 2025 27597
high System graph security Trivy conf 1.00 CVE-2025-27597: vue-i18n 9.13.1 — archive/ktransformers/website/package-lock.json
Vue I18n Allows Prototype Pollution in `handleFlatJson` Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.protot…
VulnCve 2025 27597
high System graph security Trivy conf 1.00 CVE-2025-58754: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios DoS via lack of data size check Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http …
VulnCve 2025 58754
high System graph security Trivy conf 1.00 CVE-2025-58754: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios DoS via lack of data size check Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http …
VulnCve 2025 58754
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.0 — archive/kt-sft/ktransformers/website/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.0 — archive/ktransformers/website/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 1.1.11 — archive/kt-sft/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 1.1.11 — archive/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 2.0.1 — archive/kt-sft/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 2.0.1 — archive/ktransformers/website/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13311: shell-quote 1.8.1 — archive/kt-sft/ktransformers/website/package-lock.json
shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result …
VulnCve 2026 13311
high System graph security Trivy conf 1.00 CVE-2026-13311: shell-quote 1.8.1 — archive/ktransformers/website/package-lock.json
shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result …
VulnCve 2026 13311
high System graph security Trivy conf 1.00 CVE-2026-23745: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure be…
VulnCve 2026 23745
high System graph security Trivy conf 1.00 CVE-2026-23745: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure be…
VulnCve 2026 23745
high System graph security Trivy conf 1.00 CVE-2026-23950: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On c…
VulnCve 2026 23950
high System graph security Trivy conf 1.00 CVE-2026-23950: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On c…
VulnCve 2026 23950
high System graph security Trivy conf 1.00 CVE-2026-24842: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink crea…
VulnCve 2026 24842
high System graph security Trivy conf 1.00 CVE-2026-24842: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink crea…
VulnCve 2026 24842
high System graph security Trivy conf 1.00 CVE-2026-25639: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ a…
VulnCve 2026 25639
high System graph security Trivy conf 1.00 CVE-2026-25639: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ a…
VulnCve 2026 25639
high System graph security Trivy conf 1.00 CVE-2026-26960: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outs…
VulnCve 2026 26960
high System graph security Trivy conf 1.00 CVE-2026-26960: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outs…
VulnCve 2026 26960
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 3.1.2 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 5.1.6 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 5.1.6 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 3.1.2 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 5.1.6 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 5.1.6 — archive/ktransformers/website/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 3.1.2 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 3.1.2 — archive/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 5.1.6 — archive/kt-sft/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 5.1.6 — archive/ktransformers/website/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-29786: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: hardlink path traversal via drive-relative linkpath node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables …
VulnCve 2026 29786
high System graph security Trivy conf 1.00 CVE-2026-29786: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: hardlink path traversal via drive-relative linkpath node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables …
VulnCve 2026 29786
high System graph security Trivy conf 1.00 CVE-2026-31802: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
tar: tar: File overwrite via drive-relative symlink traversal node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, …
VulnCve 2026 31802
high System graph security Trivy conf 1.00 CVE-2026-31802: tar 6.2.1 — archive/ktransformers/website/package-lock.json
tar: tar: File overwrite via drive-relative symlink traversal node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, …
VulnCve 2026 31802
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 2.3.1 — archive/kt-sft/ktransformers/website/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 2.3.1 — archive/ktransformers/website/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-42033: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: HTTP Transport Hijacking via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) s…
VulnCve 2026 42033
high System graph security Trivy conf 1.00 CVE-2026-42033: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: HTTP Transport Hijacking via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) s…
VulnCve 2026 42033
high System graph security Trivy conf 1.00 CVE-2026-42035: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Arbitrary HTTP header injection via prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP …
VulnCve 2026 42035
high System graph security Trivy conf 1.00 CVE-2026-42035: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Arbitrary HTTP header injection via prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP …
VulnCve 2026 42035
high System graph security Trivy conf 1.00 CVE-2026-42043: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: NO_PROXY bypass via crafted URL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the …
VulnCve 2026 42043
high System graph security Trivy conf 1.00 CVE-2026-42043: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: NO_PROXY bypass via crafted URL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the …
VulnCve 2026 42043
high System graph security Trivy conf 1.00 CVE-2026-42264: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Prototype pollution allows information disclosure and request manipulation Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the…
VulnCve 2026 42264
high System graph security Trivy conf 1.00 CVE-2026-42264: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Prototype pollution allows information disclosure and request manipulation Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the…
VulnCve 2026 42264
high System graph security Trivy conf 1.00 CVE-2026-44486: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via HTTP redirects Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent throug…
VulnCve 2026 44486
high System graph security Trivy conf 1.00 CVE-2026-44486: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via HTTP redirects Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent throug…
VulnCve 2026 44486
high System graph security Trivy conf 1.00 CVE-2026-44487: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via redirect flows Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct re…
VulnCve 2026 44487
high System graph security Trivy conf 1.00 CVE-2026-44487: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure of proxy credentials via redirect flows Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct re…
VulnCve 2026 44487
high System graph security Trivy conf 1.00 CVE-2026-44488: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Denial of Service due to unenforced request and response size limits Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Appli…
VulnCve 2026 44488
high System graph security Trivy conf 1.00 CVE-2026-44488: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Denial of Service due to unenforced request and response size limits Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Appli…
VulnCve 2026 44488
high System graph security Trivy conf 1.00 CVE-2026-44494: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the applicatio…
VulnCve 2026 44494
high System graph security Trivy conf 1.00 CVE-2026-44494: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the applicatio…
VulnCve 2026 44494
high System graph security Trivy conf 1.00 CVE-2026-44495: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure due to prototype pollution vulnerability Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav…
VulnCve 2026 44495
high System graph security Trivy conf 1.00 CVE-2026-44495: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure due to prototype pollution vulnerability Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav…
VulnCve 2026 44495
high System graph security Trivy conf 1.00 CVE-2026-44496: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
VulnCve 2026 44496
high System graph security Trivy conf 1.00 CVE-2026-44496: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
VulnCve 2026 44496
high System graph security Trivy conf 1.00 CVE-2026-44705: tmp 0.0.33 — archive/kt-sft/ktransformers/website/package-lock.json
tmp is a temporary file and directory creator for node.js. Prior to 0. ... tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the…
VulnCve 2026 44705
high System graph security Trivy conf 1.00 CVE-2026-44705: tmp 0.0.33 — archive/ktransformers/website/package-lock.json
tmp is a temporary file and directory creator for node.js. Prior to 0. ... tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the…
VulnCve 2026 44705
high System graph security Trivy conf 1.00 CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 — archive/kt-sft/ktransformers/website/package-lock.json
Babel is a compiler for writing next generation JavaScript. From 7.12. ... Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code t…
VulnCve 2026 44728
high System graph security Trivy conf 1.00 CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 — archive/ktransformers/website/package-lock.json
Babel is a compiler for writing next generation JavaScript. From 7.12. ... Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code t…
VulnCve 2026 44728
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash-es 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash-es 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4867: path-to-regexp 0.1.7 — archive/kt-sft/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c o…
VulnCve 2026 4867
high System graph security Trivy conf 1.00 CVE-2026-4867: path-to-regexp 0.1.7 — archive/ktransformers/website/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c o…
VulnCve 2026 4867
high System graph security Trivy conf 1.00 CVE-2026-48779: ws 7.5.9 — archive/kt-sft/ktransformers/website/package-lock.json
ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memor…
VulnCve 2026 48779
high System graph security Trivy conf 1.00 CVE-2026-48779: ws 7.5.9 — archive/ktransformers/website/package-lock.json
ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memor…
VulnCve 2026 48779
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 3.14.1 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 3.14.1 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 4.1.0 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 4.1.0 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59874: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
tar: Node-tar: Denial of Service via malformed tar archive header node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeated…
VulnCve 2026 59874
high System graph security Trivy conf 1.00 CVE-2026-59874: tar 6.2.1 — archive/ktransformers/website/package-lock.json
tar: Node-tar: Denial of Service via malformed tar archive header node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeated…
VulnCve 2026 59874
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/.devcontainer/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/.devcontainer/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/Dockerfile.xpu
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/Dockerfile.xpu
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/kt-sft/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/kt-sft/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — archive/kt-sft/Dockerfile.xpu
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: archive/kt-sft/Dockerfile.xpu
Misconfig
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — docker/Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: docker/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0017: 'RUN <package-manager> update' instruction alone — archive/Dockerfile
'RUN <package-manager> update' instruction alone The instruction 'RUN <package-manager> update' should always be followed by '<package-manager> install' in the same RUN statement. Rule: DS-0017 Severity: HIGH Target: archive/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0017: 'RUN <package-manager> update' instruction alone — archive/kt-sft/Dockerfile
'RUN <package-manager> update' instruction alone The instruction 'RUN <package-manager> update' should always be followed by '<package-manager> install' in the same RUN statement. Rule: DS-0017 Severity: HIGH Target: archive/kt-sft/Dockerfile
Misconfig
high System graph security Trivy conf 1.00 DS-0029: 'apt-get' missing '--no-install-recommends' — archive/Dockerfile.xpu
'apt-get' missing '--no-install-recommends' '--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y wget curl bash git vim ca-certificates binutils cmake g++ && rm -rf /var/lib/apt/lists/*' Rule: DS-0029 Severity: HIGH Target: archiv…
Misconfig
high System graph security Trivy conf 1.00 DS-0029: 'apt-get' missing '--no-install-recommends' — archive/kt-sft/Dockerfile.xpu
'apt-get' missing '--no-install-recommends' '--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y wget curl bash git vim ca-certificates binutils cmake g++ && rm -rf /var/lib/apt/lists/*' Rule: DS-0029 Severity: HIGH Target: archiv…
Misconfig
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 — archive/kt-sft/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 — archive/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 — archive/kt-sft/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security Trivy conf 1.00 GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 — archive/ktransformers/website/package-lock.json
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` i…
VulnGhsa 5c6j r48x rmvq
high System graph security security conf 1.00 Insecure pattern 'exec_used' in .github/workflows/release-pypi.yml:53
Found a known-risky pattern (exec_used). Review and replace if possible.
.github/workflows/release-pypi.yml:53 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in .github/workflows/release-sglang-kt.yml:48
Found a known-risky pattern (exec_used). Review and replace if possible.
.github/workflows/release-sglang-kt.yml:48 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in .github/workflows/sync-sglang-submodule.yml:49
Found a known-risky pattern (exec_used). Review and replace if possible.
.github/workflows/sync-sglang-submodule.yml:49 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in docker/Dockerfile:270
Found a known-risky pattern (exec_used). Review and replace if possible.
docker/Dockerfile:270 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in install.sh:73
Found a known-risky pattern (exec_used). Review and replace if possible.
install.sh:73 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in kt-kernel/python/__init__.py:80
Found a known-risky pattern (exec_used). Review and replace if possible.
kt-kernel/python/__init__.py:80 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in kt-kernel/python/cli/__init__.py:18
Found a known-risky pattern (exec_used). Review and replace if possible.
kt-kernel/python/cli/__init__.py:18 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in kt-kernel/setup.py:753
Found a known-risky pattern (exec_used). Review and replace if possible.
kt-kernel/setup.py:753 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in ktransformers.py:17
Found a known-risky pattern (exec_used). Review and replace if possible.
ktransformers.py:17 Exec used
high System graph security security conf 1.00 Insecure pattern 'exec_used' in setup.py:12
Found a known-risky pattern (exec_used). Review and replace if possible.
setup.py:12 Exec used
high System graph security security conf 1.00 Insecure pattern 'python_os_system' in archive/ktransformers/local_chat.py:161
Found a known-risky pattern (python_os_system). Review and replace if possible.
archive/ktransformers/local_chat.py:161 Python os system
high System graph security security conf 1.00 Insecure pattern 'subprocess_shell_true' in kt-kernel/bench/compare_moe_performance.py:825
Found a known-risky pattern (subprocess_shell_true). Review and replace if possible.
kt-kernel/bench/compare_moe_performance.py:825 Subprocess shell true
high System graph security Semgrep conf 0.70 subprocess shell true — kt-kernel/bench/compare_moe_performance.py:825
Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. Rule: py…
kt-kernel/bench/compare_moe_performance.py:825 SecurityPython
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-35jp-ww65-95wh
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-35jp-ww65-95wh (aka CVE-2026-44494). axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` Aliases: CVE-2026-44494 Advisory: …
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 35jp ww65 95wh
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-3g43-6gmg-66jw
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-3g43-6gmg-66jw (aka CVE-2026-44495). axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge Aliases: CVE-2026-4…
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 3g43 6gmg 66jw
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-43fc-jf86-j433
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-43fc-jf86-j433 (aka CVE-2026-25639). Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig Aliases: CVE-2026-25639 Advisory: https://osv.dev/vu…
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 43fc jf86 j433
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.0: GHSA-4hjh-wcwx-xvwj
OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-4hjh-wcwx-xvwj (aka CVE-2025-58754). Axios is vulnerable to DoS attack through lack of data size check Aliases: CVE-2025-58754 Advisory: https://osv.dev/vulnerabil…
archive/kt-sft/ktransformers/website/package.json ScaOsvGhsa 4hjh wcwx xvwj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 3.14.1: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `3.14.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869). Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. js-yaml: YAM…
archive/kt-sft/ktransformers/website/package-lock.json ScaOsvGhsa 52cp r559 cp3m
medium System graph security Semgrep conf 0.55 avoid pickle — archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py:322
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py:322 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/utils.py:123
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/utils.py:123 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/kt-sft/ktransformers/server/balance_serve/sched_rpc.py:51
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/kt-sft/ktransformers/server/balance_serve/sched_rpc.py:51 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/ktransformers/server/backend/interfaces/balance_serve.py:489
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/ktransformers/server/backend/interfaces/balance_serve.py:489 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/ktransformers/server/balance_serve/inference/distributed/utils.py:123
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/ktransformers/server/balance_serve/inference/distributed/utils.py:123 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 avoid pickle — archive/ktransformers/server/balance_serve/sched_rpc.py:70
Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format. Rule: python.lang.security.deserial…
archive/ktransformers/server/balance_serve/sched_rpc.py:70 SecurityPythonNon production context
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph security Trivy conf 1.00 CVE-2022-33987: got 8.3.2 — archive/kt-sft/ktransformers/website/package-lock.json
nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket. Package: got Installed: 8.3.2 Fixed in: 12.1.0, 11.8.5 Severity: MEDIUM Fix: Upgrade got to 12.1.0, 11.8.5
VulnCve 2022 33987
medium System graph security Trivy conf 1.00 CVE-2022-33987: got 8.3.2 — archive/ktransformers/website/package-lock.json
nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket. Package: got Installed: 8.3.2 Fixed in: 12.1.0, 11.8.5 Severity: MEDIUM Fix: Upgrade got to 12.1.0, 11.8.5
VulnCve 2022 33987
medium System graph security Trivy conf 1.00 CVE-2024-4067: micromatch 3.1.10 — archive/kt-sft/ktransformers/website/package-lock.json
micromatch: vulnerable to Regular Expression Denial of Service The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passin…
VulnCve 2024 4067
medium System graph security Trivy conf 1.00 CVE-2024-4067: micromatch 3.1.10 — archive/ktransformers/website/package-lock.json
micromatch: vulnerable to Regular Expression Denial of Service The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passin…
VulnCve 2024 4067
medium System graph security Trivy conf 1.00 CVE-2024-4067: micromatch 4.0.5 — archive/kt-sft/ktransformers/website/package-lock.json
micromatch: vulnerable to Regular Expression Denial of Service The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passin…
VulnCve 2024 4067
medium System graph security Trivy conf 1.00 CVE-2024-4067: micromatch 4.0.5 — archive/ktransformers/website/package-lock.json
micromatch: vulnerable to Regular Expression Denial of Service The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passin…
VulnCve 2024 4067
medium System graph security Trivy conf 1.00 CVE-2024-43788: webpack 5.91.0 — archive/kt-sft/ktransformers/website/package-lock.json
webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have disc…
VulnCve 2024 43788
medium System graph security Trivy conf 1.00 CVE-2024-43788: webpack 5.91.0 — archive/ktransformers/website/package-lock.json
webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have disc…
VulnCve 2024 43788
medium System graph security Trivy conf 1.00 CVE-2024-52809: @intlify/core-base 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
vue-i18n has cross-site scripting vulnerability with prototype pollution vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibili…
VulnCve 2024 52809
medium System graph security Trivy conf 1.00 CVE-2024-52809: @intlify/core-base 9.13.1 — archive/ktransformers/website/package-lock.json
vue-i18n has cross-site scripting vulnerability with prototype pollution vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibili…
VulnCve 2024 52809
medium System graph security Trivy conf 1.00 CVE-2024-52809: vue-i18n 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
vue-i18n has cross-site scripting vulnerability with prototype pollution vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibili…
VulnCve 2024 52809
medium System graph security Trivy conf 1.00 CVE-2024-52809: vue-i18n 9.13.1 — archive/ktransformers/website/package-lock.json
vue-i18n has cross-site scripting vulnerability with prototype pollution vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibili…
VulnCve 2024 52809
medium System graph security Trivy conf 1.00 CVE-2024-52810: @intlify/shared 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
@intlify/shared Prototype Pollution vulnerability @intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype sett…
VulnCve 2024 52810
medium System graph security Trivy conf 1.00 CVE-2024-52810: @intlify/shared 9.13.1 — archive/ktransformers/website/package-lock.json
@intlify/shared Prototype Pollution vulnerability @intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype sett…
VulnCve 2024 52810
medium System graph security Trivy conf 1.00 CVE-2024-52810: vue-i18n 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
@intlify/shared Prototype Pollution vulnerability @intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype sett…
VulnCve 2024 52810
medium System graph security Trivy conf 1.00 CVE-2024-52810: vue-i18n 9.13.1 — archive/ktransformers/website/package-lock.json
@intlify/shared Prototype Pollution vulnerability @intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype sett…
VulnCve 2024 52810
medium System graph security Trivy conf 1.00 CVE-2024-53382: prismjs 1.29.0 — archive/kt-sft/ktransformers/website/package-lock.json
prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shado…
VulnCve 2024 53382
medium System graph security Trivy conf 1.00 CVE-2024-53382: prismjs 1.29.0 — archive/ktransformers/website/package-lock.json
prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shado…
VulnCve 2024 53382
medium System graph security Trivy conf 1.00 CVE-2024-55565: nanoid 2.1.11 — archive/kt-sft/ktransformers/website/package-lock.json
nanoid: nanoid mishandles non-integer values nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. Package: nanoid Installed: 2.1.11 Fixed in: 5.0.9, 3.3.8 Severity: MEDIUM Fix: Upgrade nanoid to 5.0.9, 3.3.8
VulnCve 2024 55565
medium System graph security Trivy conf 1.00 CVE-2024-55565: nanoid 2.1.11 — archive/ktransformers/website/package-lock.json
nanoid: nanoid mishandles non-integer values nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. Package: nanoid Installed: 2.1.11 Fixed in: 5.0.9, 3.3.8 Severity: MEDIUM Fix: Upgrade nanoid to 5.0.9, 3.3.8
VulnCve 2024 55565
medium System graph security Trivy conf 1.00 CVE-2024-55565: nanoid 3.3.7 — archive/kt-sft/ktransformers/website/package-lock.json
nanoid: nanoid mishandles non-integer values nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. Package: nanoid Installed: 3.3.7 Fixed in: 5.0.9, 3.3.8 Severity: MEDIUM Fix: Upgrade nanoid to 5.0.9, 3.3.8
VulnCve 2024 55565
medium System graph security Trivy conf 1.00 CVE-2024-55565: nanoid 3.3.7 — archive/ktransformers/website/package-lock.json
nanoid: nanoid mishandles non-integer values nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. Package: nanoid Installed: 3.3.7 Fixed in: 5.0.9, 3.3.8 Severity: MEDIUM Fix: Upgrade nanoid to 5.0.9, 3.3.8
VulnCve 2024 55565
medium System graph security Trivy conf 1.00 CVE-2025-13465: lodash 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: prototype pollution in _.unset and _.omit functions Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion o…
VulnCve 2025 13465
medium System graph security Trivy conf 1.00 CVE-2025-13465: lodash 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: prototype pollution in _.unset and _.omit functions Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion o…
VulnCve 2025 13465
medium System graph security Trivy conf 1.00 CVE-2025-13465: lodash-es 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: prototype pollution in _.unset and _.omit functions Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion o…
VulnCve 2025 13465
medium System graph security Trivy conf 1.00 CVE-2025-13465: lodash-es 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: prototype pollution in _.unset and _.omit functions Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion o…
VulnCve 2025 13465
medium System graph security Trivy conf 1.00 CVE-2025-15284: qs 6.11.0 — archive/kt-sft/ktransformers/website/package-lock.json
qs: qs: Denial of Service via improper input validation in array parsing Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed…
VulnCve 2025 15284
medium System graph security Trivy conf 1.00 CVE-2025-15284: qs 6.11.0 — archive/ktransformers/website/package-lock.json
qs: qs: Denial of Service via improper input validation in array parsing Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed…
VulnCve 2025 15284
medium System graph security Trivy conf 1.00 CVE-2025-15284: qs 6.12.1 — archive/kt-sft/ktransformers/website/package-lock.json
qs: qs: Denial of Service via improper input validation in array parsing Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed…
VulnCve 2025 15284
medium System graph security Trivy conf 1.00 CVE-2025-15284: qs 6.12.1 — archive/ktransformers/website/package-lock.json
qs: qs: Denial of Service via improper input validation in array parsing Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed…
VulnCve 2025 15284
medium System graph security Trivy conf 1.00 CVE-2025-27789: @babel/helpers 7.24.5 — archive/kt-sft/ktransformers/website/package-lock.json
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel w…
VulnCve 2025 27789
medium System graph security Trivy conf 1.00 CVE-2025-27789: @babel/helpers 7.24.5 — archive/ktransformers/website/package-lock.json
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel w…
VulnCve 2025 27789
medium System graph security Trivy conf 1.00 CVE-2025-27789: @babel/runtime 7.24.5 — archive/kt-sft/ktransformers/website/package-lock.json
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel w…
VulnCve 2025 27789
medium System graph security Trivy conf 1.00 CVE-2025-27789: @babel/runtime 7.24.5 — archive/ktransformers/website/package-lock.json
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel w…
VulnCve 2025 27789
medium System graph security Trivy conf 1.00 CVE-2025-53892: @intlify/core-base 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, start…
VulnCve 2025 53892
medium System graph security Trivy conf 1.00 CVE-2025-53892: @intlify/core-base 9.13.1 — archive/ktransformers/website/package-lock.json
vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, start…
VulnCve 2025 53892
medium System graph security Trivy conf 1.00 CVE-2025-53892: vue-i18n 9.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, start…
VulnCve 2025 53892
medium System graph security Trivy conf 1.00 CVE-2025-53892: vue-i18n 9.13.1 — archive/ktransformers/website/package-lock.json
vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, start…
VulnCve 2025 53892
medium System graph security Trivy conf 1.00 CVE-2025-57665: element-plus 2.7.3 — archive/kt-sft/ktransformers/website/package-lock.json
Element Plus Link component (el-link) implements insufficient input validation for the href attribute Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. Th…
VulnCve 2025 57665
medium System graph security Trivy conf 1.00 CVE-2025-57665: element-plus 2.7.3 — archive/ktransformers/website/package-lock.json
Element Plus Link component (el-link) implements insufficient input validation for the href attribute Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. Th…
VulnCve 2025 57665
medium System graph security Trivy conf 1.00 CVE-2025-62718: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback …
VulnCve 2025 62718
medium System graph security Trivy conf 1.00 CVE-2025-62718: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback …
VulnCve 2025 62718
medium System graph security Trivy conf 1.00 CVE-2025-64718: js-yaml 3.14.1 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml prototype pollution in merge js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml …
VulnCve 2025 64718
medium System graph security Trivy conf 1.00 CVE-2025-64718: js-yaml 3.14.1 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml prototype pollution in merge js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml …
VulnCve 2025 64718
medium System graph security Trivy conf 1.00 CVE-2025-64718: js-yaml 4.1.0 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml prototype pollution in merge js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml …
VulnCve 2025 64718
medium System graph security Trivy conf 1.00 CVE-2025-64718: js-yaml 4.1.0 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml prototype pollution in merge js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml …
VulnCve 2025 64718
medium System graph security Trivy conf 1.00 CVE-2025-69873: ajv 6.12.6 — archive/kt-sft/ktransformers/website/package-lock.json
ajv: ReDoS via $data reference ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaS…
VulnCve 2025 69873
medium System graph security Trivy conf 1.00 CVE-2025-69873: ajv 6.12.6 — archive/ktransformers/website/package-lock.json
ajv: ReDoS via $data reference ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaS…
VulnCve 2025 69873
medium System graph security Trivy conf 1.00 CVE-2026-2739: bn.js 4.12.0 — archive/kt-sft/ktransformers/website/package-lock.json
bn.js: bn.js: Denial of Service via calling maskn(0) This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. Package: bn.j…
VulnCve 2026 2739
medium System graph security Trivy conf 1.00 CVE-2026-2739: bn.js 4.12.0 — archive/ktransformers/website/package-lock.json
bn.js: bn.js: Denial of Service via calling maskn(0) This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. Package: bn.j…
VulnCve 2026 2739
medium System graph security Trivy conf 1.00 CVE-2026-2739: bn.js 5.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
bn.js: bn.js: Denial of Service via calling maskn(0) This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. Package: bn.j…
VulnCve 2026 2739
medium System graph security Trivy conf 1.00 CVE-2026-2739: bn.js 5.2.1 — archive/ktransformers/website/package-lock.json
bn.js: bn.js: Denial of Service via calling maskn(0) This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. Package: bn.j…
VulnCve 2026 2739
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash-es 4.17.21 — archive/kt-sft/ktransformers/website/package-lock.json
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash-es 4.17.21 — archive/ktransformers/website/package-lock.json
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-33672: picomatch 2.3.1 — archive/kt-sft/ktransformers/website/package-lock.json
picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Becau…
VulnCve 2026 33672
medium System graph security Trivy conf 1.00 CVE-2026-33672: picomatch 2.3.1 — archive/ktransformers/website/package-lock.json
picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Becau…
VulnCve 2026 33672
medium System graph security Trivy conf 1.00 CVE-2026-33750: brace-expansion 1.1.11 — archive/kt-sft/ktransformers/website/package-lock.json
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) caus…
VulnCve 2026 33750
medium System graph security Trivy conf 1.00 CVE-2026-33750: brace-expansion 1.1.11 — archive/ktransformers/website/package-lock.json
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) caus…
VulnCve 2026 33750
medium System graph security Trivy conf 1.00 CVE-2026-33750: brace-expansion 2.0.1 — archive/kt-sft/ktransformers/website/package-lock.json
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) caus…
VulnCve 2026 33750
medium System graph security Trivy conf 1.00 CVE-2026-33750: brace-expansion 2.0.1 — archive/ktransformers/website/package-lock.json
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) caus…
VulnCve 2026 33750
medium System graph security Trivy conf 1.00 CVE-2026-34043: serialize-javascript 6.0.2 — archive/kt-sft/ktransformers/website/package-lock.json
serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exh…
VulnCve 2026 34043
medium System graph security Trivy conf 1.00 CVE-2026-34043: serialize-javascript 6.0.2 — archive/ktransformers/website/package-lock.json
serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exh…
VulnCve 2026 34043
medium System graph security Trivy conf 1.00 CVE-2026-40175: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Remote Code Execution via Prototype Pollution escalation Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leverag…
VulnCve 2026 40175
medium System graph security Trivy conf 1.00 CVE-2026-40175: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Remote Code Execution via Prototype Pollution escalation Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leverag…
VulnCve 2026 40175
medium System graph security Trivy conf 1.00 CVE-2026-41305: postcss 8.4.38 — archive/kt-sft/ktransformers/website/package-lock.json
postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifyin…
VulnCve 2026 41305
medium System graph security Trivy conf 1.00 CVE-2026-41305: postcss 8.4.38 — archive/ktransformers/website/package-lock.json
postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifyin…
VulnCve 2026 41305
medium System graph security Trivy conf 1.00 CVE-2026-41907: uuid 8.3.2 — archive/kt-sft/ktransformers/website/package-lock.json
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silen…
VulnCve 2026 41907
medium System graph security Trivy conf 1.00 CVE-2026-41907: uuid 8.3.2 — archive/ktransformers/website/package-lock.json
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silen…
VulnCve 2026 41907
medium System graph security Trivy conf 1.00 CVE-2026-41907: uuid 9.0.1 — archive/kt-sft/ktransformers/website/package-lock.json
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silen…
VulnCve 2026 41907
medium System graph security Trivy conf 1.00 CVE-2026-41907: uuid 9.0.1 — archive/ktransformers/website/package-lock.json
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silen…
VulnCve 2026 41907
medium System graph security Trivy conf 1.00 CVE-2026-42034: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Denial of Service via oversized streamed uploads bypassing body limits Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). …
VulnCve 2026 42034
medium System graph security Trivy conf 1.00 CVE-2026-42034: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Denial of Service via oversized streamed uploads bypassing body limits Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). …
VulnCve 2026 42034
medium System graph security Trivy conf 1.00 CVE-2026-42036: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is used Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLe…
VulnCve 2026 42036
medium System graph security Trivy conf 1.00 CVE-2026-42036: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is used Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLe…
VulnCve 2026 42036
medium System graph security Trivy conf 1.00 CVE-2026-42037: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type header Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the…
VulnCve 2026 42037
medium System graph security Trivy conf 1.00 CVE-2026-42037: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type header Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the…
VulnCve 2026 42037
medium System graph security Trivy conf 1.00 CVE-2026-42038: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure due to `no_proxy` bypass Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route t…
VulnCve 2026 42038
medium System graph security Trivy conf 1.00 CVE-2026-42038: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure due to `no_proxy` bypass Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route t…
VulnCve 2026 42038
medium System graph security Trivy conf 1.00 CVE-2026-42039: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value pas…
VulnCve 2026 42039
medium System graph security Trivy conf 1.00 CVE-2026-42039: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value pas…
VulnCve 2026 42039
medium System graph security Trivy conf 1.00 CVE-2026-42041: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to…
VulnCve 2026 42041
medium System graph security Trivy conf 1.00 CVE-2026-42041: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to…
VulnCve 2026 42041
medium System graph security Trivy conf 1.00 CVE-2026-42042: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: XSRF token bypass leading to information disclosure Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXS…
VulnCve 2026 42042
medium System graph security Trivy conf 1.00 CVE-2026-42042: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: XSRF token bypass leading to information disclosure Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXS…
VulnCve 2026 42042
medium System graph security Trivy conf 1.00 CVE-2026-42044: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the ap…
VulnCve 2026 42044
medium System graph security Trivy conf 1.00 CVE-2026-42044: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the ap…
VulnCve 2026 42044
medium System graph security Trivy conf 1.00 CVE-2026-44288: @protobufjs/utf8 1.1.0 — archive/kt-sft/ktransformers/website/package-lock.json
protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decode…
VulnCve 2026 44288
medium System graph security Trivy conf 1.00 CVE-2026-44288: @protobufjs/utf8 1.1.0 — archive/ktransformers/website/package-lock.json
protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decode…
VulnCve 2026 44288
medium System graph security Trivy conf 1.00 CVE-2026-44490: axios 1.7.0 — archive/kt-sft/ktransformers/website/package-lock.json
axios: Axios: Information disclosure and denial of service due to prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency i…
VulnCve 2026 44490
medium System graph security Trivy conf 1.00 CVE-2026-44490: axios 1.7.0 — archive/ktransformers/website/package-lock.json
axios: Axios: Information disclosure and denial of service due to prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency i…
VulnCve 2026 44490
medium System graph security Trivy conf 1.00 CVE-2026-48038: joi 17.13.1 — archive/kt-sft/ktransformers/website/package-lock.json
joi: joi: Denial of Service via uncaught RangeError on deeply nested input through recursive link() schemas joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supp…
VulnCve 2026 48038
medium System graph security Trivy conf 1.00 CVE-2026-48038: joi 17.13.1 — archive/ktransformers/website/package-lock.json
joi: joi: Denial of Service via uncaught RangeError on deeply nested input through recursive link() schemas joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supp…
VulnCve 2026 48038
medium System graph security Trivy conf 1.00 CVE-2026-53550: js-yaml 3.14.1 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence.…
VulnCve 2026 53550
medium System graph security Trivy conf 1.00 CVE-2026-53550: js-yaml 3.14.1 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence.…
VulnCve 2026 53550
medium System graph security Trivy conf 1.00 CVE-2026-53550: js-yaml 4.1.0 — archive/kt-sft/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence.…
VulnCve 2026 53550
medium System graph security Trivy conf 1.00 CVE-2026-53550: js-yaml 4.1.0 — archive/ktransformers/website/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence.…
VulnCve 2026 53550
medium System graph security Trivy conf 1.00 CVE-2026-53632: launch-editor 2.6.1 — archive/kt-sft/ktransformers/website/package-lock.json
launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a U…
VulnCve 2026 53632
medium System graph security Trivy conf 1.00 CVE-2026-53632: launch-editor 2.6.1 — archive/ktransformers/website/package-lock.json
launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a U…
VulnCve 2026 53632
medium System graph security Trivy conf 1.00 CVE-2026-53655: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: node-tar: File smuggling due to inconsistent tar archive parsing node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata heade…
VulnCve 2026 53655
medium System graph security Trivy conf 1.00 CVE-2026-53655: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: node-tar: File smuggling due to inconsistent tar archive parsing node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata heade…
VulnCve 2026 53655
medium System graph security Trivy conf 1.00 CVE-2026-59871: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: node-tar: Denial of Service due to incorrect PAX path handling node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindo…
VulnCve 2026 59871
medium System graph security Trivy conf 1.00 CVE-2026-59871: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: node-tar: Denial of Service due to incorrect PAX path handling node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindo…
VulnCve 2026 59871
medium System graph security Trivy conf 1.00 CVE-2026-59875: tar 6.2.1 — archive/kt-sft/ktransformers/website/package-lock.json
node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.l…
VulnCve 2026 59875
medium System graph security Trivy conf 1.00 CVE-2026-59875: tar 6.2.1 — archive/ktransformers/website/package-lock.json
node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.l…
VulnCve 2026 59875
medium System graph security Trivy conf 1.00 CVE-2026-8723: qs 6.12.1 — archive/kt-sft/ktransformers/website/package-lock.json
### Summary `qs.stringify` throws `TypeError` when called with `arr ... ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's nul…
VulnCve 2026 8723
medium System graph security Trivy conf 1.00 CVE-2026-8723: qs 6.12.1 — archive/ktransformers/website/package-lock.json
### Summary `qs.stringify` throws `TypeError` when called with `arr ... ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's nul…
VulnCve 2026 8723
medium System graph dependencies dependencies conf 0.90 Dependency apexcharts is two or more major versions behind
`apexcharts` is pinned at `3.49.1` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `6.5.0` — 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and …
archive/kt-sft/ktransformers/website/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency marked is two or more major versions behind
`marked` is pinned at `12.0.2` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `18.0.7` — 6 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upg…
archive/kt-sft/ktransformers/website/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency vue-i18n is two or more major versions behind
`vue-i18n` is pinned at `9.13.1` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `11.4.7` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and u…
archive/kt-sft/ktransformers/website/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency webpack-cli is two or more major versions behind
`webpack-cli` is pinned at `5.1.4` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `7.2.1` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and …
archive/kt-sft/ktransformers/website/package.json FreshnessOutdated
medium System graph hardware Security conf 1.00 Dockerfile runs as root: archive/.devcontainer/Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph hardware Security conf 1.00 Dockerfile runs as root: archive/Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph hardware Security conf 1.00 Dockerfile runs as root: archive/kt-sft/Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph hardware Security conf 1.00 Dockerfile runs as root: docker/Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph security Trivy conf 1.00 DS-0013: 'RUN cd ...' to change directory — archive/Dockerfile.xpu
'RUN cd ...' to change directory RUN should not be used to change directory: 'bash -c " source $CONDA_DIR/etc/profile.d/conda.sh && conda activate ktransformers && git clone https://github.com/kvcache-ai/ktransformers.git && cd ktransformers && git submodule update --init && …
Misconfig
medium System graph security Trivy conf 1.00 DS-0013: 'RUN cd ...' to change directory — archive/kt-sft/Dockerfile.xpu
'RUN cd ...' to change directory RUN should not be used to change directory: 'bash -c " source $CONDA_DIR/etc/profile.d/conda.sh && conda activate ktransformers && git clone https://github.com/kvcache-ai/ktransformers.git && cd ktransformers && git submodule update --init && …
Misconfig
medium System graph security Trivy conf 1.00 DS-0013: 'RUN cd ...' to change directory — docker/Dockerfile
'RUN cd ...' to change directory RUN should not be used to change directory: '. /opt/miniconda3/etc/profile.d/conda.sh && conda activate serve && cd /workspace/ktransformers/kt-kernel && CPUINFER_BUILD_ALL_VARIANTS=1 ./install.sh build'. Use 'WORKDIR' statement instead. Rule: DS-0013 Seve…
Misconfig
medium System graph security Semgrep conf 0.55 dynamic urllib use detected — archive/kt-sft/setup.py:300
Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead. R…
archive/kt-sft/setup.py:300 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 dynamic urllib use detected — archive/setup.py:281
Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead. R…
archive/setup.py:281 SecurityPythonNon production context
medium System graph security Semgrep conf 0.55 exec detected — kt-kernel/python/__init__.py:80
Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. Rule: python.lang.security.audit.exec-detected.…
kt-kernel/python/__init__.py:80 SecurityPython
medium System graph security Semgrep conf 0.55 exec detected — kt-kernel/python/cli/__init__.py:18
Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. Rule: python.lang.security.audit.exec-detected.…
kt-kernel/python/cli/__init__.py:18 SecurityPython
medium System graph security Semgrep conf 0.55 exec detected — kt-kernel/setup.py:753
Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. Rule: python.lang.security.audit.exec-detected.…
kt-kernel/setup.py:753 SecurityPython
medium System graph security Semgrep conf 0.55 exec detected — ktransformers.py:17
Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. Rule: python.lang.security.audit.exec-detected.…
ktransformers.py:17 SecurityPython
medium System graph security Semgrep conf 0.55 exec detected — setup.py:12
Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources. Rule: python.lang.security.audit.exec-detected.…
setup.py:12 SecurityPython
medium System graph security auth conf 0.50 FastAPI DELETE `delete_assistant` without auth dependency — archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:62
`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachab…
archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:62 securityAuth fastapi unauth mutationNon production context
medium System graph security auth conf 0.50 FastAPI DELETE `delete_assistant` without auth dependency — archive/ktransformers/server/api/openai/assistants/assistants.py:62
`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachab…
archive/ktransformers/server/api/openai/assistants/assistants.py:62 securityAuth fastapi unauth mutationNon production context
medium System graph security auth conf 0.50 FastAPI DELETE `delete_message` without auth dependency — archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:48
`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachab…
archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:48 securityAuth fastapi unauth mutationNon production context

Showing first 300 of 579. Refine filters or use the findings page for deep search.

For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/5a2dcb17-955a-4003-a052-52b5eb857cff/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/5a2dcb17-955a-4003-a052-52b5eb857cff/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.