{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-57ca406d5f84905e", "name": "Possibly dead Python function: preprocess_function", "shortDescription": {"text": "Possibly dead Python function: preprocess_function"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03df420c6a24fde6", "name": "Possibly dead Python function: save_model", "shortDescription": {"text": "Possibly dead Python function: save_model"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-268b7e6d9ece87fe", "name": "Possibly dead Python function: is_marlin_supported", "shortDescription": {"text": "Possibly dead Python function: is_marlin_supported"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-937a7928ef2c6cf9", "name": "Possibly dead Python function: check_24", "shortDescription": {"text": "Possibly dead Python function: check_24"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b33532ee51957914", "name": "Possibly dead Python function: marlin_24_quantize", "shortDescription": {"text": "Possibly dead Python function: marlin_24_quantize"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f4ded60f49239cc", "name": "Possibly dead Python function: compute_max_diff", "shortDescription": {"text": "Possibly dead Python function: compute_max_diff"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c0fb148e4fc7251", "name": "Possibly dead Python function: sparse_semi_structured_to_dense_cutlass", "shortDescription": {"text": "Possibly dead Python function: sparse_semi_structured_to_dense_cutlass"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a4378d27419ed12", "name": "Possibly dead Python function: dequantize_weights", "shortDescription": {"text": "Possibly dead Python function: dequantize_weights"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d4548f2c9952aa80", "name": "Possibly dead Python function: gptq_pack", "shortDescription": {"text": "Possibly dead Python function: gptq_pack"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47de50b3241525ad", "name": "Possibly dead Python function: gptq_unpack", "shortDescription": {"text": "Possibly dead Python function: gptq_unpack"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ecc8cf16484992e", "name": "Possibly dead Python function: write_to_file", "shortDescription": {"text": "Possibly dead Python function: write_to_file"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c06758092646cf1d", "name": "Possibly dead Python function: set_input_embeddings", "shortDescription": {"text": "Possibly dead Python function: set_input_embeddings"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa98d735a261a7cb", "name": "Possibly dead Python function: set_output_embeddings", "shortDescription": {"text": "Possibly dead Python function: set_output_embeddings"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d011dafc5622b5a", "name": "Possibly dead Python function: set_decoder", "shortDescription": {"text": "Possibly dead Python function: set_decoder"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-673887be97fd2cce", "name": "Possibly dead Python function: prepare_inputs_for_generation", "shortDescription": {"text": "Possibly dead Python function: prepare_inputs_for_generation"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50464cdcc18d9fa3", "name": "Possibly dead Python function: set_input_embeddings", "shortDescription": {"text": "Possibly dead Python function: set_input_embeddings"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-200a8f65341aa795", "name": "Possibly dead Python function: set_output_embeddings", "shortDescription": {"text": "Possibly dead Python function: set_output_embeddings"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ff80e4869752ad6", "name": "Possibly dead Python function: set_decoder", "shortDescription": {"text": "Possibly dead Python function: set_decoder"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a448bf1408984a2", "name": "Possibly dead Python function: prepare_inputs_for_generation", "shortDescription": {"text": "Possibly dead Python function: prepare_inputs_for_generation"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9cf69711843afb5", "name": "Possibly dead Python function: set_input_embeddings", "shortDescription": {"text": "Possibly dead Python function: set_input_embeddings"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f5501fd18dde796", "name": "Possibly dead Python function: set_output_embeddings", "shortDescription": {"text": "Possibly dead Python function: set_output_embeddings"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-955c2c601bb9c0c0", "name": "Possibly dead Python function: set_decoder", "shortDescription": {"text": "Possibly dead Python function: set_decoder"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86deb946b3e43ace", "name": "Possibly dead Python function: prepare_inputs_for_generation", "shortDescription": {"text": "Possibly dead Python function: prepare_inputs_for_generation"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ff39877efe08aad", "name": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/components/chat/index.vue:", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/components/chat/index.vue:339"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-4610b033ff33dcc4", "name": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.j", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-b881236d2d688787", "name": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/views/home.vue:367", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/views/home.vue:367"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-947299ff378a92a5", "name": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/components/chat/index.vue:339", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/components/chat/index.vue:339"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-0f438f16f5df192e", "name": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/assets/iconfont/iconfont.js:1", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-0d6f096367bbe912", "name": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/views/home.vue:367", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/views/home.vue:367"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-dd717848b5ceb0bb", "name": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py:322", "shortDescription": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py:322"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-ca31cc2573007266", "name": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237", "shortDescription": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-51538ea96f00399c", "name": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567", "shortDescription": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-ac8b6b8216d5b525", "name": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/utils.py:123", "shortDescription": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/utils.py:123"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-a11ea51dd2c423ec", "name": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/sched_rpc.py:51", "shortDescription": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/sched_rpc.py:51"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-ce52891c64b0d224", "name": "avoid bind to all interfaces \u2014 archive/kt-sft/ktransformers/sft/metrics_utils/misc.py:318", "shortDescription": {"text": "avoid bind to all interfaces \u2014 archive/kt-sft/ktransformers/sft/metrics_utils/misc.py:318"}, "fullDescription": {"text": "Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose the server publicly as it binds to all available interfaces. Consider instead getting correct address from an environment variable or configuration file.\n\nRule: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces\nSeverity: INFO\nOWASP: A01:2021 - Broken Access Control, A01:2025 - Broken Access Control\nCWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.55}}, {"id": "scanner-208b487dfa3a109f", "name": "avoid bind to all interfaces \u2014 archive/kt-sft/ktransformers/util/utils.py:101", "shortDescription": {"text": "avoid bind to all interfaces \u2014 archive/kt-sft/ktransformers/util/utils.py:101"}, "fullDescription": {"text": "Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose the server publicly as it binds to all available interfaces. Consider instead getting correct address from an environment variable or configuration file.\n\nRule: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces\nSeverity: INFO\nOWASP: A01:2021 - Broken Access Control, A01:2025 - Broken Access Control\nCWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.55}}, {"id": "scanner-ba0afbd44f8c6332", "name": "dynamic urllib use detected \u2014 archive/kt-sft/setup.py:300", "shortDescription": {"text": "dynamic urllib use detected \u2014 archive/kt-sft/setup.py:300"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-13fac8d572d83861", "name": "avoid pickle \u2014 archive/ktransformers/server/backend/interfaces/balance_serve.py:489", "shortDescription": {"text": "avoid pickle \u2014 archive/ktransformers/server/backend/interfaces/balance_serve.py:489"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-5ed4ec0d74fd055c", "name": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237", "shortDescription": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-250ca500c3377931", "name": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567", "shortDescription": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-a7a08784f1ac16b8", "name": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/utils.py:123", "shortDescription": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/utils.py:123"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-b39c73aa25b314d5", "name": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/sched_rpc.py:70", "shortDescription": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/sched_rpc.py:70"}, "fullDescription": {"text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\nRule: python.lang.security.deserialization.pickle.avoid-pickle\nSeverity: WARNING\nOWASP: A08:2017 - Insecure Deserialization, A08:2021 - Software and Data Integrity Failures, A08:2025 - Software or Data Integrity Failures\nCWE: CWE-502: Deserialization of Untrusted Data\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-48f0da5b4b2322b9", "name": "avoid bind to all interfaces \u2014 archive/ktransformers/util/utils.py:161", "shortDescription": {"text": "avoid bind to all interfaces \u2014 archive/ktransformers/util/utils.py:161"}, "fullDescription": {"text": "Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose the server publicly as it binds to all available interfaces. Consider instead getting correct address from an environment variable or configuration file.\n\nRule: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces\nSeverity: INFO\nOWASP: A01:2021 - Broken Access Control, A01:2025 - Broken Access Control\nCWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.55}}, {"id": "scanner-bd687a30d4500527", "name": "dynamic urllib use detected \u2014 archive/setup.py:281", "shortDescription": {"text": "dynamic urllib use detected \u2014 archive/setup.py:281"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-058dd35b68de1bff", "name": "subprocess shell true \u2014 kt-kernel/bench/compare_moe_performance.py:825", "shortDescription": {"text": "subprocess shell true \u2014 kt-kernel/bench/compare_moe_performance.py:825"}, "fullDescription": {"text": "Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.\n\nRule: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true\nSeverity: ERROR\nOWASP: A01:2017 - Injection, A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-d46c8a405d9b692b", "name": "exec detected \u2014 kt-kernel/python/__init__.py:80", "shortDescription": {"text": "exec detected \u2014 kt-kernel/python/__init__.py:80"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-4f444a2280df58fb", "name": "exec detected \u2014 kt-kernel/python/cli/__init__.py:18", "shortDescription": {"text": "exec detected \u2014 kt-kernel/python/cli/__init__.py:18"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-f3b14a44169dec28", "name": "exec detected \u2014 kt-kernel/setup.py:753", "shortDescription": {"text": "exec detected \u2014 kt-kernel/setup.py:753"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-21653d74bfba8079", "name": "exec detected \u2014 ktransformers.py:17", "shortDescription": {"text": "exec detected \u2014 ktransformers.py:17"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-5506e741c2d2b408", "name": "exec detected \u2014 setup.py:12", "shortDescription": {"text": "exec detected \u2014 setup.py:12"}, "fullDescription": {"text": "Detected the use of exec(). exec() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\nRule: python.lang.security.audit.exec-detected.exec-detected\nSeverity: WARNING\nOWASP: A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-b97870def601f7d1", "name": "CVE-2026-49356: @babel/core 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.24.5\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3bff8607c5600a4b", "name": "CVE-2025-27789: @babel/helpers 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27789: @babel/helpers 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups\n\nBabel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel will generate a polyfill for the `.replace` method that has quadratic complexity on some specific replacement pattern strings (i.e. the second argument passed to `.replace`). Generated code is vulnerable if all the following conditions are true: Using Babel to compile regular expression named capturing groups, usi\n\nPackage: @babel/helpers\nInstalled: 7.24.5\nFixed in: 7.26.10, 8.0.0-alpha.17\nSeverity: MEDIUM\nFix: Upgrade @babel/helpers to 7.26.10, 8.0.0-alpha.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf1231fa36fe81dd", "name": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Babel is a compiler for writing next generation JavaScript. From 7.12. ...\n\nBabel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.\n\nPackage: @babel/plugin-transform-modules-systemjs\nInstalled: 7.24.1\nFixed in: 7.29.4, 8.0.0-alpha.13\nSeverity: HIGH\nFix: Upgrade @babel/plugin-transform-modules-systemjs to 7.29.4, 8.0.0-alpha.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9454849e71ae494a", "name": "CVE-2025-27789: @babel/runtime 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27789: @babel/runtime 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups\n\nBabel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel will generate a polyfill for the `.replace` method that has quadratic complexity on some specific replacement pattern strings (i.e. the second argument passed to `.replace`). Generated code is vulnerable if all the following conditions are true: Using Babel to compile regular expression named capturing groups, usi\n\nPackage: @babel/runtime\nInstalled: 7.24.5\nFixed in: 7.26.10, 8.0.0-alpha.17\nSeverity: MEDIUM\nFix: Upgrade @babel/runtime to 7.26.10, 8.0.0-alpha.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8489e84fda8f961b", "name": "CVE-2024-52809: @intlify/core-base 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52809: @intlify/core-base 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n has cross-site scripting vulnerability with prototype pollution\n\nvue-i18n  is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.\n\nPackage: @intlify/core-base\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade @intlify/core-base to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9436c06ffe1bd87c", "name": "CVE-2025-53892: @intlify/core-base 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-53892: @intlify/core-base 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes\n\nVue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html. This may lead to a DOM-based XSS vulnerab\n\nPackage: @intlify/core-base\nInstalled: 9.13.1\nFixed in: 9.14.5, 10.0.8, 11.1.10\nSeverity: MEDIUM\nFix: Upgrade @intlify/core-base to 9.14.5, 10.0.8, 11.1.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cecac97a9d57449", "name": "CVE-2024-52810: @intlify/shared 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52810: @intlify/shared 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "@intlify/shared Prototype Pollution vulnerability\n\n@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) as the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the lib\n\nPackage: @intlify/shared\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade @intlify/shared to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-210acfe48b4def43", "name": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain \n\nPackage: @protobufjs/utf8\nInstalled: 1.1.0\nFixed in: 1.1.1\nSeverity: MEDIUM\nFix: Upgrade @protobufjs/utf8 to 1.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-41273e776bcd453a", "name": "CVE-2025-69873: ajv 6.12.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-69873: ajv 6.12.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 6.12.6\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e4d335545da333bb", "name": "GHSA-9q82-xgwf-vj6h: apollo-server-core 3.13.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-9q82-xgwf-vj6h: apollo-server-core 3.13.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention\n\n# Impact\n\nIn a Cross-Site Request Forgery attack, untrusted web content causes browsers to send authenticated requests to web servers which use cookies for authentication. While the web content is prevented from reading the request's response due to the Cross-Origin Request Sharing (CORS) protocol, an attacker may be able to cause side effects in the server (\"CSRF\" attack), or learn something about the response via timing analysis (\"XS-Search\" attack).\n\nApollo Server has a built-in feature which\n\nPackage: apollo-server-core\nInstalled: 3.13.0\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e7a59a09a4bce68", "name": "CVE-2024-39338: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-39338: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: axios: Server-Side Request Forgery\n\naxios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.7.4\nSeverity: HIGH\nFix: Upgrade axios to 1.7.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-03cd8cf632b8ffb8", "name": "CVE-2025-27152: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27152: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests\n\naxios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if \u2060baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.8.2, 0.30.0\nSeverity: HIGH\nFix: Upgrade axios to 1.8.2, 0.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2d048346e089f70c", "name": "CVE-2025-58754: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-58754: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios DoS via lack of data size check\n\nAxios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (`Buffer`/`Blob`) and returns a synthetic 200 response. This path ignores `maxContentLength` / `maxBodyLength` (which only protect HTTP responses), so an attacker can supply a very large `data:` URI a\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.12.0, 0.30.2\nSeverity: HIGH\nFix: Upgrade axios to 1.12.0, 0.30.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40222fa32de80e47", "name": "CVE-2026-25639: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-25639: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.13.5, 0.30.3\nSeverity: HIGH\nFix: Upgrade axios to 1.13.5, 0.30.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2d3b8b7b11e4e4be", "name": "CVE-2026-42033: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42033: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: HTTP Transport Hijacking via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-437dc476cd133b8c", "name": "CVE-2026-42035: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42035: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Arbitrary HTTP header injection via prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type checking of the data payload, where if Object.prototype is polluted with getHeaders, append, pipe, on, once, and Symbol.toStringTag, Axios misidentifies any plain object payload as a FormData instance an\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-969022c2aae42ef1", "name": "CVE-2026-42043: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42043: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: NO_PROXY bypass via crafted URL\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4cb0e4e6e138d043", "name": "CVE-2026-42264: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42264: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Prototype pollution allows information disclosure and request manipulation\n\nAxios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.2\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-83d0534013e9f434", "name": "CVE-2026-44486: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44486: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via HTTP redirects\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019 Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. T\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-20b161116aa02b09", "name": "CVE-2026-44487: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44487: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via redirect flows\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was in\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5c23c74d30db155c", "name": "CVE-2026-44488: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44488: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service due to unenforced request and response size limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. This can cause resource exhaustion in server-side usag\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-54aff46017b4e433", "name": "CVE-2026-44494: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44494: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack \u2014 intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, whic\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8170b2bbf87b9f36", "name": "CVE-2026-44495: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44495: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to prototype pollution vulnerability\n\nAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-p\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.2, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b1531b0251daacdf", "name": "CVE-2026-44496: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44496: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9f1750743221ce5e", "name": "CVE-2025-62718: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-62718: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This is\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-087617e068887180", "name": "CVE-2026-40175: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-40175: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Remote Code Execution via Prototype Pollution escalation\n\nAxios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13044fb062bb9002", "name": "CVE-2026-42034: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42034: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via oversized streamed uploads bypassing body limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-baeb0e9f9c979011", "name": "CVE-2026-42036: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42036: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is used\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e14dea92143251e", "name": "CVE-2026-42037: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42037: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type header\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\\r\\n) sequences. An attacker who controls the .type property of a Blob/File-like object (e.g., via a user-uploaded file in a Node.js proxy service) can inject arbitrary MIME part headers into the multipart form-data body. This bypa\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3d8288920289f9d8", "name": "CVE-2026-42038: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42038: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to `no_proxy` bypass\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy() function does pure string matching \u2014 it does not resolve IP aliases or loopback equivalents. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4406d50a3657102e", "name": "CVE-2026-42039: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42039: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9da4e9ac6b9eaa2e", "name": "CVE-2026-42041: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42041: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5f5fcd457d7e8999", "name": "CVE-2026-42042: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42042: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: XSRF token bypass leading to information disclosure\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy non-boolean value (via prototype pollution or misconfiguration), the same-origin check (isURLSameOrigin) is short-circuited, causing XSRF tokens to be sent to all request targets including cross-origin s\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7be920a797f2e7d", "name": "CVE-2026-42044: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42044: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses \u2014 including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.2\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57816ac5abc98cf2", "name": "CVE-2026-44490: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44490: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure and denial of service due to prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values. (1) lib/utils.js line 406 builds merge()'s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket's own keys are copied into the mer\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-354e4eb241d857f2", "name": "GHSA-42h9-826w-cgv3: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-42h9-826w-cgv3: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Excessive recursion in formDataToJSON can cause denial of service\n\n## Summary\nAxios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.\n\nApplications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8493a66e1a9c3b99", "name": "GHSA-7q8q-rj6j-mhjq: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Nested axios option objects can consume polluted prototype values\n\n## Summary\n\nAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.\n\nThe top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound re\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-286219ea2194d27e", "name": "GHSA-jqh4-m9w3-8hp9: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`\n\n## Summary\n\naxios\u2019 fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: \"fetch\"` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.\n\nThis affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20094c53bcf5763a", "name": "GHSA-mmx7-hfxf-jppx: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Prototype pollution gadgets can alter axios request construction\n\n## Summary\n\naxios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in the bodyless method aliases: `axios.get()`, `axios.delete()`, `axios.head()`, and `axios.options()` read inherited `data` before config normalization, causing attacker-controlled body data to be sent on requests that did not explicitly set a body.\n\nAdditional low-level paths affect consumers that \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4418693fd1de8763", "name": "GHSA-pmv8-rq9r-6j72: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Deep formToJSON Key Recursion Can Cause Denial of Service\n\n## Summary\n\nAxios versions starting with `0.28.0` contain uncontrolled recursion in `formDataToJSON`, which is exposed as `axios.formToJSON()` and used internally when axios serialises `FormData` with `Content-Type: application/json`.\n\nIf an application passes attacker-controlled `FormData` field names to this functionality, a field name with thousands of nested bracket segments can exhaust the JavaScript call stack and cause denial of service for that request or, in applications without appropr\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e618535ae8b58cc", "name": "CVE-2026-42040: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42040: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Incorrect null byte handling can lead to data integrity issues\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at line 21 that reverses the safe percent-encoding of null bytes. After encodeURIComponent('\\x00') correctly produces the safe sequence %00, the charMap entry '%00': '\\x00' converts it back to a raw null byte. Primary impact is limited because the standard axios request flow is not affected. This vulnerab\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: LOW\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a9c147d7aa47fe04", "name": "CVE-2026-2739: bn.js 4.12.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2739: bn.js 4.12.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "bn.js: bn.js: Denial of Service via calling maskn(0)\n\nThis affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.\n\nPackage: bn.js\nInstalled: 4.12.0\nFixed in: 4.12.3, 5.2.3\nSeverity: MEDIUM\nFix: Upgrade bn.js to 4.12.3, 5.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b2637e6873970732", "name": "CVE-2026-2739: bn.js 5.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2739: bn.js 5.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "bn.js: bn.js: Denial of Service via calling maskn(0)\n\nThis affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.\n\nPackage: bn.js\nInstalled: 5.2.1\nFixed in: 4.12.3, 5.2.3\nSeverity: MEDIUM\nFix: Upgrade bn.js to 4.12.3, 5.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-41ceff131080cbc2", "name": "CVE-2024-45590: body-parser 1.20.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-45590: body-parser 1.20.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "body-parser: Denial of Service Vulnerability in body-parser\n\nbody-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.\n\nPackage: body-parser\nInstalled: 1.20.2\nFixed in: 1.20.3\nSeverity: HIGH\nFix: Upgrade body-parser to 1.20.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-203c0f117845dc1d", "name": "CVE-2026-12590: body-parser 1.20.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70cfc3642247ad9d", "name": "CVE-2026-13149: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 1.1.11\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f82fb10dd98a9eea", "name": "CVE-2026-33750: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33750: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.\n\nPackage: brace-expansion\nInstalled: 1.1.11\nFixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.5, 3.0.2, 2.0.3, 1.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f949ae8d82bb5355", "name": "CVE-2025-5889: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-5889: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: juliangruber brace-expansion index.js expand redos\n\nA vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 i\n\nPackage: brace-expansion\nInstalled: 1.1.11\nFixed in: 2.0.2, 1.1.12, 3.0.1, 4.0.1\nSeverity: LOW\nFix: Upgrade brace-expansion to 2.0.2, 1.1.12, 3.0.1, 4.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eea59c2830416434", "name": "CVE-2026-13149: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 2.0.1\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1cf26c7ead5adddd", "name": "CVE-2026-33750: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33750: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.\n\nPackage: brace-expansion\nInstalled: 2.0.1\nFixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.5, 3.0.2, 2.0.3, 1.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94d7fe32df0dffbf", "name": "CVE-2025-5889: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-5889: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: juliangruber brace-expansion index.js expand redos\n\nA vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 i\n\nPackage: brace-expansion\nInstalled: 2.0.1\nFixed in: 2.0.2, 1.1.12, 3.0.1, 4.0.1\nSeverity: LOW\nFix: Upgrade brace-expansion to 2.0.2, 1.1.12, 3.0.1, 4.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7564c1a20370d6b7", "name": "CVE-2024-4068: braces 2.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4068: braces 2.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "braces: fails to limit the number of characters it can handle\n\nThe NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends \"imbalanced braces\" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.\n\nPackage: braces\nInstalled: 2.3.2\nFixed in: 3.0.3\nSeverity: HIGH\nFix: Upgrade braces to 3.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3785378cdd08b3d", "name": "CVE-2024-4068: braces 3.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4068: braces 3.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "braces: fails to limit the number of characters it can handle\n\nThe NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends \"imbalanced braces\" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.\n\nPackage: braces\nInstalled: 3.0.2\nFixed in: 3.0.3\nSeverity: HIGH\nFix: Upgrade braces to 3.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f560c2ec6501ed38", "name": "CVE-2025-9287: cipher-base 1.0.4 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-9287: cipher-base 1.0.4 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cipher-base: Cipher-base hash manipulation\n\nImproper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.\n\nPackage: cipher-base\nInstalled: 1.0.4\nFixed in: 1.0.5\nSeverity: CRITICAL\nFix: Upgrade cipher-base to 1.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-6478b66ae8df1fa5", "name": "CVE-2024-47764: cookie 0.6.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-47764: cookie 0.6.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cookie: cookie accepts cookie name, path, and domain with out of bounds characters\n\ncookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.\n\nPackage: cookie\nInstalled: 0.6.0\nFixed in: 0.7.0\nSeverity: LOW\nFix: Upgrade cookie to 0.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65f60c3cc5338e28", "name": "CVE-2024-21538: cross-spawn 6.0.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-21538: cross-spawn 6.0.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cross-spawn: regular expression denial of service\n\nVersions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.\n\nPackage: cross-spawn\nInstalled: 6.0.5\nFixed in: 7.0.5, 6.0.6\nSeverity: HIGH\nFix: Upgrade cross-spawn to 7.0.5, 6.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5411c2bce63c1a25", "name": "CVE-2024-21538: cross-spawn 7.0.3 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-21538: cross-spawn 7.0.3 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cross-spawn: regular expression denial of service\n\nVersions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.\n\nPackage: cross-spawn\nInstalled: 7.0.3\nFixed in: 7.0.5, 6.0.6\nSeverity: HIGH\nFix: Upgrade cross-spawn to 7.0.5, 6.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0199a09e32c73ea2", "name": "CVE-2026-53486: decompress 4.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53486: decompress 4.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction\n\nThe decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/\n\nPackage: decompress\nInstalled: 4.2.1\nFixed in: \u2014\nSeverity: CRITICAL\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-291cac5262f3cea9", "name": "CVE-2025-57665: element-plus 2.7.3 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-57665: element-plus 2.7.3 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Element Plus Link component (el-link) implements insufficient input validation for the href attribute\n\nElement Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. This allows attackers to inject malicious URLs using dangerous protocols (javascript:, data:, file:) or redirect users to external malicious sites. Wh\n\nPackage: element-plus\nInstalled: 2.7.3\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-818bb4f37908d3f4", "name": "GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)\n\n### Summary\n\nPrivate key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input\n\nNote that `elliptic` by design accepts hex strings as one of the possible input types\n\n### Details\n\nIn this code: https://github.com/indutny/elliptic/blob/3e46a48fdd2ef2f89593e5e058d85530578c9761/lib/elliptic/ec/index.js#L100-L107\n\n`msg` is a BN instance after conversion, but `nonce` is an array, and different BN instances could\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.6.1\nSeverity: CRITICAL\nFix: Upgrade elliptic to 6.6.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-f5581b5d86696eaa", "name": "CVE-2024-42459: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-42459: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: nodejs/elliptic: EDDSA signature malleability due to missing signature length check\n\nIn the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.7\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c48f5da160ef9279", "name": "CVE-2024-42460: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-42460: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: nodejs/elliptic: ECDSA signature malleability due to missing checks\n\nIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.7\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a0f08fbc519ed65", "name": "CVE-2024-42461: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-42461: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: nodejs/elliptic: ECDSA implementation malleability due to BER-enconded signatures being allowed\n\nIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.7\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff8970f5ad11d230", "name": "CVE-2024-48948: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-48948: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: ECDSA signature verification error may reject legitimate transactions\n\nThe Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.6.0\nSeverity: LOW\nFix: Upgrade elliptic to 6.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0c9d6ecc74928cd", "name": "CVE-2024-48949: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-48949: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: Missing Validation in Elliptic's EDDSA Signature Verification\n\nThe verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits \"sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()\" validation.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.6\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-058b4f1bb7dc6eb3", "name": "CVE-2025-14505: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-14505: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: Key handling flaws in Elliptic\n\nThe ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of  RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure. This happens, because the byte-length of 'k' is incorrectly computed, resulting in its getting truncated during the computation. Legitimate transactions or communications will be broken as a result.\u00a0Furtherm\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c7778d57e25bf100", "name": "CVE-2024-43796: express 4.19.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43796: express 4.19.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "express: Improper Input Handling in Express Redirects\n\nExpress.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.\n\nPackage: express\nInstalled: 4.19.2\nFixed in: 4.20.0, 5.0.0\nSeverity: LOW\nFix: Upgrade express to 4.20.0, 5.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a55613ab4bb6d9aa", "name": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets\n\n## Summary\n\nWhen an HTTP request follows a cross-domain redirect (301/302/307/308), `follow-redirects` only strips `authorization`, `proxy-authorization`, and `cookie` headers (matched by regex at index.js:469-476). Any custom authentication header (e.g., `X-API-Key`, `X-Auth-Token`, `Api-Key`, `Token`) is forwarded verbatim to the redirect target.\n\nSince `follow-redirects` is the redirect-handling dependency for **axios** (105K+ stars), this vulnerability affects the entire axios ecosystem.\n\n##\n\nPackage: follow-redirects\nInstalled: 1.15.6\nFixed in: 1.16.0\nSeverity: MEDIUM\nFix: Upgrade follow-redirects to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e3378da60a68c43", "name": "CVE-2025-7783: form-data 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-7783: form-data 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "form-data: Unsafe random function in form-data\n\nUse of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.\n\nThis issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.\n\nPackage: form-data\nInstalled: 4.0.0\nFixed in: 2.5.4, 3.0.4, 4.0.4\nSeverity: CRITICAL\nFix: Upgrade form-data to 2.5.4, 3.0.4, 4.0.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-02e4efdf86668863", "name": "CVE-2026-12143: form-data 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.0\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6508943c638d451d", "name": "CVE-2022-25900: git-clone 0.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2022-25900: git-clone 0.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Command injection in git-clone\n\nAll versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.\n\nPackage: git-clone\nInstalled: 0.1.0\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-11ac06ff22880c1f", "name": "CVE-2022-33987: got 8.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2022-33987: got 8.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets\n\nThe got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.\n\nPackage: got\nInstalled: 8.3.2\nFixed in: 12.1.0, 11.8.5\nSeverity: MEDIUM\nFix: Upgrade got to 12.1.0, 11.8.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74950c41c70ba2e9", "name": "CVE-2022-25881: http-cache-semantics 3.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2022-25881: http-cache-semantics 3.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability\n\nThis affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.\n\nPackage: http-cache-semantics\nInstalled: 3.8.1\nFixed in: 4.1.1\nSeverity: HIGH\nFix: Upgrade http-cache-semantics to 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1dc120afddfc8989", "name": "CVE-2026-48038: joi 17.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-48038: joi 17.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "joi: joi: Denial of Service via uncaught RangeError on deeply nested input through recursive link() schemas\n\njoi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supplied JSON or object input with recursive link() schemas. When validate() is called without try/catch in a request handler, deeply nested input can trigger an unhandled RangeError and potentially crash the process; lower-impact paths using validateAsync() or try/catch produce a RangeError instead of a structur\n\nPackage: joi\nInstalled: 17.13.1\nFixed in: 18.2.1, 17.13.4\nSeverity: MEDIUM\nFix: Upgrade joi to 18.2.1, 17.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5a1365e3792e29a3", "name": "CVE-2026-59869: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 3.14.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b08a737c57fc03ee", "name": "CVE-2025-64718: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-64718: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml prototype pollution in merge\n\njs-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).\n\nPackage: js-yaml\nInstalled: 3.14.1\nFixed in: 4.1.1, 3.14.2\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.1.1, 3.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8cee7bd48dffc46e", "name": "CVE-2026-53550: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 3.14.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4817c6ecbd96b539", "name": "CVE-2026-59869: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.0\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bce7ca9cb3b0a86d", "name": "CVE-2025-64718: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-64718: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml prototype pollution in merge\n\njs-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).\n\nPackage: js-yaml\nInstalled: 4.1.0\nFixed in: 4.1.1, 3.14.2\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.1.1, 3.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e91dcc81e879e8f", "name": "CVE-2026-53550: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.0\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a46f429441755131", "name": "CVE-2024-52011: launch-editor 2.6.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52011: launch-editor 2.6.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.\n\nPackage: launch-editor\nInstalled: 2.6.1\nFixed in: 2.9.0\nSeverity: HIGH\nFix: Upgrade launch-editor to 2.9.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-baadf3fd0041bbbc", "name": "CVE-2026-53632: launch-editor 2.6.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53632: launch-editor 2.6.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: launch-editor\nInstalled: 2.6.1\nFixed in: 2.14.1\nSeverity: MEDIUM\nFix: Upgrade launch-editor to 2.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba7c2a5a2cf4ee61", "name": "CVE-2026-4800: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f7a3b45e35a307dc", "name": "CVE-2025-13465: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29ed3173bbdab352", "name": "CVE-2026-2950: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-857de1a1dd904756", "name": "CVE-2026-4800: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27028985745e1a2f", "name": "CVE-2025-13465: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a458940504012007", "name": "CVE-2026-2950: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-011dd8fa34e638b3", "name": "CVE-2024-4067: micromatch 3.1.10 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4067: micromatch 3.1.10 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "micromatch: vulnerable to Regular Expression Denial of Service\n\nThe NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged \n\nPackage: micromatch\nInstalled: 3.1.10\nFixed in: 4.0.8\nSeverity: MEDIUM\nFix: Upgrade micromatch to 4.0.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f7943cc41ff39a1", "name": "CVE-2024-4067: micromatch 4.0.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4067: micromatch 4.0.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "micromatch: vulnerable to Regular Expression Denial of Service\n\nThe NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged \n\nPackage: micromatch\nInstalled: 4.0.5\nFixed in: 4.0.8\nSeverity: MEDIUM\nFix: Upgrade micromatch to 4.0.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1a272788e485f37", "name": "CVE-2026-26996: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 3.1.2\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ff8dade712bbb5c", "name": "CVE-2026-27903: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 3.1.2\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6fe518a3a6f4e36d", "name": "CVE-2026-27904: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 3.1.2\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c80494aff42fe89a", "name": "CVE-2026-26996: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-730dfc387c6fd43d", "name": "CVE-2026-27903: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-964fbeb044e0ff30", "name": "CVE-2026-27904: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f38bf7635947984c", "name": "CVE-2024-55565: nanoid 2.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-55565: nanoid 2.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nanoid: nanoid mishandles non-integer values\n\nnanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.\n\nPackage: nanoid\nInstalled: 2.1.11\nFixed in: 5.0.9, 3.3.8\nSeverity: MEDIUM\nFix: Upgrade nanoid to 5.0.9, 3.3.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e95b6f0891bdb9e7", "name": "CVE-2024-55565: nanoid 3.3.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-55565: nanoid 3.3.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nanoid: nanoid mishandles non-integer values\n\nnanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.\n\nPackage: nanoid\nInstalled: 3.3.7\nFixed in: 5.0.9, 3.3.8\nSeverity: MEDIUM\nFix: Upgrade nanoid to 5.0.9, 3.3.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-08182652afb4af5c", "name": "CVE-2025-25975: parse-git-config 3.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-25975: parse-git-config 3.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "parse-git-config: Prototype Pollution Vulneralbility in parse-git-config\n\nAn issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function\n\nPackage: parse-git-config\nInstalled: 3.0.0\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-edabfb51fcd83e6d", "name": "CVE-2024-45296: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-45296: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: Backtracking regular expressions cause ReDoS\n\npath-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1\n\nPackage: path-to-regexp\nInstalled: 0.1.7\nFixed in: 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b682201d8f66b821", "name": "CVE-2024-52798: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52798: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x\n\npath-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.\n\nPackage: path-to-regexp\nInstalled: 0.1.7\nFixed in: 0.1.12\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-189c73853995cfd6", "name": "CVE-2026-4867: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-4867: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters\n\nImpact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\n\n\nPackage: path-to-regexp\nInstalled: 0.1.7\nFixed in: 0.1.13\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a81dc8f35de358ad", "name": "CVE-2025-6545: pbkdf2 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-6545: pbkdf2 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "pbkdf2: pbkdf2 silently returns predictable key material\n\nImproper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js.\n\nThis issue affects pbkdf2: from 3.0.10 through 3.1.2.\n\nPackage: pbkdf2\nInstalled: 3.1.2\nFixed in: 3.1.3\nSeverity: CRITICAL\nFix: Upgrade pbkdf2 to 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-88c61cecb5b8ca49", "name": "CVE-2025-6547: pbkdf2 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-6547: pbkdf2 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "pbkdf2: pbkdf2 silently returns static keys\n\nImproper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.\n\nPackage: pbkdf2\nInstalled: 3.1.2\nFixed in: 3.1.3\nSeverity: CRITICAL\nFix: Upgrade pbkdf2 to 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-70bfc2840e418ae3", "name": "CVE-2024-4367: pdfjs-dist 2.6.347 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4367: pdfjs-dist 2.6.347 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Mozilla: Arbitrary JavaScript execution in PDF.js\n\nA type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.\n\nPackage: pdfjs-dist\nInstalled: 2.6.347\nFixed in: 4.2.67\nSeverity: HIGH\nFix: Upgrade pdfjs-dist to 4.2.67"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1089be8b3e698ef7", "name": "CVE-2024-4367: pdfjs-dist 3.5.141 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4367: pdfjs-dist 3.5.141 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Mozilla: Arbitrary JavaScript execution in PDF.js\n\nA type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.\n\nPackage: pdfjs-dist\nInstalled: 3.5.141\nFixed in: 4.2.67\nSeverity: HIGH\nFix: Upgrade pdfjs-dist to 4.2.67"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e0a299fac3395bb6", "name": "CVE-2026-33671: picomatch 2.3.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-295cf74d0dd553ff", "name": "CVE-2026-33672: picomatch 2.3.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e8a4ccba36b54be5", "name": "CVE-2026-41305: postcss 8.4.38 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.38 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.38\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b69fc47d00680aab", "name": "CVE-2024-53382: prismjs 1.29.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.29.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.29.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70e2041e293e7e48", "name": "CVE-2025-15284: qs 6.11.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-15284: qs 6.11.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs: Denial of Service via improper input validation in array parsing\n\nImproper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummary\n\nThe arrayLimit\u00a0option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit\u00a0should apply uniformly across all array notations.\n\nNote:\u00a0The default parameterLimit\u00a0of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la\n\nPackage: qs\nInstalled: 6.11.0\nFixed in: 6.14.1\nSeverity: MEDIUM\nFix: Upgrade qs to 6.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ab1ecf3a7c41161", "name": "CVE-2026-2391: qs 6.11.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.11.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.11.0\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef915955d39d009e", "name": "CVE-2025-15284: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-15284: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs: Denial of Service via improper input validation in array parsing\n\nImproper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummary\n\nThe arrayLimit\u00a0option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit\u00a0should apply uniformly across all array notations.\n\nNote:\u00a0The default parameterLimit\u00a0of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la\n\nPackage: qs\nInstalled: 6.12.1\nFixed in: 6.14.1\nSeverity: MEDIUM\nFix: Upgrade qs to 6.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9567d4e2f3bd1216", "name": "CVE-2026-8723: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.12.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27e3f60904ecb2f4", "name": "CVE-2026-2391: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.12.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab92d670448c2bd8", "name": "CVE-2024-43799: send 0.18.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43799: send 0.18.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "send: Code Execution Vulnerability in Send Library\n\nSend is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.\n\nPackage: send\nInstalled: 0.18.0\nFixed in: 0.19.0\nSeverity: LOW\nFix: Upgrade send to 0.19.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6ad799bd3b8358c", "name": "GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()\n\n### Impact\n\nThe serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660.\n\nWhile `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A similar issue exists in `Date.prototype.toISOString()`.\n\nIf an attacker can control the input object passed to `serialize()`, they can inject malicious JavaScript via the flags property of a RegExp object. When the serialize\n\nPackage: serialize-javascript\nInstalled: 4.0.0\nFixed in: 7.0.3\nSeverity: HIGH\nFix: Upgrade serialize-javascript to 7.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5cc7487b1b836706", "name": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()\n\n### Impact\n\nThe serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660.\n\nWhile `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A similar issue exists in `Date.prototype.toISOString()`.\n\nIf an attacker can control the input object passed to `serialize()`, they can inject malicious JavaScript via the flags property of a RegExp object. When the serialize\n\nPackage: serialize-javascript\nInstalled: 6.0.2\nFixed in: 7.0.3\nSeverity: HIGH\nFix: Upgrade serialize-javascript to 7.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b42f348bd2fb432d", "name": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization\n\nSerialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted \"array-like\" object (an object that inherits from Array.prototype but has a very large length property), the process enters an intensive loop that consumes 100% CPU and hangs indefinitely. This issue has been patched in version 7.0.5.\n\nPackage: serialize-javascript\nInstalled: 6.0.2\nFixed in: 7.0.5\nSeverity: MEDIUM\nFix: Upgrade serialize-javascript to 7.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-461e401ebf9a57aa", "name": "CVE-2024-43800: serve-static 1.15.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43800: serve-static 1.15.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "serve-static: Improper Sanitization in serve-static\n\nserve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.\n\nPackage: serve-static\nInstalled: 1.15.0\nFixed in: 1.16.0, 2.1.0\nSeverity: LOW\nFix: Upgrade serve-static to 1.16.0, 2.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d082d0c77dafc977", "name": "CVE-2025-9288: sha.js 2.4.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-9288: sha.js 2.4.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "sha.js: Missing type checks leading to hash rewind and passing on crafted data\n\nImproper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.\n\nPackage: sha.js\nInstalled: 2.4.11\nFixed in: 2.4.12\nSeverity: CRITICAL\nFix: Upgrade sha.js to 2.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-fe754672f28824cc", "name": "CVE-2026-9277: shell-quote 1.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-9277: shell-quote 1.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators\n\nshell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\\n, \\r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is re\n\nPackage: shell-quote\nInstalled: 1.8.1\nFixed in: 1.8.4\nSeverity: CRITICAL\nFix: Upgrade shell-quote to 1.8.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-5af47bd4ec8df1d3", "name": "CVE-2026-13311: shell-quote 1.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-13311: shell-quote 1.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing\n\nshell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled string to any code path that calls parse() (no shell metacharacters are required; plain space-separated words suffice) can block the single-threaded Node.js event loop for an exten\n\nPackage: shell-quote\nInstalled: 1.8.1\nFixed in: 1.9.0\nSeverity: HIGH\nFix: Upgrade shell-quote to 1.9.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c0d6e4eb625f370", "name": "CVE-2026-59873: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59873: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tar: node-tar: Denial of Service via crafted gzip bomb\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.19\nSeverity: CRITICAL\nFix: Upgrade tar to 7.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-fee1755c8b9fbc7b", "name": "CVE-2026-23745: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-23745: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives\n\nnode-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.3\nSeverity: HIGH\nFix: Upgrade tar to 7.5.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b764c833ab5f9585", "name": "CVE-2026-23950: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-23950: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition\n\nnode-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `\u00df` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.4\nSeverity: HIGH\nFix: Upgrade tar to 7.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-78778d0b4ad7680d", "name": "CVE-2026-24842: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-24842: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check\n\nnode-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.7\nSeverity: HIGH\nFix: Upgrade tar to 7.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cf3f7677f8ce8433", "name": "CVE-2026-26960: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-26960: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation\n\nnode-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.8\nSeverity: HIGH\nFix: Upgrade tar to 7.5.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4ac1f51bae6d5a67", "name": "CVE-2026-29786: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-29786: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: hardlink path traversal via drive-relative linkpath\n\nnode-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.10\nSeverity: HIGH\nFix: Upgrade tar to 7.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0146cea8ec32c7df", "name": "CVE-2026-31802: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-31802: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tar: tar: File overwrite via drive-relative symlink traversal\n\nnode-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.11\nSeverity: HIGH\nFix: Upgrade tar to 7.5.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d756f80dfa11ac7e", "name": "CVE-2026-59874: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59874: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tar: Node-tar: Denial of Service via malformed tar archive header\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.18\nSeverity: HIGH\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e81920a6628ebe25", "name": "CVE-2026-53655: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53655: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: File smuggling due to inconsistent tar archive parsing\n\nnode-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the by\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.16\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5131f2d0f0854cc", "name": "CVE-2026-59871: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59871: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service due to incorrect PAX path handling\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.18\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f019ce49be0cb3e8", "name": "CVE-2026-59875: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59875: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.17\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-677e4affbb010d69", "name": "CVE-2026-44705: tmp 0.0.33 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44705: tmp 0.0.33 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tmp is a temporary file and directory creator for node.js. Prior to 0. ...\n\ntmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running pr\n\nPackage: tmp\nInstalled: 0.0.33\nFixed in: 0.2.6\nSeverity: HIGH\nFix: Upgrade tmp to 0.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bac6a1c5d9159815", "name": "CVE-2025-54798: tmp 0.0.33 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-54798: tmp 0.0.33 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tmp: tmp Symbolic Link Write Vulnerability\n\ntmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.\n\nPackage: tmp\nInstalled: 0.0.33\nFixed in: 0.2.4\nSeverity: LOW\nFix: Upgrade tmp to 0.2.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b7433bb08a06b53", "name": "CVE-2026-41907: uuid 8.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 8.3.2\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc6e0ced8855c06d", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ddd5052a8691938", "name": "CVE-2024-9506: vue 2.7.16 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-9506: vue 2.7.16 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue: Regular Expression Denial of Service (ReDoS)\n\nImproper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.\n\nPackage: vue\nInstalled: 2.7.16\nFixed in: 3.0.0-alpha.0\nSeverity: LOW\nFix: Upgrade vue to 3.0.0-alpha.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0debd7897f8450a", "name": "CVE-2025-27597: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27597: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Vue I18n Allows Prototype Pollution in `handleFlatJson`\n\nVue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the li\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.3, 10.0.6, 11.1.2\nSeverity: HIGH\nFix: Upgrade vue-i18n to 9.14.3, 10.0.6, 11.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-400549ac70acf431", "name": "CVE-2024-52809: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52809: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n has cross-site scripting vulnerability with prototype pollution\n\nvue-i18n  is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade vue-i18n to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0c1686713ba79f97", "name": "CVE-2024-52810: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52810: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "@intlify/shared Prototype Pollution vulnerability\n\n@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) as the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the lib\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade vue-i18n to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f2e565710cc0fc04", "name": "CVE-2025-53892: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-53892: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes\n\nVue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html. This may lead to a DOM-based XSS vulnerab\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.5, 10.0.8, 11.1.10\nSeverity: MEDIUM\nFix: Upgrade vue-i18n to 9.14.5, 10.0.8, 11.1.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06304a0528a9013a", "name": "CVE-2024-43788: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43788: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule\n\nWebpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have discovered a DOM Clobbering vulnerability in Webpack\u2019s `AutoPublicPathRuntimeModule`. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name`\n\nPackage: webpack\nInstalled: 5.91.0\nFixed in: 5.94.0\nSeverity: MEDIUM\nFix: Upgrade webpack to 5.94.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a430daae123a8817", "name": "CVE-2025-68157: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-68157: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects\n\nWebpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack\u2019s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build mac\n\nPackage: webpack\nInstalled: 5.91.0\nFixed in: 5.104.0\nSeverity: LOW\nFix: Upgrade webpack to 5.104.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed2ce49888cda742", "name": "CVE-2025-68458: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-68458: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior\n\nWebpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack\u2019s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/ho\n\nPackage: webpack\nInstalled: 5.91.0\nFixed in: 5.104.1\nSeverity: LOW\nFix: Upgrade webpack to 5.104.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f909497092c44f4a", "name": "CVE-2024-37890: ws 7.5.9 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-37890: ws 7.5.9 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nodejs-ws: denial of service when handling a request with many HTTP headers\n\nws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in ws@8.17.1 (e55e510) and backported to ws@7.5.10 (22c2876), ws@6.2.3 (eeb76d3), and ws@5.2.4 (4abd8f6). In vulnerable versions of ws, the issue can be mitigated in the following ways: 1. Reduce the maximum allowed length of the request headers using the --max-http-header-size=size and/or th\n\nPackage: ws\nInstalled: 7.5.9\nFixed in: 5.2.4, 6.2.3, 7.5.10, 8.17.1\nSeverity: HIGH\nFix: Upgrade ws to 5.2.4, 6.2.3, 7.5.10, 8.17.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8724c57681087597", "name": "CVE-2026-48779: ws 7.5.9 \u2014 archive/kt-sft/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-48779: ws 7.5.9 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 7.5.9\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-48de6843214cf0aa", "name": "CVE-2026-49356: @babel/core 7.24.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.24.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.24.5\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd2e68d60dd582ad", "name": "CVE-2025-27789: @babel/helpers 7.24.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27789: @babel/helpers 7.24.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups\n\nBabel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel will generate a polyfill for the `.replace` method that has quadratic complexity on some specific replacement pattern strings (i.e. the second argument passed to `.replace`). Generated code is vulnerable if all the following conditions are true: Using Babel to compile regular expression named capturing groups, usi\n\nPackage: @babel/helpers\nInstalled: 7.24.5\nFixed in: 7.26.10, 8.0.0-alpha.17\nSeverity: MEDIUM\nFix: Upgrade @babel/helpers to 7.26.10, 8.0.0-alpha.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c142bf74bf2f61b0", "name": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Babel is a compiler for writing next generation JavaScript. From 7.12. ...\n\nBabel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.\n\nPackage: @babel/plugin-transform-modules-systemjs\nInstalled: 7.24.1\nFixed in: 7.29.4, 8.0.0-alpha.13\nSeverity: HIGH\nFix: Upgrade @babel/plugin-transform-modules-systemjs to 7.29.4, 8.0.0-alpha.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-520a523287f6372f", "name": "CVE-2025-27789: @babel/runtime 7.24.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27789: @babel/runtime 7.24.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups\n\nBabel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel will generate a polyfill for the `.replace` method that has quadratic complexity on some specific replacement pattern strings (i.e. the second argument passed to `.replace`). Generated code is vulnerable if all the following conditions are true: Using Babel to compile regular expression named capturing groups, usi\n\nPackage: @babel/runtime\nInstalled: 7.24.5\nFixed in: 7.26.10, 8.0.0-alpha.17\nSeverity: MEDIUM\nFix: Upgrade @babel/runtime to 7.26.10, 8.0.0-alpha.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7382f4e949db04bb", "name": "CVE-2024-52809: @intlify/core-base 9.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52809: @intlify/core-base 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n has cross-site scripting vulnerability with prototype pollution\n\nvue-i18n  is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.\n\nPackage: @intlify/core-base\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade @intlify/core-base to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f6212dc4954467e", "name": "CVE-2025-53892: @intlify/core-base 9.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-53892: @intlify/core-base 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes\n\nVue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html. This may lead to a DOM-based XSS vulnerab\n\nPackage: @intlify/core-base\nInstalled: 9.13.1\nFixed in: 9.14.5, 10.0.8, 11.1.10\nSeverity: MEDIUM\nFix: Upgrade @intlify/core-base to 9.14.5, 10.0.8, 11.1.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6232fc13b77d82bb", "name": "CVE-2024-52810: @intlify/shared 9.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52810: @intlify/shared 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "@intlify/shared Prototype Pollution vulnerability\n\n@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) as the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the lib\n\nPackage: @intlify/shared\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade @intlify/shared to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e97a382ed73b802", "name": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain \n\nPackage: @protobufjs/utf8\nInstalled: 1.1.0\nFixed in: 1.1.1\nSeverity: MEDIUM\nFix: Upgrade @protobufjs/utf8 to 1.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2a54ea989f4db767", "name": "CVE-2025-69873: ajv 6.12.6 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-69873: ajv 6.12.6 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 6.12.6\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-035b7994f8f26f5f", "name": "GHSA-9q82-xgwf-vj6h: apollo-server-core 3.13.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-9q82-xgwf-vj6h: apollo-server-core 3.13.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention\n\n# Impact\n\nIn a Cross-Site Request Forgery attack, untrusted web content causes browsers to send authenticated requests to web servers which use cookies for authentication. While the web content is prevented from reading the request's response due to the Cross-Origin Request Sharing (CORS) protocol, an attacker may be able to cause side effects in the server (\"CSRF\" attack), or learn something about the response via timing analysis (\"XS-Search\" attack).\n\nApollo Server has a built-in feature which\n\nPackage: apollo-server-core\nInstalled: 3.13.0\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-556838da5eafe399", "name": "CVE-2024-39338: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-39338: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: axios: Server-Side Request Forgery\n\naxios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.7.4\nSeverity: HIGH\nFix: Upgrade axios to 1.7.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e53ffbb6622f9072", "name": "CVE-2025-27152: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27152: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests\n\naxios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if \u2060baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.8.2, 0.30.0\nSeverity: HIGH\nFix: Upgrade axios to 1.8.2, 0.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-74578cd6ba4c512d", "name": "CVE-2025-58754: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-58754: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios DoS via lack of data size check\n\nAxios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (`Buffer`/`Blob`) and returns a synthetic 200 response. This path ignores `maxContentLength` / `maxBodyLength` (which only protect HTTP responses), so an attacker can supply a very large `data:` URI a\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.12.0, 0.30.2\nSeverity: HIGH\nFix: Upgrade axios to 1.12.0, 0.30.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-34e4558d3c078c07", "name": "CVE-2026-25639: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-25639: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.13.5, 0.30.3\nSeverity: HIGH\nFix: Upgrade axios to 1.13.5, 0.30.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-db1bba77e5567a88", "name": "CVE-2026-42033: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42033: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: HTTP Transport Hijacking via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c8206852131fe6db", "name": "CVE-2026-42035: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42035: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Arbitrary HTTP header injection via prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type checking of the data payload, where if Object.prototype is polluted with getHeaders, append, pipe, on, once, and Symbol.toStringTag, Axios misidentifies any plain object payload as a FormData instance an\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1d0d934af9ef4742", "name": "CVE-2026-42043: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42043: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: NO_PROXY bypass via crafted URL\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1915bb304b2df785", "name": "CVE-2026-42264: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42264: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Prototype pollution allows information disclosure and request manipulation\n\nAxios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.2\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-858014d6850b81e9", "name": "CVE-2026-44486: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44486: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via HTTP redirects\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019 Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. T\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ab36798ab560bf4", "name": "CVE-2026-44487: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44487: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via redirect flows\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was in\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-670a2142ab536d5e", "name": "CVE-2026-44488: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44488: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service due to unenforced request and response size limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. This can cause resource exhaustion in server-side usag\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bb0d147883a54e42", "name": "CVE-2026-44494: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44494: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack \u2014 intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, whic\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93eae9a9be1fe156", "name": "CVE-2026-44495: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44495: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to prototype pollution vulnerability\n\nAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-p\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.2, 0.31.1\nSeverity: HIGH\nFix: Upgrade axios to 1.15.2, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0dcc16a006b5c97d", "name": "CVE-2026-44496: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44496: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e27403edc4234c0", "name": "CVE-2025-62718: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-62718: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This is\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61329ed2afb25393", "name": "CVE-2026-40175: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-40175: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Remote Code Execution via Prototype Pollution escalation\n\nAxios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.0, 0.31.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.0, 0.31.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-366947cc0f6851b7", "name": "CVE-2026-42034: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42034: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via oversized streamed uploads bypassing body limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ebe484f24f310fd7", "name": "CVE-2026-42036: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42036: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is used\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f130720a1f28b7fe", "name": "CVE-2026-42037: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42037: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type header\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\\r\\n) sequences. An attacker who controls the .type property of a Blob/File-like object (e.g., via a user-uploaded file in a Node.js proxy service) can inject arbitrary MIME part headers into the multipart form-data body. This bypa\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f605ce0bb2f97725", "name": "CVE-2026-42038: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42038: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure due to `no_proxy` bypass\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy() function does pure string matching \u2014 it does not resolve IP aliases or loopback equivalents. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a420180cd6f0fc49", "name": "CVE-2026-42039: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42039: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4e380e19f2f7ab3", "name": "CVE-2026-42041: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42041: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a9e189291225c298", "name": "CVE-2026-42042: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42042: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: XSRF token bypass leading to information disclosure\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy non-boolean value (via prototype pollution or misconfiguration), the same-origin check (isURLSameOrigin) is short-circuited, causing XSRF tokens to be sent to all request targets including cross-origin s\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba677091ab0c793d", "name": "CVE-2026-42044: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42044: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses \u2014 including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.2\nSeverity: MEDIUM\nFix: Upgrade axios to 1.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef56a36f194d9b1b", "name": "CVE-2026-44490: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44490: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure and denial of service due to prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values. (1) lib/utils.js line 406 builds merge()'s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket's own keys are copied into the mer\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.16.0, 0.32.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-634c3c21fabc60c5", "name": "GHSA-42h9-826w-cgv3: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-42h9-826w-cgv3: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Excessive recursion in formDataToJSON can cause denial of service\n\n## Summary\nAxios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.\n\nApplications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5ba7d03e8e399c9", "name": "GHSA-7q8q-rj6j-mhjq: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Nested axios option objects can consume polluted prototype values\n\n## Summary\n\nAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.\n\nThe top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound re\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a42a512d751498b", "name": "GHSA-jqh4-m9w3-8hp9: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`\n\n## Summary\n\naxios\u2019 fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: \"fetch\"` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.\n\nThis affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected.\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9697aa75a986abd", "name": "GHSA-mmx7-hfxf-jppx: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Prototype pollution gadgets can alter axios request construction\n\n## Summary\n\naxios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in the bodyless method aliases: `axios.get()`, `axios.delete()`, `axios.head()`, and `axios.options()` read inherited `data` before config normalization, causing attacker-controlled body data to be sent on requests that did not explicitly set a body.\n\nAdditional low-level paths affect consumers that \n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-004e946ecec65e3f", "name": "GHSA-pmv8-rq9r-6j72: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Axios: Deep formToJSON Key Recursion Can Cause Denial of Service\n\n## Summary\n\nAxios versions starting with `0.28.0` contain uncontrolled recursion in `formDataToJSON`, which is exposed as `axios.formToJSON()` and used internally when axios serialises `FormData` with `Content-Type: application/json`.\n\nIf an application passes attacker-controlled `FormData` field names to this functionality, a field name with thousands of nested bracket segments can exhaust the JavaScript call stack and cause denial of service for that request or, in applications without appropr\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-60a22ddd0e88750a", "name": "CVE-2026-42040: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-42040: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "axios: Axios: Incorrect null byte handling can lead to data integrity issues\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at line 21 that reverses the safe percent-encoding of null bytes. After encodeURIComponent('\\x00') correctly produces the safe sequence %00, the charMap entry '%00': '\\x00' converts it back to a raw null byte. Primary impact is limited because the standard axios request flow is not affected. This vulnerab\n\nPackage: axios\nInstalled: 1.7.0\nFixed in: 1.15.1, 0.31.1\nSeverity: LOW\nFix: Upgrade axios to 1.15.1, 0.31.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-959f7a8f194318de", "name": "CVE-2026-2739: bn.js 4.12.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2739: bn.js 4.12.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "bn.js: bn.js: Denial of Service via calling maskn(0)\n\nThis affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.\n\nPackage: bn.js\nInstalled: 4.12.0\nFixed in: 4.12.3, 5.2.3\nSeverity: MEDIUM\nFix: Upgrade bn.js to 4.12.3, 5.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25afec95b0279d56", "name": "CVE-2026-2739: bn.js 5.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2739: bn.js 5.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "bn.js: bn.js: Denial of Service via calling maskn(0)\n\nThis affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.\n\nPackage: bn.js\nInstalled: 5.2.1\nFixed in: 4.12.3, 5.2.3\nSeverity: MEDIUM\nFix: Upgrade bn.js to 4.12.3, 5.2.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c22fc7c8cb27b9ed", "name": "CVE-2024-45590: body-parser 1.20.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-45590: body-parser 1.20.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "body-parser: Denial of Service Vulnerability in body-parser\n\nbody-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.\n\nPackage: body-parser\nInstalled: 1.20.2\nFixed in: 1.20.3\nSeverity: HIGH\nFix: Upgrade body-parser to 1.20.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6acfb7291d8a5921", "name": "CVE-2026-12590: body-parser 1.20.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e031f71f0a778eee", "name": "CVE-2026-13149: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 1.1.11\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0743551610c20ebf", "name": "CVE-2026-33750: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33750: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.\n\nPackage: brace-expansion\nInstalled: 1.1.11\nFixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.5, 3.0.2, 2.0.3, 1.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0b7e3b0dac68fb04", "name": "CVE-2025-5889: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-5889: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: juliangruber brace-expansion index.js expand redos\n\nA vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 i\n\nPackage: brace-expansion\nInstalled: 1.1.11\nFixed in: 2.0.2, 1.1.12, 3.0.1, 4.0.1\nSeverity: LOW\nFix: Upgrade brace-expansion to 2.0.2, 1.1.12, 3.0.1, 4.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb409be30d2e8845", "name": "CVE-2026-13149: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 2.0.1\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-73a9a7f4b72f158b", "name": "CVE-2026-33750: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33750: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.\n\nPackage: brace-expansion\nInstalled: 2.0.1\nFixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.5, 3.0.2, 2.0.3, 1.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e338abbe8726a576", "name": "CVE-2025-5889: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-5889: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "brace-expansion: juliangruber brace-expansion index.js expand redos\n\nA vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 i\n\nPackage: brace-expansion\nInstalled: 2.0.1\nFixed in: 2.0.2, 1.1.12, 3.0.1, 4.0.1\nSeverity: LOW\nFix: Upgrade brace-expansion to 2.0.2, 1.1.12, 3.0.1, 4.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06a92ce6dc1ed278", "name": "CVE-2024-4068: braces 2.3.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4068: braces 2.3.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "braces: fails to limit the number of characters it can handle\n\nThe NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends \"imbalanced braces\" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.\n\nPackage: braces\nInstalled: 2.3.2\nFixed in: 3.0.3\nSeverity: HIGH\nFix: Upgrade braces to 3.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4b2cd767e53ca073", "name": "CVE-2024-4068: braces 3.0.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4068: braces 3.0.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "braces: fails to limit the number of characters it can handle\n\nThe NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends \"imbalanced braces\" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.\n\nPackage: braces\nInstalled: 3.0.2\nFixed in: 3.0.3\nSeverity: HIGH\nFix: Upgrade braces to 3.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-418d4a5d97cc034e", "name": "CVE-2025-9287: cipher-base 1.0.4 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-9287: cipher-base 1.0.4 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cipher-base: Cipher-base hash manipulation\n\nImproper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.\n\nPackage: cipher-base\nInstalled: 1.0.4\nFixed in: 1.0.5\nSeverity: CRITICAL\nFix: Upgrade cipher-base to 1.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-0a232bf0ff77a9fd", "name": "CVE-2024-47764: cookie 0.6.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-47764: cookie 0.6.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cookie: cookie accepts cookie name, path, and domain with out of bounds characters\n\ncookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.\n\nPackage: cookie\nInstalled: 0.6.0\nFixed in: 0.7.0\nSeverity: LOW\nFix: Upgrade cookie to 0.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cbf7c92d8cbf747", "name": "CVE-2024-21538: cross-spawn 6.0.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-21538: cross-spawn 6.0.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cross-spawn: regular expression denial of service\n\nVersions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.\n\nPackage: cross-spawn\nInstalled: 6.0.5\nFixed in: 7.0.5, 6.0.6\nSeverity: HIGH\nFix: Upgrade cross-spawn to 7.0.5, 6.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ad7bf98f8378bc50", "name": "CVE-2024-21538: cross-spawn 7.0.3 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-21538: cross-spawn 7.0.3 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "cross-spawn: regular expression denial of service\n\nVersions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.\n\nPackage: cross-spawn\nInstalled: 7.0.3\nFixed in: 7.0.5, 6.0.6\nSeverity: HIGH\nFix: Upgrade cross-spawn to 7.0.5, 6.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f63871d5be5903a9", "name": "CVE-2026-53486: decompress 4.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53486: decompress 4.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction\n\nThe decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/\n\nPackage: decompress\nInstalled: 4.2.1\nFixed in: \u2014\nSeverity: CRITICAL\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-e8b9eed7385eae85", "name": "CVE-2025-57665: element-plus 2.7.3 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-57665: element-plus 2.7.3 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Element Plus Link component (el-link) implements insufficient input validation for the href attribute\n\nElement Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor elements without protocol validation, URL sanitization, or security headers. This allows attackers to inject malicious URLs using dangerous protocols (javascript:, data:, file:) or redirect users to external malicious sites. Wh\n\nPackage: element-plus\nInstalled: 2.7.3\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5e2039e7c2f94e4", "name": "GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)\n\n### Summary\n\nPrivate key can be extracted from ECDSA signature upon signing a malformed input (e.g. a string or a number), which could e.g. come from JSON network input\n\nNote that `elliptic` by design accepts hex strings as one of the possible input types\n\n### Details\n\nIn this code: https://github.com/indutny/elliptic/blob/3e46a48fdd2ef2f89593e5e058d85530578c9761/lib/elliptic/ec/index.js#L100-L107\n\n`msg` is a BN instance after conversion, but `nonce` is an array, and different BN instances could\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.6.1\nSeverity: CRITICAL\nFix: Upgrade elliptic to 6.6.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-c33d7b4293a7286c", "name": "CVE-2024-42459: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-42459: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: nodejs/elliptic: EDDSA signature malleability due to missing signature length check\n\nIn the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.7\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed2ab25aa296c14d", "name": "CVE-2024-42460: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-42460: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: nodejs/elliptic: ECDSA signature malleability due to missing checks\n\nIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.7\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a7715af16179dec", "name": "CVE-2024-42461: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-42461: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: nodejs/elliptic: ECDSA implementation malleability due to BER-enconded signatures being allowed\n\nIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.7\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7900233c77bc74f", "name": "CVE-2024-48948: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-48948: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: ECDSA signature verification error may reject legitimate transactions\n\nThe Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.6.0\nSeverity: LOW\nFix: Upgrade elliptic to 6.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef3580b49c25ac78", "name": "CVE-2024-48949: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-48949: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: Missing Validation in Elliptic's EDDSA Signature Verification\n\nThe verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits \"sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()\" validation.\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: 6.5.6\nSeverity: LOW\nFix: Upgrade elliptic to 6.5.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b585f2ada50e5cc", "name": "CVE-2025-14505: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-14505: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "elliptic: Key handling flaws in Elliptic\n\nThe ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of  RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure. This happens, because the byte-length of 'k' is incorrectly computed, resulting in its getting truncated during the computation. Legitimate transactions or communications will be broken as a result.\u00a0Furtherm\n\nPackage: elliptic\nInstalled: 6.5.5\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5eb39be20a7f3622", "name": "CVE-2024-43796: express 4.19.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43796: express 4.19.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "express: Improper Input Handling in Express Redirects\n\nExpress.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.\n\nPackage: express\nInstalled: 4.19.2\nFixed in: 4.20.0, 5.0.0\nSeverity: LOW\nFix: Upgrade express to 4.20.0, 5.0.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-467bce10e59a0743", "name": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.6 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.6 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets\n\n## Summary\n\nWhen an HTTP request follows a cross-domain redirect (301/302/307/308), `follow-redirects` only strips `authorization`, `proxy-authorization`, and `cookie` headers (matched by regex at index.js:469-476). Any custom authentication header (e.g., `X-API-Key`, `X-Auth-Token`, `Api-Key`, `Token`) is forwarded verbatim to the redirect target.\n\nSince `follow-redirects` is the redirect-handling dependency for **axios** (105K+ stars), this vulnerability affects the entire axios ecosystem.\n\n##\n\nPackage: follow-redirects\nInstalled: 1.15.6\nFixed in: 1.16.0\nSeverity: MEDIUM\nFix: Upgrade follow-redirects to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc3c8700f12de0ad", "name": "CVE-2025-7783: form-data 4.0.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-7783: form-data 4.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "form-data: Unsafe random function in form-data\n\nUse of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.\n\nThis issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.\n\nPackage: form-data\nInstalled: 4.0.0\nFixed in: 2.5.4, 3.0.4, 4.0.4\nSeverity: CRITICAL\nFix: Upgrade form-data to 2.5.4, 3.0.4, 4.0.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-e460781466755821", "name": "CVE-2026-12143: form-data 4.0.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.0\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-067e60b37b41449c", "name": "CVE-2022-25900: git-clone 0.1.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2022-25900: git-clone 0.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Command injection in git-clone\n\nAll versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.\n\nPackage: git-clone\nInstalled: 0.1.0\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4dfa2692e20940ae", "name": "CVE-2022-33987: got 8.3.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2022-33987: got 8.3.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets\n\nThe got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.\n\nPackage: got\nInstalled: 8.3.2\nFixed in: 12.1.0, 11.8.5\nSeverity: MEDIUM\nFix: Upgrade got to 12.1.0, 11.8.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5f756f682587b8a", "name": "CVE-2022-25881: http-cache-semantics 3.8.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2022-25881: http-cache-semantics 3.8.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability\n\nThis affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.\n\nPackage: http-cache-semantics\nInstalled: 3.8.1\nFixed in: 4.1.1\nSeverity: HIGH\nFix: Upgrade http-cache-semantics to 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c7f388699d73ca7", "name": "CVE-2026-48038: joi 17.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-48038: joi 17.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "joi: joi: Denial of Service via uncaught RangeError on deeply nested input through recursive link() schemas\n\njoi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supplied JSON or object input with recursive link() schemas. When validate() is called without try/catch in a request handler, deeply nested input can trigger an unhandled RangeError and potentially crash the process; lower-impact paths using validateAsync() or try/catch produce a RangeError instead of a structur\n\nPackage: joi\nInstalled: 17.13.1\nFixed in: 18.2.1, 17.13.4\nSeverity: MEDIUM\nFix: Upgrade joi to 18.2.1, 17.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a7f5b7b8c970555", "name": "CVE-2026-59869: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 3.14.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c2fcb6067e24ed3f", "name": "CVE-2025-64718: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-64718: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml prototype pollution in merge\n\njs-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).\n\nPackage: js-yaml\nInstalled: 3.14.1\nFixed in: 4.1.1, 3.14.2\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.1.1, 3.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a422ddde33da1cae", "name": "CVE-2026-53550: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 3.14.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-99f92ac312dcccc4", "name": "CVE-2026-59869: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.0\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6807e87c4d44eff0", "name": "CVE-2025-64718: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-64718: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml prototype pollution in merge\n\njs-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).\n\nPackage: js-yaml\nInstalled: 4.1.0\nFixed in: 4.1.1, 3.14.2\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.1.1, 3.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6ab31fadec361b80", "name": "CVE-2026-53550: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.0\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7e3874b726441b54", "name": "CVE-2024-52011: launch-editor 2.6.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52011: launch-editor 2.6.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.\n\nPackage: launch-editor\nInstalled: 2.6.1\nFixed in: 2.9.0\nSeverity: HIGH\nFix: Upgrade launch-editor to 2.9.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d9b00b53939d81cd", "name": "CVE-2026-53632: launch-editor 2.6.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53632: launch-editor 2.6.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: launch-editor\nInstalled: 2.6.1\nFixed in: 2.14.1\nSeverity: MEDIUM\nFix: Upgrade launch-editor to 2.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-08e1960dee695ba2", "name": "CVE-2026-4800: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fd1141aadca181b3", "name": "CVE-2025-13465: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e4c4ca61e123053a", "name": "CVE-2026-2950: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6faecbfe0f4a3ec2", "name": "CVE-2026-4800: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3f89bf0191d18f18", "name": "CVE-2025-13465: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc1fc60b6261dd0b", "name": "CVE-2026-2950: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b2e05ead1e0a3af6", "name": "CVE-2024-4067: micromatch 3.1.10 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4067: micromatch 3.1.10 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "micromatch: vulnerable to Regular Expression Denial of Service\n\nThe NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged \n\nPackage: micromatch\nInstalled: 3.1.10\nFixed in: 4.0.8\nSeverity: MEDIUM\nFix: Upgrade micromatch to 4.0.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-44f1e4d00c533930", "name": "CVE-2024-4067: micromatch 4.0.5 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4067: micromatch 4.0.5 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "micromatch: vulnerable to Regular Expression Denial of Service\n\nThe NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged \n\nPackage: micromatch\nInstalled: 4.0.5\nFixed in: 4.0.8\nSeverity: MEDIUM\nFix: Upgrade micromatch to 4.0.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0b97a9287eedcd99", "name": "CVE-2026-26996: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 3.1.2\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4aa3a8a3c29f9b0b", "name": "CVE-2026-27903: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 3.1.2\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3d0f6f84303a97d", "name": "CVE-2026-27904: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 3.1.2\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-89e151cbdcfac4ac", "name": "CVE-2026-26996: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-39520f7f4587fa3b", "name": "CVE-2026-27903: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a2b466e60f48cd5d", "name": "CVE-2026-27904: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 5.1.6\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-250abafcdd7a7048", "name": "CVE-2024-55565: nanoid 2.1.11 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-55565: nanoid 2.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nanoid: nanoid mishandles non-integer values\n\nnanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.\n\nPackage: nanoid\nInstalled: 2.1.11\nFixed in: 5.0.9, 3.3.8\nSeverity: MEDIUM\nFix: Upgrade nanoid to 5.0.9, 3.3.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-370748266a09a7ab", "name": "CVE-2024-55565: nanoid 3.3.7 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-55565: nanoid 3.3.7 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nanoid: nanoid mishandles non-integer values\n\nnanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.\n\nPackage: nanoid\nInstalled: 3.3.7\nFixed in: 5.0.9, 3.3.8\nSeverity: MEDIUM\nFix: Upgrade nanoid to 5.0.9, 3.3.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16bff9f079a3b2cc", "name": "CVE-2025-25975: parse-git-config 3.0.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-25975: parse-git-config 3.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "parse-git-config: Prototype Pollution Vulneralbility in parse-git-config\n\nAn issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function\n\nPackage: parse-git-config\nInstalled: 3.0.0\nFixed in: \u2014\nSeverity: HIGH\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d3e037ec0bf00072", "name": "CVE-2024-45296: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-45296: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: Backtracking regular expressions cause ReDoS\n\npath-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1\n\nPackage: path-to-regexp\nInstalled: 0.1.7\nFixed in: 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ae847b7babf71822", "name": "CVE-2024-52798: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52798: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x\n\npath-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.\n\nPackage: path-to-regexp\nInstalled: 0.1.7\nFixed in: 0.1.12\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c310bb690eb1a9d5", "name": "CVE-2026-4867: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-4867: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters\n\nImpact:\n\nA bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or more, the generated lookahead does not block single separator characters, so capture groups overlap and cause catastrophic backtracking.\n\nPatches:\n\nUpgrade to path-to-regexp@0.1.13\n\n\n\nPackage: path-to-regexp\nInstalled: 0.1.7\nFixed in: 0.1.13\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 0.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6361044321b3b5f5", "name": "CVE-2025-6545: pbkdf2 3.1.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-6545: pbkdf2 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "pbkdf2: pbkdf2 silently returns predictable key material\n\nImproper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js.\n\nThis issue affects pbkdf2: from 3.0.10 through 3.1.2.\n\nPackage: pbkdf2\nInstalled: 3.1.2\nFixed in: 3.1.3\nSeverity: CRITICAL\nFix: Upgrade pbkdf2 to 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-058c40d32441ba28", "name": "CVE-2025-6547: pbkdf2 3.1.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-6547: pbkdf2 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "pbkdf2: pbkdf2 silently returns static keys\n\nImproper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.\n\nPackage: pbkdf2\nInstalled: 3.1.2\nFixed in: 3.1.3\nSeverity: CRITICAL\nFix: Upgrade pbkdf2 to 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-43752afd4a9c7e66", "name": "CVE-2024-4367: pdfjs-dist 2.6.347 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4367: pdfjs-dist 2.6.347 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Mozilla: Arbitrary JavaScript execution in PDF.js\n\nA type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.\n\nPackage: pdfjs-dist\nInstalled: 2.6.347\nFixed in: 4.2.67\nSeverity: HIGH\nFix: Upgrade pdfjs-dist to 4.2.67"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76fa9d930a700c54", "name": "CVE-2024-4367: pdfjs-dist 3.5.141 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-4367: pdfjs-dist 3.5.141 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Mozilla: Arbitrary JavaScript execution in PDF.js\n\nA type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.\n\nPackage: pdfjs-dist\nInstalled: 3.5.141\nFixed in: 4.2.67\nSeverity: HIGH\nFix: Upgrade pdfjs-dist to 4.2.67"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dc454d1512caa955", "name": "CVE-2026-33671: picomatch 2.3.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1592c702e7685c8c", "name": "CVE-2026-33672: picomatch 2.3.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f81ee1e159514aa", "name": "CVE-2026-41305: postcss 8.4.38 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.38 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.38\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b3249c1232669ad", "name": "CVE-2024-53382: prismjs 1.29.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-53382: prismjs 1.29.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin\n\nPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.\n\nPackage: prismjs\nInstalled: 1.29.0\nFixed in: 1.30.0\nSeverity: MEDIUM\nFix: Upgrade prismjs to 1.30.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d79c22ca4aa4195d", "name": "CVE-2025-15284: qs 6.11.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-15284: qs 6.11.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs: Denial of Service via improper input validation in array parsing\n\nImproper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummary\n\nThe arrayLimit\u00a0option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit\u00a0should apply uniformly across all array notations.\n\nNote:\u00a0The default parameterLimit\u00a0of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la\n\nPackage: qs\nInstalled: 6.11.0\nFixed in: 6.14.1\nSeverity: MEDIUM\nFix: Upgrade qs to 6.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cdf06edd6a91ac09", "name": "CVE-2026-2391: qs 6.11.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.11.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.11.0\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c029abf160b1d926", "name": "CVE-2025-15284: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-15284: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs: Denial of Service via improper input validation in array parsing\n\nImproper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummary\n\nThe arrayLimit\u00a0option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit\u00a0should apply uniformly across all array notations.\n\nNote:\u00a0The default parameterLimit\u00a0of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la\n\nPackage: qs\nInstalled: 6.12.1\nFixed in: 6.14.1\nSeverity: MEDIUM\nFix: Upgrade qs to 6.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98c6b9034b24a418", "name": "CVE-2026-8723: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.12.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e962d86de05cb60", "name": "CVE-2026-2391: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.12.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e1c629f230ccdcb", "name": "CVE-2024-43799: send 0.18.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43799: send 0.18.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "send: Code Execution Vulnerability in Send Library\n\nSend is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.\n\nPackage: send\nInstalled: 0.18.0\nFixed in: 0.19.0\nSeverity: LOW\nFix: Upgrade send to 0.19.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65d441ec7c27b309", "name": "GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()\n\n### Impact\n\nThe serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660.\n\nWhile `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A similar issue exists in `Date.prototype.toISOString()`.\n\nIf an attacker can control the input object passed to `serialize()`, they can inject malicious JavaScript via the flags property of a RegExp object. When the serialize\n\nPackage: serialize-javascript\nInstalled: 4.0.0\nFixed in: 7.0.3\nSeverity: HIGH\nFix: Upgrade serialize-javascript to 7.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bdb36b2a3a4e8f64", "name": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()\n\n### Impact\n\nThe serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660.\n\nWhile `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A similar issue exists in `Date.prototype.toISOString()`.\n\nIf an attacker can control the input object passed to `serialize()`, they can inject malicious JavaScript via the flags property of a RegExp object. When the serialize\n\nPackage: serialize-javascript\nInstalled: 6.0.2\nFixed in: 7.0.3\nSeverity: HIGH\nFix: Upgrade serialize-javascript to 7.0.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f1bd69cf8319d1f", "name": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization\n\nSerialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted \"array-like\" object (an object that inherits from Array.prototype but has a very large length property), the process enters an intensive loop that consumes 100% CPU and hangs indefinitely. This issue has been patched in version 7.0.5.\n\nPackage: serialize-javascript\nInstalled: 6.0.2\nFixed in: 7.0.5\nSeverity: MEDIUM\nFix: Upgrade serialize-javascript to 7.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a24dcbd31340cccd", "name": "CVE-2024-43800: serve-static 1.15.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43800: serve-static 1.15.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "serve-static: Improper Sanitization in serve-static\n\nserve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.\n\nPackage: serve-static\nInstalled: 1.15.0\nFixed in: 1.16.0, 2.1.0\nSeverity: LOW\nFix: Upgrade serve-static to 1.16.0, 2.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61a1e9e84b129cfb", "name": "CVE-2025-9288: sha.js 2.4.11 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-9288: sha.js 2.4.11 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "sha.js: Missing type checks leading to hash rewind and passing on crafted data\n\nImproper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.\n\nPackage: sha.js\nInstalled: 2.4.11\nFixed in: 2.4.12\nSeverity: CRITICAL\nFix: Upgrade sha.js to 2.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-fdd8532e36b4e4e5", "name": "CVE-2026-9277: shell-quote 1.8.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-9277: shell-quote 1.8.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators\n\nshell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\\n, \\r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is re\n\nPackage: shell-quote\nInstalled: 1.8.1\nFixed in: 1.8.4\nSeverity: CRITICAL\nFix: Upgrade shell-quote to 1.8.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-167a4f730d379a8b", "name": "CVE-2026-13311: shell-quote 1.8.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-13311: shell-quote 1.8.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing\n\nshell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled string to any code path that calls parse() (no shell metacharacters are required; plain space-separated words suffice) can block the single-threaded Node.js event loop for an exten\n\nPackage: shell-quote\nInstalled: 1.8.1\nFixed in: 1.9.0\nSeverity: HIGH\nFix: Upgrade shell-quote to 1.9.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-538dc6f071316881", "name": "CVE-2026-59873: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59873: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tar: node-tar: Denial of Service via crafted gzip bomb\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.19\nSeverity: CRITICAL\nFix: Upgrade tar to 7.5.19"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-6bb682832c15660a", "name": "CVE-2026-23745: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-23745: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives\n\nnode-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.3\nSeverity: HIGH\nFix: Upgrade tar to 7.5.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5f13fec4b265428", "name": "CVE-2026-23950: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-23950: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition\n\nnode-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has been tested), the library fails to lock colliding paths (e.g., `\u00df` and `ss`), allowing them to be processed in parallel. This bypasses the library's internal concurrency safeguards and permits Symlink\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.4\nSeverity: HIGH\nFix: Upgrade tar to 7.5.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2b4cf5b6ed31b696", "name": "CVE-2026-24842: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-24842: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check\n\nnode-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.7\nSeverity: HIGH\nFix: Upgrade tar to 7.5.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-af511a02c4ec1c40", "name": "CVE-2026-26960: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-26960: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation\n\nnode-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.8\nSeverity: HIGH\nFix: Upgrade tar to 7.5.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-11bb63a25ef9fb4c", "name": "CVE-2026-29786: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-29786: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: hardlink path traversal via drive-relative linkpath\n\nnode-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.10\nSeverity: HIGH\nFix: Upgrade tar to 7.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-90c90ac7d88e2a4c", "name": "CVE-2026-31802: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-31802: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tar: tar: File overwrite via drive-relative symlink traversal\n\nnode-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.11\nSeverity: HIGH\nFix: Upgrade tar to 7.5.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3aceeb2b5e26f0f8", "name": "CVE-2026-59874: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59874: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tar: Node-tar: Denial of Service via malformed tar archive header\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.18\nSeverity: HIGH\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7f8290d198c79d2", "name": "CVE-2026-53655: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-53655: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: File smuggling due to inconsistent tar archive parsing\n\nnode-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the by\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.16\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d213454d3f39e1c1", "name": "CVE-2026-59871: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59871: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service due to incorrect PAX path handling\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.18\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2694ea824638a8bd", "name": "CVE-2026-59875: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-59875: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata\n\nnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.\n\nPackage: tar\nInstalled: 6.2.1\nFixed in: 7.5.17\nSeverity: MEDIUM\nFix: Upgrade tar to 7.5.17"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-41e433416f3f024e", "name": "CVE-2026-44705: tmp 0.0.33 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-44705: tmp 0.0.33 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tmp is a temporary file and directory creator for node.js. Prior to 0. ...\n\ntmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal sequences (e.g., ../) or path separators in these parameters, attackers can cause files to be created outside the configured temporary base directory at attacker-controlled locations with the privileges of the running pr\n\nPackage: tmp\nInstalled: 0.0.33\nFixed in: 0.2.6\nSeverity: HIGH\nFix: Upgrade tmp to 0.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f052bbdcc44e4d20", "name": "CVE-2025-54798: tmp 0.0.33 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-54798: tmp 0.0.33 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "tmp: tmp Symbolic Link Write Vulnerability\n\ntmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.\n\nPackage: tmp\nInstalled: 0.0.33\nFixed in: 0.2.4\nSeverity: LOW\nFix: Upgrade tmp to 0.2.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4948c080f294ecc4", "name": "CVE-2026-41907: uuid 8.3.2 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 8.3.2\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89c1e2d55d362bcf", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a6c5896611da0c66", "name": "CVE-2024-9506: vue 2.7.16 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-9506: vue 2.7.16 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue: Regular Expression Denial of Service (ReDoS)\n\nImproper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.\n\nPackage: vue\nInstalled: 2.7.16\nFixed in: 3.0.0-alpha.0\nSeverity: LOW\nFix: Upgrade vue to 3.0.0-alpha.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-705590938c9fa6d8", "name": "CVE-2025-27597: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-27597: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "Vue I18n Allows Prototype Pollution in `handleFlatJson`\n\nVue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the li\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.3, 10.0.6, 11.1.2\nSeverity: HIGH\nFix: Upgrade vue-i18n to 9.14.3, 10.0.6, 11.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4129bad75d05a56e", "name": "CVE-2024-52809: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52809: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n has cross-site scripting vulnerability with prototype pollution\n\nvue-i18n  is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade vue-i18n to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15150ddd6b3a3e19", "name": "CVE-2024-52810: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-52810: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "@intlify/shared Prototype Pollution vulnerability\n\n@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) as the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the lib\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.2, 10.0.5\nSeverity: MEDIUM\nFix: Upgrade vue-i18n to 9.14.2, 10.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a11ba25b8be738a2", "name": "CVE-2025-53892: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-53892: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes\n\nVue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html. This may lead to a DOM-based XSS vulnerab\n\nPackage: vue-i18n\nInstalled: 9.13.1\nFixed in: 9.14.5, 10.0.8, 11.1.10\nSeverity: MEDIUM\nFix: Upgrade vue-i18n to 9.14.5, 10.0.8, 11.1.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0db9d2c9e113a6a", "name": "CVE-2024-43788: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-43788: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule\n\nWebpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have discovered a DOM Clobbering vulnerability in Webpack\u2019s `AutoPublicPathRuntimeModule`. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name`\n\nPackage: webpack\nInstalled: 5.91.0\nFixed in: 5.94.0\nSeverity: MEDIUM\nFix: Upgrade webpack to 5.94.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa06edcb5abdc111", "name": "CVE-2025-68157: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-68157: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects\n\nWebpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack\u2019s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build mac\n\nPackage: webpack\nInstalled: 5.91.0\nFixed in: 5.104.0\nSeverity: LOW\nFix: Upgrade webpack to 5.104.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b58dc387b73025f6", "name": "CVE-2025-68458: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2025-68458: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior\n\nWebpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack\u2019s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/ho\n\nPackage: webpack\nInstalled: 5.91.0\nFixed in: 5.104.1\nSeverity: LOW\nFix: Upgrade webpack to 5.104.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b860885f46e9aae7", "name": "CVE-2024-37890: ws 7.5.9 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2024-37890: ws 7.5.9 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "nodejs-ws: denial of service when handling a request with many HTTP headers\n\nws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in ws@8.17.1 (e55e510) and backported to ws@7.5.10 (22c2876), ws@6.2.3 (eeb76d3), and ws@5.2.4 (4abd8f6). In vulnerable versions of ws, the issue can be mitigated in the following ways: 1. Reduce the maximum allowed length of the request headers using the --max-http-header-size=size and/or th\n\nPackage: ws\nInstalled: 7.5.9\nFixed in: 5.2.4, 6.2.3, 7.5.10, 8.17.1\nSeverity: HIGH\nFix: Upgrade ws to 5.2.4, 6.2.3, 7.5.10, 8.17.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a243ec813c793d56", "name": "CVE-2026-48779: ws 7.5.9 \u2014 archive/ktransformers/website/package-lock.json", "shortDescription": {"text": "CVE-2026-48779: ws 7.5.9 \u2014 archive/ktransformers/website/package-lock.json"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 7.5.9\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ee598ca43700591", "name": "CVE-2025-3000: torch 2.9.1 \u2014 kt-kernel/requirements.txt", "shortDescription": {"text": "CVE-2025-3000: torch 2.9.1 \u2014 kt-kernel/requirements.txt"}, "fullDescription": {"text": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...\n\nA vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.9.1\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade torch to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a080ae058f069d02", "name": "CVE-2025-3001: torch 2.9.1 \u2014 kt-kernel/requirements.txt", "shortDescription": {"text": "CVE-2025-3001: torch 2.9.1 \u2014 kt-kernel/requirements.txt"}, "fullDescription": {"text": "A vulnerability classified as critical was found in PyTorch 2.6.0. Thi ...\n\nA vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.\n\nPackage: torch\nInstalled: 2.9.1\nFixed in: 2.10.0\nSeverity: LOW\nFix: Upgrade torch to 2.10.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-38ac2599b07e36d6", "name": "DS-0002: Image user should not be 'root' \u2014 archive/.devcontainer/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/.devcontainer/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: archive/.devcontainer/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4ffa53f2e58b1568", "name": "DS-0026: No HEALTHCHECK defined \u2014 archive/.devcontainer/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/.devcontainer/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: archive/.devcontainer/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-259523e79aab68f6", "name": "DS-0002: Image user should not be 'root' \u2014 archive/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: archive/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1a502253fb1443b", "name": "DS-0017: 'RUN <package-manager> update' instruction alone \u2014 archive/Dockerfile", "shortDescription": {"text": "DS-0017: 'RUN <package-manager> update' instruction alone \u2014 archive/Dockerfile"}, "fullDescription": {"text": "'RUN <package-manager> update' instruction alone\n\nThe instruction 'RUN <package-manager> update' should always be followed by '<package-manager> install' in the same RUN statement.\n\nRule: DS-0017\nSeverity: HIGH\nTarget: archive/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-42919ec3ef201587", "name": "DS-0026: No HEALTHCHECK defined \u2014 archive/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: archive/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65e1ffe71dc8a797", "name": "DS-0002: Image user should not be 'root' \u2014 archive/Dockerfile.xpu", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/Dockerfile.xpu"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: archive/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4d0c266c5bbb06b", "name": "DS-0013: 'RUN cd ...' to change directory \u2014 archive/Dockerfile.xpu", "shortDescription": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 archive/Dockerfile.xpu"}, "fullDescription": {"text": "'RUN cd ...' to change directory\n\nRUN should not be used to change directory: 'bash -c \"    source $CONDA_DIR/etc/profile.d/conda.sh &&     conda activate ktransformers &&     git clone https://github.com/kvcache-ai/ktransformers.git &&     cd ktransformers &&     git submodule update --init &&     sed -i 's/torch\\.xpu\\.is_available()/True/g' setup.py &&     bash install.sh --dev xpu \"'. Use 'WORKDIR' statement instead.\n\nRule: DS-0013\nSeverity: MEDIUM\nTarget: archive/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5380bc1a49bf5899", "name": "DS-0026: No HEALTHCHECK defined \u2014 archive/Dockerfile.xpu", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/Dockerfile.xpu"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: archive/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02009d509ce3a631", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 archive/Dockerfile.xpu", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 archive/Dockerfile.xpu"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y     wget     curl     bash     git     vim     ca-certificates     binutils     cmake     g++     && rm -rf /var/lib/apt/lists/*'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: archive/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e74b7ffc67c4fc0d", "name": "DS-0002: Image user should not be 'root' \u2014 archive/kt-sft/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/kt-sft/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: archive/kt-sft/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a728d3fea5697f77", "name": "DS-0017: 'RUN <package-manager> update' instruction alone \u2014 archive/kt-sft/Dockerfile", "shortDescription": {"text": "DS-0017: 'RUN <package-manager> update' instruction alone \u2014 archive/kt-sft/Dockerfile"}, "fullDescription": {"text": "'RUN <package-manager> update' instruction alone\n\nThe instruction 'RUN <package-manager> update' should always be followed by '<package-manager> install' in the same RUN statement.\n\nRule: DS-0017\nSeverity: HIGH\nTarget: archive/kt-sft/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9da7bf9c8c5d0217", "name": "DS-0026: No HEALTHCHECK defined \u2014 archive/kt-sft/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/kt-sft/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: archive/kt-sft/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61186b19d7d38d3b", "name": "DS-0002: Image user should not be 'root' \u2014 archive/kt-sft/Dockerfile.xpu", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/kt-sft/Dockerfile.xpu"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: archive/kt-sft/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1bd7ec4c3bd6c06a", "name": "DS-0013: 'RUN cd ...' to change directory \u2014 archive/kt-sft/Dockerfile.xpu", "shortDescription": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 archive/kt-sft/Dockerfile.xpu"}, "fullDescription": {"text": "'RUN cd ...' to change directory\n\nRUN should not be used to change directory: 'bash -c \"    source $CONDA_DIR/etc/profile.d/conda.sh &&     conda activate ktransformers &&     git clone https://github.com/kvcache-ai/ktransformers.git &&     cd ktransformers &&     git submodule update --init &&     sed -i 's/torch\\.xpu\\.is_available()/True/g' setup.py &&     bash install.sh --dev xpu \"'. Use 'WORKDIR' statement instead.\n\nRule: DS-0013\nSeverity: MEDIUM\nTarget: archive/kt-sft/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aff6d2a52d666ed5", "name": "DS-0026: No HEALTHCHECK defined \u2014 archive/kt-sft/Dockerfile.xpu", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/kt-sft/Dockerfile.xpu"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: archive/kt-sft/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f5ae22e92d075176", "name": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 archive/kt-sft/Dockerfile.xpu", "shortDescription": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 archive/kt-sft/Dockerfile.xpu"}, "fullDescription": {"text": "'apt-get' missing '--no-install-recommends'\n\n'--no-install-recommends' flag is missed: 'apt-get update && apt-get install -y     wget     curl     bash     git     vim     ca-certificates     binutils     cmake     g++     && rm -rf /var/lib/apt/lists/*'\n\nRule: DS-0029\nSeverity: HIGH\nTarget: archive/kt-sft/Dockerfile.xpu"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5233dbedff634681", "name": "DS-0002: Image user should not be 'root' \u2014 docker/Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 docker/Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: docker/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5fc0f19b37712e2", "name": "DS-0013: 'RUN cd ...' to change directory \u2014 docker/Dockerfile", "shortDescription": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 docker/Dockerfile"}, "fullDescription": {"text": "'RUN cd ...' to change directory\n\nRUN should not be used to change directory: '. /opt/miniconda3/etc/profile.d/conda.sh && conda activate serve     && cd /workspace/ktransformers/kt-kernel     && CPUINFER_BUILD_ALL_VARIANTS=1 ./install.sh build'. Use 'WORKDIR' statement instead.\n\nRule: DS-0013\nSeverity: MEDIUM\nTarget: docker/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10db0d8457b5093d", "name": "DS-0014: RUN using 'wget' and 'curl' \u2014 docker/Dockerfile", "shortDescription": {"text": "DS-0014: RUN using 'wget' and 'curl' \u2014 docker/Dockerfile"}, "fullDescription": {"text": "RUN using 'wget' and 'curl'\n\nShouldn't use both curl and wget\n\nRule: DS-0014\nSeverity: LOW\nTarget: docker/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-055d03fec591276a", "name": "DS-0026: No HEALTHCHECK defined \u2014 docker/Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 docker/Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: docker/Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47636e33caef255d", "name": "Dockerfile runs as root: docker/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: docker/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30a2e0d374af3108", "name": "Docker base image is tag-pinned but not digest-pinned: docker.1ms.run/nvidia/cuda:${CUDA_VERSION}-cudnn-devel-ubuntu24.0", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.1ms.run/nvidia/cuda:${CUDA_VERSION}-cudnn-devel-ubuntu24.04"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1728a10eb12732aa", "name": "Dockerfile runs as root: archive/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: archive/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e925d93358cd73c5", "name": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e29d3e75117b262", "name": "Dockerfile runs as root: archive/.devcontainer/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: archive/.devcontainer/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-605fced2016697c3", "name": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3395a3e45d370088", "name": "Dockerfile runs as root: archive/kt-sft/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: archive/kt-sft/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-60d8137c87d754a4", "name": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3fdef7be6d3a8c3", "name": "Insecure pattern 'exec_used' in ktransformers.py:17", "shortDescription": {"text": "Insecure pattern 'exec_used' in ktransformers.py:17"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40b2742ab36d1c93", "name": "Insecure pattern 'exec_used' in install.sh:73", "shortDescription": {"text": "Insecure pattern 'exec_used' in install.sh:73"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-57e993a9c63dae8e", "name": "Insecure pattern 'exec_used' in setup.py:12", "shortDescription": {"text": "Insecure pattern 'exec_used' in setup.py:12"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8c88088be40fe75", "name": "Insecure pattern 'exec_used' in docker/Dockerfile:270", "shortDescription": {"text": "Insecure pattern 'exec_used' in docker/Dockerfile:270"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6928e946cbe72734", "name": "Insecure pattern 'vue_v_html' in archive/kt-sft/ktransformers/website/src/components/chat/index.vue:40", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in archive/kt-sft/ktransformers/website/src/components/chat/index.vue:40"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-c29d4c4fce26c314", "name": "Insecure pattern 'document_write' in archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1", "shortDescription": {"text": "Insecure pattern 'document_write' in archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8484ea576eba0f3c", "name": "Insecure pattern 'direct_innerhtml_assignment' in archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-6164b92fc7497e2a", "name": "Insecure pattern 'cors_wildcard' in archive/kt-sft/ktransformers/server/main.py:38", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in archive/kt-sft/ktransformers/server/main.py:38"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9c0ae1661d9c873", "name": "Insecure pattern 'python_os_system' in archive/ktransformers/local_chat_test.py:131", "shortDescription": {"text": "Insecure pattern 'python_os_system' in archive/ktransformers/local_chat_test.py:131"}, "fullDescription": {"text": "Found a known-risky pattern (python_os_system). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-59409e24e4b07723", "name": "Insecure pattern 'python_os_system' in archive/ktransformers/local_chat.py:161", "shortDescription": {"text": "Insecure pattern 'python_os_system' in archive/ktransformers/local_chat.py:161"}, "fullDescription": {"text": "Found a known-risky pattern (python_os_system). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38444494b3af6247", "name": "Insecure pattern 'vue_v_html' in archive/ktransformers/website/src/components/chat/index.vue:40", "shortDescription": {"text": "Insecure pattern 'vue_v_html' in archive/ktransformers/website/src/components/chat/index.vue:40"}, "fullDescription": {"text": "Found a known-risky pattern (vue_v_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-4569d61f1b6a8553", "name": "Insecure pattern 'document_write' in archive/ktransformers/website/src/assets/iconfont/iconfont.js:1", "shortDescription": {"text": "Insecure pattern 'document_write' in archive/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16a973f714251f32", "name": "Insecure pattern 'direct_innerhtml_assignment' in archive/ktransformers/website/src/assets/iconfont/iconfont.js:1", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in archive/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-29468091f27dc786", "name": "Insecure pattern 'cors_wildcard' in archive/ktransformers/server/main.py:46", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in archive/ktransformers/server/main.py:46"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27afcd178c85ea26", "name": "Insecure pattern 'exec_used' in kt-kernel/setup.py:753", "shortDescription": {"text": "Insecure pattern 'exec_used' in kt-kernel/setup.py:753"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c69f045e2bd2f75c", "name": "Insecure pattern 'subprocess_shell_true' in kt-kernel/bench/compare_moe_performance.py:825", "shortDescription": {"text": "Insecure pattern 'subprocess_shell_true' in kt-kernel/bench/compare_moe_performance.py:825"}, "fullDescription": {"text": "Found a known-risky pattern (subprocess_shell_true). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c49da81e64ee1a07", "name": "Insecure pattern 'exec_used' in kt-kernel/python/__init__.py:80", "shortDescription": {"text": "Insecure pattern 'exec_used' in kt-kernel/python/__init__.py:80"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3770298887aaea9d", "name": "Insecure pattern 'exec_used' in kt-kernel/python/cli/__init__.py:18", "shortDescription": {"text": "Insecure pattern 'exec_used' in kt-kernel/python/cli/__init__.py:18"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-65116d685636e1dd", "name": "Insecure pattern 'exec_used' in .github/workflows/sync-sglang-submodule.yml:49", "shortDescription": {"text": "Insecure pattern 'exec_used' in .github/workflows/sync-sglang-submodule.yml:49"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f907e1362801558d", "name": "Insecure pattern 'exec_used' in .github/workflows/release-sglang-kt.yml:48", "shortDescription": {"text": "Insecure pattern 'exec_used' in .github/workflows/release-sglang-kt.yml:48"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8ef7f635008ae87d", "name": "Insecure pattern 'exec_used' in .github/workflows/release-pypi.yml:53", "shortDescription": {"text": "Insecure pattern 'exec_used' in .github/workflows/release-pypi.yml:53"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93afed2afb1d3d4a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e8f4cf73c7733319", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "peaceiris/actions-mdbook@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad6701f0a8405e22", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d7426ae81ce844e", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7eff9ff1697123c4", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e57343c0bee0f9c0", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e29504e3d50d6f3", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-211f7d3f743a10c1", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "peaceiris/actions-mdbook@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-350bc90d555d8dff", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-45a16c3ce361bbca", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9f974bb8fb136e5", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b126c22a1b9b8a46", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff3ea4f0d78df150", "name": "Very large file: archive/kt-sft/ktransformers/models/modeling_llama.py (1745 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_llama.py (1745 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc6cccd69c16d411", "name": "Very large file: archive/kt-sft/ktransformers/models/modeling_deepseek.py (1996 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_deepseek.py (1996 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-362ec68e5ef8b69c", "name": "Very large file: archive/kt-sft/ktransformers/models/modeling_deepseek_v3.py (1941 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_deepseek_v3.py (1941 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3351f648ad9ddfd9", "name": "Very large file: archive/kt-sft/ktransformers/models/modeling_mixtral.py (1735 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_mixtral.py (1735 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-097d89b14bdd5c89", "name": "Very large file: archive/kt-sft/ktransformers/models/modeling_qwen3_moe.py (1472 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_qwen3_moe.py (1472 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c06b68ead597fa8d", "name": "Very large file: archive/kt-sft/ktransformers/models/modeling_qwen2_moe.py (1766 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_qwen2_moe.py (1766 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c96f482afc258a73", "name": "Very large file: archive/kt-sft/ktransformers/operators/experts.py (2310 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/operators/experts.py (2310 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da40c71c75ff4ef8", "name": "Very large file: archive/kt-sft/ktransformers/operators/models.py (1756 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/operators/models.py (1756 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-515c5877d2bc6f8b", "name": "Very large file: archive/kt-sft/ktransformers/operators/attention.py (1083 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/operators/attention.py (1083 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21f1a82d4e6e41f2", "name": "Very large file: archive/kt-sft/ktransformers/sft/metrics_utils/constants.py (3464 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/sft/metrics_utils/constants.py (3464 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa79900433db2a11", "name": "Very large file: archive/kt-sft/ktransformers/sft/peft_utils/peft_model.py (1920 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/sft/peft_utils/peft_model.py (1920 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2bbea6dd490087c", "name": "Very large file: archive/kt-sft/ktransformers/sft/peft_utils/lora_layer.py (1161 lines)", "shortDescription": {"text": "Very large file: archive/kt-sft/ktransformers/sft/peft_utils/lora_layer.py (1161 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-180d1dbcf986a262", "name": "Very large file: archive/ktransformers/models/modeling_llama.py (1744 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_llama.py (1744 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28dc1c925d63a06b", "name": "Very large file: archive/ktransformers/models/modeling_deepseek.py (1992 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_deepseek.py (1992 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-632de071b11210ab", "name": "Very large file: archive/ktransformers/models/modeling_deepseek_v3.py (1955 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_deepseek_v3.py (1955 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c469391679bedd6d", "name": "Very large file: archive/ktransformers/models/modeling_mixtral.py (1734 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_mixtral.py (1734 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-538efa3b7a913d50", "name": "Very large file: archive/ktransformers/models/modeling_qwen3_next.py (1286 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_qwen3_next.py (1286 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3c61ffe56fa1322", "name": "Very large file: archive/ktransformers/models/modeling_qwen3_moe.py (1471 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_qwen3_moe.py (1471 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e74196b9fee42a6", "name": "Very large file: archive/ktransformers/models/modeling_smallthinker.py (1235 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_smallthinker.py (1235 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f50c9936c0e5fbd2", "name": "Very large file: archive/ktransformers/models/modeling_qwen2_moe.py (1765 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/models/modeling_qwen2_moe.py (1765 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b5a05c149bd227b", "name": "Very large file: archive/ktransformers/operators/experts.py (2096 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/operators/experts.py (2096 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad13f8e24d67385b", "name": "Very large file: archive/ktransformers/operators/models.py (1395 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/operators/models.py (1395 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c0024492cd56d7d", "name": "Very large file: archive/ktransformers/operators/ascend/ascend_attention.py (1263 lines)", "shortDescription": {"text": "Very large file: archive/ktransformers/operators/ascend/ascend_attention.py (1263 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c5581ce9223613b", "name": "Very large file: kt-kernel/scripts/convert_cpu_weights.py (1236 lines)", "shortDescription": {"text": "Very large file: kt-kernel/scripts/convert_cpu_weights.py (1236 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b41b3e4d8b4d6578", "name": "Very large file: kt-kernel/scripts/convert_cpu_weights_ds4.py (1396 lines)", "shortDescription": {"text": "Very large file: kt-kernel/scripts/convert_cpu_weights_ds4.py (1396 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a3ec4e091a72280", "name": "Very large file: kt-kernel/bench/compare_moe_performance.py (1370 lines)", "shortDescription": {"text": "Very large file: kt-kernel/bench/compare_moe_performance.py (1370 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7bfbd8cd64e199a9", "name": "Very large file: kt-kernel/examples/modeling_deepseek_v3.py (1937 lines)", "shortDescription": {"text": "Very large file: kt-kernel/examples/modeling_deepseek_v3.py (1937 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fb23bfce5484b41", "name": "Very large file: kt-kernel/python/cli/i18n.py (1345 lines)", "shortDescription": {"text": "Very large file: kt-kernel/python/cli/i18n.py (1345 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-382f3272db7c7827", "name": "Very large file: kt-kernel/python/cli/commands/model.py (2810 lines)", "shortDescription": {"text": "Very large file: kt-kernel/python/cli/commands/model.py (2810 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9b4d93b2c9715b0", "name": "Very large file: kt-kernel/python/utils/loader.py (1349 lines)", "shortDescription": {"text": "Very large file: kt-kernel/python/utils/loader.py (1349 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63818d01d879149b", "name": "312 TODO/FIXME markers", "shortDescription": {"text": "312 TODO/FIXME markers"}, "fullDescription": {"text": "High count of TODO/FIXME/HACK markers \u2014 track them as issues so they're not forgotten."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 1393 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 59 placeholder/mock markers across 27 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc924c18fbe69d69", "name": "Network/subprocess call without timeout or try/except \u2014 archive/setup.py:81", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 archive/setup.py:81"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-fd5403f93bbdd080", "name": "Network/subprocess call without timeout or try/except \u2014 archive/kt-sft/setup.py:106", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 archive/kt-sft/setup.py:106"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-1cca08e5cc1a3321", "name": "Commented-code block (7 lines) in archive/kt-sft/withoutKT_PEFT.py:95", "shortDescription": {"text": "Commented-code block (7 lines) in archive/kt-sft/withoutKT_PEFT.py:95"}, "fullDescription": {"text": "7 of 7 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-68954f7ecb775321", "name": "Commented-code block (5 lines) in archive/kt-sft/merge_tensors/merge_safetensor_gguf.py:42", "shortDescription": {"text": "Commented-code block (5 lines) in archive/kt-sft/merge_tensors/merge_safetensor_gguf.py:42"}, "fullDescription": {"text": "5 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-f409b4d6702c46f2", "name": "Commented-code block (8 lines) in archive/kt-sft/ktransformers/local_chat.py:238", "shortDescription": {"text": "Commented-code block (8 lines) in archive/kt-sft/ktransformers/local_chat.py:238"}, "fullDescription": {"text": "8 of 8 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-233cb8a09137b632", "name": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/moe_test_module_old.py:37", "shortDescription": {"text": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/moe_test_module_old.py:37"}, "fullDescription": {"text": "6 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-93b12239c9c9b40b", "name": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/lora_test_module.py:106", "shortDescription": {"text": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/lora_test_module.py:106"}, "fullDescription": {"text": "4 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-9c7ea6687298ce63", "name": "Legacy-named symbol `deepseek_v2` in archive/kt-sft/ktransformers/models/configuration_deepseek.py:110", "shortDescription": {"text": "Legacy-named symbol `deepseek_v2` in archive/kt-sft/ktransformers/models/configuration_deepseek.py:110"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-633108877b12fc21", "name": "Commented-code block (16 lines) in archive/kt-sft/ktransformers/util/custom_gguf.py:715", "shortDescription": {"text": "Commented-code block (16 lines) in archive/kt-sft/ktransformers/util/custom_gguf.py:715"}, "fullDescription": {"text": "16 of 16 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-d915b9b2afb648f8", "name": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/gate.py:32", "shortDescription": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/gate.py:32"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a28e044e064c95ff", "name": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/operators/experts.py:643", "shortDescription": {"text": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/operators/experts.py:643"}, "fullDescription": {"text": "5 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-0d20c4178b684818", "name": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/experts.py:77", "shortDescription": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/experts.py:77"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5517967c9268c95", "name": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/linear.py:80", "shortDescription": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/linear.py:80"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eecf1254a792bb5b", "name": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/operators/RoPE.py:213", "shortDescription": {"text": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/operators/RoPE.py:213"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-a6520ad9062e9baa", "name": "Commented-code block (7 lines) in archive/kt-sft/ktransformers/operators/models.py:1570", "shortDescription": {"text": "Commented-code block (7 lines) in archive/kt-sft/ktransformers/operators/models.py:1570"}, "fullDescription": {"text": "5 of 7 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-c7c0b4f7adaf0051", "name": "Commented-code block (13 lines) in archive/kt-sft/ktransformers/sft/flops_utils/lora_test_utils.py:142", "shortDescription": {"text": "Commented-code block (13 lines) in archive/kt-sft/ktransformers/sft/flops_utils/lora_test_utils.py:142"}, "fullDescription": {"text": "13 of 13 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-0c14025ad5530cb5", "name": "Commented-code block (10 lines) in archive/kt-sft/ktransformers/sft/peft_utils/lora_model.py:415", "shortDescription": {"text": "Commented-code block (10 lines) in archive/kt-sft/ktransformers/sft/peft_utils/lora_model.py:415"}, "fullDescription": {"text": "7 of 10 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-0d35448c24c1cad6", "name": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/kt-sft/ktransformers/server/balance_serve/inference/model_r", "shortDescription": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/kt-sft/ktransformers/server/balance_serve/inference/model_runner.py:29"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b10bedc69f284652", "name": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state", "shortDescription": {"text": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:241"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-6878c6c2a0e083f9", "name": "Stub function `inplace_all_reduce_fake` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_ser", "shortDescription": {"text": "Stub function `inplace_all_reduce_fake` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:108"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a231b6598cdfd7ab", "name": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serv", "shortDescription": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/frequency_penalty.py:53"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e1921deb923ca57", "name": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serv", "shortDescription": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/presence_penalty.py:53"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fcc87f50808740b5", "name": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serv", "shortDescription": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/min_new_tokens.py:81"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0228540b431a56e5", "name": "Stub function `get_interface` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/backend/interfaces/ex", "shortDescription": {"text": "Stub function `get_interface` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/backend/interfaces/exllamav2.py:18"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dda2a71d1087876e", "name": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/kt-sft/ktransformers/server/backend/interfaces/balance_serv", "shortDescription": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py:24"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-277cbf993e5614c4", "name": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/server/backend/interfaces/transformers.py:189", "shortDescription": {"text": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/server/backend/interfaces/transformers.py:189"}, "fullDescription": {"text": "4 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-4857a7314e813b11", "name": "Legacy-named symbol `model_copy` in archive/kt-sft/ktransformers/server/schemas/assistants/assistants.py:164", "shortDescription": {"text": "Legacy-named symbol `model_copy` in archive/kt-sft/ktransformers/server/schemas/assistants/assistants.py:164"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-169dbc860b62ca2d", "name": "Legacy-named symbol `deepseek_v2` in archive/kt-sft/ktransformers/configs/model_config/configuration_deepseek.py:112", "shortDescription": {"text": "Legacy-named symbol `deepseek_v2` in archive/kt-sft/ktransformers/configs/model_config/configuration_deepseek.py:112"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ae25c9c15c87cbc", "name": "Commented-code block (5 lines) in archive/merge_tensors/merge_safetensor_gguf.py:42", "shortDescription": {"text": "Commented-code block (5 lines) in archive/merge_tensors/merge_safetensor_gguf.py:42"}, "fullDescription": {"text": "5 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-be356b926917af8d", "name": "Legacy-named symbol `deepseek_v2` in archive/ktransformers/models/configuration_deepseek.py:110", "shortDescription": {"text": "Legacy-named symbol `deepseek_v2` in archive/ktransformers/models/configuration_deepseek.py:110"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c3f85de074ee86d", "name": "Commented-code block (5 lines) in archive/ktransformers/models/modeling_qwen3_moe.py:208", "shortDescription": {"text": "Commented-code block (5 lines) in archive/ktransformers/models/modeling_qwen3_moe.py:208"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-58a983279476a924", "name": "Commented-code block (6 lines) in archive/ktransformers/models/modeling_smallthinker.py:983", "shortDescription": {"text": "Commented-code block (6 lines) in archive/ktransformers/models/modeling_smallthinker.py:983"}, "fullDescription": {"text": "6 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-99eb7ad2395ca9a4", "name": "Commented-code block (5 lines) in archive/ktransformers/util/utils.py:76", "shortDescription": {"text": "Commented-code block (5 lines) in archive/ktransformers/util/utils.py:76"}, "fullDescription": {"text": "5 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-abbfecfda35a231b", "name": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/gate.py:32", "shortDescription": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/gate.py:32"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-deabf0aaf67afb82", "name": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/experts.py:77", "shortDescription": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/experts.py:77"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-339b80d19b697d79", "name": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/linear.py:89", "shortDescription": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/linear.py:89"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d661054182fd27a5", "name": "Commented-code block (5 lines) in archive/ktransformers/operators/RoPE.py:214", "shortDescription": {"text": "Commented-code block (5 lines) in archive/ktransformers/operators/RoPE.py:214"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-e34140c672f70a9c", "name": "Stub function `load` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/ascend/ascend_linear.py:102", "shortDescription": {"text": "Stub function `load` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/ascend/ascend_linear.py:102"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a61bfa66fa7f81cb", "name": "Commented-code block (5 lines) in archive/ktransformers/server/utils/serve_profiling.py:17", "shortDescription": {"text": "Commented-code block (5 lines) in archive/ktransformers/server/utils/serve_profiling.py:17"}, "fullDescription": {"text": "5 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-33c80d115ac2a112", "name": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/ktransformers/server/balance_serve/inference/model_runner.p", "shortDescription": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/ktransformers/server/balance_serve/inference/model_runner.py:34"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cff5ae421135624e", "name": "Commented-code block (5 lines) in archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:241", "shortDescription": {"text": "Commented-code block (5 lines) in archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:241"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-349e003981fe1c86", "name": "Stub function `inplace_all_reduce_fake` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/infe", "shortDescription": {"text": "Stub function `inplace_all_reduce_fake` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:108"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa4b19d8179eeed5", "name": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/infer", "shortDescription": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/frequency_penalty.py:53"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ede51115d46ca57a", "name": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/infer", "shortDescription": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/presence_penalty.py:53"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4a29a4c5ebd0b72", "name": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/infer", "shortDescription": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/min_new_tokens.py:81"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1fd6874d532030d", "name": "Stub function `get_interface` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/backend/interfaces/exllamav2", "shortDescription": {"text": "Stub function `get_interface` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/backend/interfaces/exllamav2.py:18"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9593318b44281f97", "name": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/ktransformers/server/backend/interfaces/balance_serve.py:25", "shortDescription": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/ktransformers/server/backend/interfaces/balance_serve.py:25"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ae7a232b13195cc", "name": "Commented-code block (11 lines) in archive/ktransformers/server/backend/interfaces/transformers.py:199", "shortDescription": {"text": "Commented-code block (11 lines) in archive/ktransformers/server/backend/interfaces/transformers.py:199"}, "fullDescription": {"text": "7 of 11 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-8c70a85bc43bacde", "name": "Legacy-named symbol `model_copy` in archive/ktransformers/server/schemas/assistants/assistants.py:164", "shortDescription": {"text": "Legacy-named symbol `model_copy` in archive/ktransformers/server/schemas/assistants/assistants.py:164"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf05d94f17f527f6", "name": "Legacy-named symbol `env_backup` in kt-kernel/setup.py:302", "shortDescription": {"text": "Legacy-named symbol `env_backup` in kt-kernel/setup.py:302"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4919da0e66aecd28", "name": "Commented-code block (5 lines) in kt-kernel/setup.py:566", "shortDescription": {"text": "Commented-code block (5 lines) in kt-kernel/setup.py:566"}, "fullDescription": {"text": "5 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-a9e2c559561b24b2", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/setup.py:721", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/setup.py:721"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-51c1c7de7b60d363", "name": "Commented-code block (5 lines) in kt-kernel/scripts/check.py:69", "shortDescription": {"text": "Commented-code block (5 lines) in kt-kernel/scripts/check.py:69"}, "fullDescription": {"text": "5 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-3ec47686874e7b5f", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_k2_moe_amx.py:49", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_k2_moe_amx.py:49"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-de2e3e459cac3612", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_bf16_moe.py:52", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_bf16_moe.py:52"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-141ae60397c5e707", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_mla.py:78", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_mla.py:78"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-91c1a439f39dc332", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_write_buffer.py:57", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_write_buffer.py:57"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-765636b64d666518", "name": "Commented-code block (7 lines) in kt-kernel/bench/bench_moe_kml.py:38", "shortDescription": {"text": "Commented-code block (7 lines) in kt-kernel/bench/bench_moe_kml.py:38"}, "fullDescription": {"text": "7 of 7 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-62ca7b95c3482b81", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_kml.py:60", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_kml.py:60"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-fb5ab28bb63c12cc", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_fp8_perchannel_moe.py:52", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_fp8_perchannel_moe.py:52"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-e731547ce98d6147", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_k2_write_buffer.py:49", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_k2_write_buffer.py:49"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-c1b74deb4fb9dfdb", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_amx.py:101", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_amx.py:101"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-f8b1eccd391fbc43", "name": "Commented-code block (11 lines) in kt-kernel/bench/bench_moe.py:343", "shortDescription": {"text": "Commented-code block (11 lines) in kt-kernel/bench/bench_moe.py:343"}, "fullDescription": {"text": "10 of 11 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-6f514df5146c60df", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe.py:54", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe.py:54"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-6c8d87eeaa361549", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_amx_k.py:60", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_amx_k.py:60"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-21d2b47e39bf4114", "name": "Commented-code block (7 lines) in kt-kernel/bench/bench_moe_kernel.py:44", "shortDescription": {"text": "Commented-code block (7 lines) in kt-kernel/bench/bench_moe_kernel.py:44"}, "fullDescription": {"text": "7 of 7 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-72cb4694b013ba09", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_kernel.py:66", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_kernel.py:66"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-1d9fb9b1884f46b5", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_fp8_moe.py:53", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_fp8_moe.py:53"}, "fullDescription": {"text": "`subprocess.check_output(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-a27042c5d4cec608", "name": "Legacy-named symbol `_deep_copy` in kt-kernel/python/cli/config/settings.py:95", "shortDescription": {"text": "Legacy-named symbol `_deep_copy` in kt-kernel/python/cli/config/settings.py:95"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df3d4b4c5250b7b8", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/python/cli/commands/quant.py:368", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/python/cli/commands/quant.py:368"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-d7396b3f39864cf5", "name": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/python/cli/commands/config.py:115", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/python/cli/commands/config.py:115"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-2441aed68ba4c848", "name": "Legacy-named symbol `moe_analysis_v2` in kt-kernel/python/cli/utils/analyze_moe_model.py:67", "shortDescription": {"text": "Legacy-named symbol `moe_analysis_v2` in kt-kernel/python/cli/utils/analyze_moe_model.py:67"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\narchive/setup.py:80:get_musa_bare_metal_version, archive/kt-sft/setup.py:105:get_musa_bare_metal_version\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\narchive/setup.py:304:colored, archive/setup.py:337:colored, archive/kt-sft/setup.py:323:colored, archive/kt-sft/setup.py:356:colored\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9aa9133a808c09bc", "name": "FastAPI POST `chat_completion` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/endpoints/chat.p", "shortDescription": {"text": "FastAPI POST `chat_completion` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/endpoints/chat.py:135"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-094ac7c5b8dc1238", "name": "FastAPI POST `create_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:19", "shortDescription": {"text": "FastAPI POST `create_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:19"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-c42f5e846e9114eb", "name": "FastAPI POST `create_thread_and_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants", "shortDescription": {"text": "FastAPI POST `create_thread_and_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:39"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-6204a96c59e6d295", "name": "FastAPI POST `modify_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:66", "shortDescription": {"text": "FastAPI POST `modify_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:66"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-1849a0f4cbd50f39", "name": "FastAPI POST `submit_tool_outputs_to_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assis", "shortDescription": {"text": "FastAPI POST `submit_tool_outputs_to_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:75"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-85d091ae93b92c6d", "name": "FastAPI POST `cancel_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:80", "shortDescription": {"text": "FastAPI POST `cancel_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:80"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-d48b22ada310d46e", "name": "FastAPI POST `create_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads", "shortDescription": {"text": "FastAPI POST `create_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py:13"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-1414dc0137980c36", "name": "FastAPI POST `modify_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads", "shortDescription": {"text": "FastAPI POST `modify_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py:28"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-b4ca22a78bfc7028", "name": "FastAPI DELETE `delete_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threa", "shortDescription": {"text": "FastAPI DELETE `delete_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py:33"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-4e42fd4899470cbd", "name": "FastAPI POST `create_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messag", "shortDescription": {"text": "FastAPI POST `create_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:15"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-c528cb0d6a59c5d8", "name": "FastAPI POST `modify_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messag", "shortDescription": {"text": "FastAPI POST `modify_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:42"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-935518436fee785e", "name": "FastAPI DELETE `delete_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/mess", "shortDescription": {"text": "FastAPI DELETE `delete_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:48"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-b3ac7cd45500dacd", "name": "FastAPI POST `create_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assi", "shortDescription": {"text": "FastAPI POST `create_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:18"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-3a70091700950312", "name": "FastAPI POST `modify_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assi", "shortDescription": {"text": "FastAPI POST `modify_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:54"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-46bd6c0ff6840334", "name": "FastAPI DELETE `delete_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/as", "shortDescription": {"text": "FastAPI DELETE `delete_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:62"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-a99ca61d8f7b4256", "name": "FastAPI POST `create_completion` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/legacy/complet", "shortDescription": {"text": "FastAPI POST `create_completion` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/legacy/completions.py:14"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-fb7c2b97bbf78f81", "name": "FastAPI POST `generate` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:57", "shortDescription": {"text": "FastAPI POST `generate` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:57"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-aed755fe5d94a523", "name": "FastAPI POST `chat` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:139", "shortDescription": {"text": "FastAPI POST `chat` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:139"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-39193be4f29bdb19", "name": "FastAPI POST `show` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:266", "shortDescription": {"text": "FastAPI POST `show` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:266"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-ce68fcc5d5710992", "name": "FastAPI POST `chat_completion` without auth dependency \u2014 archive/ktransformers/server/api/openai/endpoints/chat.py:135", "shortDescription": {"text": "FastAPI POST `chat_completion` without auth dependency \u2014 archive/ktransformers/server/api/openai/endpoints/chat.py:135"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-c62b61293f1a95af", "name": "FastAPI POST `create_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:19", "shortDescription": {"text": "FastAPI POST `create_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:19"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-9878e623ca100be9", "name": "FastAPI POST `create_thread_and_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.p", "shortDescription": {"text": "FastAPI POST `create_thread_and_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:39"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-92daebe3c0df88d4", "name": "FastAPI POST `modify_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:66", "shortDescription": {"text": "FastAPI POST `modify_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:66"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-02e95e44e63621d2", "name": "FastAPI POST `submit_tool_outputs_to_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/r", "shortDescription": {"text": "FastAPI POST `submit_tool_outputs_to_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:75"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-d3e977626b1a5fb4", "name": "FastAPI POST `cancel_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:80", "shortDescription": {"text": "FastAPI POST `cancel_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:80"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-116aee81415df0be", "name": "FastAPI POST `create_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:13", "shortDescription": {"text": "FastAPI POST `create_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:13"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-f31453b764c6eab0", "name": "FastAPI POST `modify_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:28", "shortDescription": {"text": "FastAPI POST `modify_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:28"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-621caf26f336afc0", "name": "FastAPI DELETE `delete_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:3", "shortDescription": {"text": "FastAPI DELETE `delete_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:33"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-79f7ff081d6b9c03", "name": "FastAPI POST `create_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:1", "shortDescription": {"text": "FastAPI POST `create_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:15"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-820c27a62a2af71f", "name": "FastAPI POST `modify_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:4", "shortDescription": {"text": "FastAPI POST `modify_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:42"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-6bba0a534acc7790", "name": "FastAPI DELETE `delete_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py", "shortDescription": {"text": "FastAPI DELETE `delete_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:48"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-1547148a093d115c", "name": "FastAPI POST `create_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.", "shortDescription": {"text": "FastAPI POST `create_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.py:18"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-a4eaf23dd1de120a", "name": "FastAPI POST `modify_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.", "shortDescription": {"text": "FastAPI POST `modify_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.py:54"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-3d788b6c79bf86ef", "name": "FastAPI DELETE `delete_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistant", "shortDescription": {"text": "FastAPI DELETE `delete_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.py:62"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-c30e97f3864ba2fa", "name": "FastAPI POST `create_completion` without auth dependency \u2014 archive/ktransformers/server/api/openai/legacy/completions.py", "shortDescription": {"text": "FastAPI POST `create_completion` without auth dependency \u2014 archive/ktransformers/server/api/openai/legacy/completions.py:14"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-6f992371167dd70c", "name": "FastAPI POST `generate` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:57", "shortDescription": {"text": "FastAPI POST `generate` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:57"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-944ced08b475a5ce", "name": "FastAPI POST `chat` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:139", "shortDescription": {"text": "FastAPI POST `chat` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:139"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-63b3d658d1a19884", "name": "FastAPI POST `show` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:267", "shortDescription": {"text": "FastAPI POST `show` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:267"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-4565c1b5d8ea90ad", "name": "Vulnerable dependency vue 2.7.16: GHSA-5j4c-8p2g-v4jx", "shortDescription": {"text": "Vulnerable dependency vue 2.7.16: GHSA-5j4c-8p2g-v4jx"}, "fullDescription": {"text": "OSV.dev reports `vue` at version `2.7.16` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-5j4c-8p2g-v4jx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5j4c-8p2g-v4jx\nFix: upgrade `vue` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-52401540afdf487d", "name": "Vulnerable dependency axios 1.7.0: GHSA-35jp-ww65-95wh", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-35jp-ww65-95wh"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-35jp-ww65-95wh (aka CVE-2026-44494).\n\naxios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`\n\nAliases: CVE-2026-44494\nAdvisory: https://osv.dev/vulnerability/GHSA-35jp-ww65-95wh\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1260a9c0fb073bcb", "name": "Vulnerable dependency axios 1.7.0: GHSA-3g43-6gmg-66jw", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-3g43-6gmg-66jw"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-3g43-6gmg-66jw (aka CVE-2026-44495).\n\naxios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge\n\nAliases: CVE-2026-44495\nAdvisory: https://osv.dev/vulnerability/GHSA-3g43-6gmg-66jw\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0e13a129e5df3254", "name": "Vulnerable dependency axios 1.7.0: GHSA-3p68-rc4w-qgx5", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-3p68-rc4w-qgx5"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-3p68-rc4w-qgx5 (aka CVE-2025-62718).\n\nAxios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF\n\nAliases: CVE-2025-62718\nAdvisory: https://osv.dev/vulnerability/GHSA-3p68-rc4w-qgx5\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b703335c1160961", "name": "Vulnerable dependency axios 1.7.0: GHSA-3w6x-2g7m-8v23", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-3w6x-2g7m-8v23"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-3w6x-2g7m-8v23 (aka CVE-2026-42044).\n\nAxios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`\n\nAliases: CVE-2026-42044\nAdvisory: https://osv.dev/vulnerability/GHSA-3w6x-2g7m-8v23\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-790ef3e1ec01c689", "name": "Vulnerable dependency axios 1.7.0: GHSA-42h9-826w-cgv3", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-42h9-826w-cgv3"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-42h9-826w-cgv3.\n\nAxios: Excessive recursion in formDataToJSON can cause denial of service\n\nAdvisory: https://osv.dev/vulnerability/GHSA-42h9-826w-cgv3\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa62449923e5afc6", "name": "Vulnerable dependency axios 1.7.0: GHSA-43fc-jf86-j433", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-43fc-jf86-j433"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-43fc-jf86-j433 (aka CVE-2026-25639).\n\nAxios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig\n\nAliases: CVE-2026-25639\nAdvisory: https://osv.dev/vulnerability/GHSA-43fc-jf86-j433\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f5c05d45a740ed69", "name": "Vulnerable dependency axios 1.7.0: GHSA-445q-vr5w-6q77", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-445q-vr5w-6q77"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-445q-vr5w-6q77 (aka CVE-2026-42037).\n\nAxios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream\n\nAliases: CVE-2026-42037\nAdvisory: https://osv.dev/vulnerability/GHSA-445q-vr5w-6q77\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19ec582ed03cc970", "name": "Vulnerable dependency axios 1.7.0: GHSA-4hjh-wcwx-xvwj", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-4hjh-wcwx-xvwj"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-4hjh-wcwx-xvwj (aka CVE-2025-58754).\n\nAxios is vulnerable to DoS attack through lack of data size check\n\nAliases: CVE-2025-58754\nAdvisory: https://osv.dev/vulnerability/GHSA-4hjh-wcwx-xvwj\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4db23c0baefd87ac", "name": "Vulnerable dependency axios 1.7.0: GHSA-5c9x-8gcm-mpgx", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-5c9x-8gcm-mpgx"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-5c9x-8gcm-mpgx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5c9x-8gcm-mpgx\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6cbbacea8cc8d4b6", "name": "Vulnerable dependency axios 1.7.0: GHSA-62hf-57xw-28j9", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-62hf-57xw-28j9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-62hf-57xw-28j9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-62hf-57xw-28j9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-52cd910384888415", "name": "Vulnerable dependency axios 1.7.0: GHSA-6chq-wfr3-2hj9", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-6chq-wfr3-2hj9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-6chq-wfr3-2hj9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6chq-wfr3-2hj9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-645959c4353c262a", "name": "Vulnerable dependency axios 1.7.0: GHSA-777c-7fjr-54vf", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-777c-7fjr-54vf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-777c-7fjr-54vf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-777c-7fjr-54vf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5a21f319a417954", "name": "Vulnerable dependency axios 1.7.0: GHSA-7q8q-rj6j-mhjq", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-7q8q-rj6j-mhjq"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-7q8q-rj6j-mhjq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7q8q-rj6j-mhjq\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-257aaa1d249d75b2", "name": "Vulnerable dependency axios 1.7.0: GHSA-898c-q2cr-xwhg", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-898c-q2cr-xwhg"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-898c-q2cr-xwhg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-898c-q2cr-xwhg\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ab73eb57063c17c0", "name": "Vulnerable dependency axios 1.7.0: GHSA-8hc4-vh64-cxmj", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-8hc4-vh64-cxmj"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-8hc4-vh64-cxmj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8hc4-vh64-cxmj\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46c159653bd8e0d3", "name": "Vulnerable dependency axios 1.7.0: GHSA-fvcv-3m26-pcqx", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-fvcv-3m26-pcqx"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-fvcv-3m26-pcqx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fvcv-3m26-pcqx\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58c7dff9b6c4041d", "name": "Vulnerable dependency axios 1.7.0: GHSA-hfxv-24rg-xrqf", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-hfxv-24rg-xrqf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-hfxv-24rg-xrqf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hfxv-24rg-xrqf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b35a5575c0f5fd56", "name": "Vulnerable dependency axios 1.7.0: GHSA-j5f8-grm9-p9fc", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-j5f8-grm9-p9fc"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-j5f8-grm9-p9fc.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-j5f8-grm9-p9fc\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-054001df7101ba2e", "name": "Vulnerable dependency axios 1.7.0: GHSA-jqh4-m9w3-8hp9", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-jqh4-m9w3-8hp9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-jqh4-m9w3-8hp9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jqh4-m9w3-8hp9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-daa07a5d1e3d9e2d", "name": "Vulnerable dependency axios 1.7.0: GHSA-jr5f-v2jv-69x6", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-jr5f-v2jv-69x6"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-jr5f-v2jv-69x6.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jr5f-v2jv-69x6\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-78d0a66249a23e0a", "name": "Vulnerable dependency axios 1.7.0: GHSA-m7pr-hjqh-92cm", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-m7pr-hjqh-92cm"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-m7pr-hjqh-92cm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m7pr-hjqh-92cm\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc71b40fe89b7b68", "name": "Vulnerable dependency axios 1.7.0: GHSA-mmx7-hfxf-jppx", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-mmx7-hfxf-jppx"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-mmx7-hfxf-jppx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mmx7-hfxf-jppx\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e554c25cb3f12974", "name": "Vulnerable dependency axios 1.7.0: GHSA-p92q-9vqr-4j8v", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-p92q-9vqr-4j8v"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-p92q-9vqr-4j8v.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p92q-9vqr-4j8v\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8c10537472335f06", "name": "Vulnerable dependency axios 1.7.0: GHSA-pf86-5x62-jrwf", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-pf86-5x62-jrwf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-pf86-5x62-jrwf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pf86-5x62-jrwf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2dac33350324e89d", "name": "Vulnerable dependency axios 1.7.0: GHSA-pmv8-rq9r-6j72", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-pmv8-rq9r-6j72"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-pmv8-rq9r-6j72.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pmv8-rq9r-6j72\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-31f13a3f5daf69ea", "name": "Vulnerable dependency axios 1.7.0: GHSA-pmwg-cvhr-8vh7", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-pmwg-cvhr-8vh7"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-pmwg-cvhr-8vh7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pmwg-cvhr-8vh7\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed3118abcd81bdda", "name": "Vulnerable dependency axios 1.7.0: GHSA-q8qp-cvcw-x6jj", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-q8qp-cvcw-x6jj"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-q8qp-cvcw-x6jj.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q8qp-cvcw-x6jj\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9039dedc46d6be95", "name": "Vulnerable dependency axios 1.7.0: GHSA-vf2m-468p-8v99", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-vf2m-468p-8v99"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-vf2m-468p-8v99.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vf2m-468p-8v99\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d8749791bc749977", "name": "Vulnerable dependency axios 1.7.0: GHSA-w9j2-pvgh-6h63", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-w9j2-pvgh-6h63"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-w9j2-pvgh-6h63.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w9j2-pvgh-6h63\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e773b57ae5c87186", "name": "Vulnerable dependency axios 1.7.0: GHSA-xhjh-pmcv-23jw", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-xhjh-pmcv-23jw"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-xhjh-pmcv-23jw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xhjh-pmcv-23jw\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ff1b73aaab6cefc", "name": "Vulnerable dependency axios 1.7.0: GHSA-xx6v-rp6x-q39c", "shortDescription": {"text": "Vulnerable dependency axios 1.7.0: GHSA-xx6v-rp6x-q39c"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.7.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-xx6v-rp6x-q39c.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xx6v-rp6x-q39c\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b803dc6092028b65", "name": "Vulnerable dependency element-plus 2.7.3: GHSA-5m5x-9j46-h678", "shortDescription": {"text": "Vulnerable dependency element-plus 2.7.3: GHSA-5m5x-9j46-h678"}, "fullDescription": {"text": "OSV.dev reports `element-plus` at version `2.7.3` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-5m5x-9j46-h678.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5m5x-9j46-h678\nFix: upgrade `element-plus` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1f1fd5f83a61dd37", "name": "Vulnerable dependency vue-i18n 9.13.1: GHSA-9r9m-ffp6-9x4v", "shortDescription": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-9r9m-ffp6-9x4v"}, "fullDescription": {"text": "OSV.dev reports `vue-i18n` at version `9.13.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-9r9m-ffp6-9x4v (aka CVE-2024-52809).\n\nvue-i18n has cross-site scripting vulnerability with prototype pollution\n\nAliases: CVE-2024-52809\nAdvisory: https://osv.dev/vulnerability/GHSA-9r9m-ffp6-9x4v\nFix: upgrade `vue-i18n` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6bccfd1679510e48", "name": "Vulnerable dependency vue-i18n 9.13.1: GHSA-hjwq-mjwj-4x6c", "shortDescription": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-hjwq-mjwj-4x6c"}, "fullDescription": {"text": "OSV.dev reports `vue-i18n` at version `9.13.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-hjwq-mjwj-4x6c (aka CVE-2024-52810).\n\n@intlify/shared Prototype Pollution vulnerability\n\nAliases: CVE-2024-52810\nAdvisory: https://osv.dev/vulnerability/GHSA-hjwq-mjwj-4x6c\nFix: upgrade `vue-i18n` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98c491fec6086609", "name": "Vulnerable dependency vue-i18n 9.13.1: GHSA-p2ph-7g93-hw3m", "shortDescription": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-p2ph-7g93-hw3m"}, "fullDescription": {"text": "OSV.dev reports `vue-i18n` at version `9.13.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-p2ph-7g93-hw3m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p2ph-7g93-hw3m\nFix: upgrade `vue-i18n` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f56f3e2d7611b7d", "name": "Vulnerable dependency vue-i18n 9.13.1: GHSA-x8qp-wqqm-57ph", "shortDescription": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-x8qp-wqqm-57ph"}, "fullDescription": {"text": "OSV.dev reports `vue-i18n` at version `9.13.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-x8qp-wqqm-57ph (aka CVE-2025-53892).\n\nvue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes\n\nAliases: CVE-2025-53892\nAdvisory: https://osv.dev/vulnerability/GHSA-x8qp-wqqm-57ph\nFix: upgrade `vue-i18n` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ee2bb4d308528438", "name": "Vulnerable dependency webpack 5.91.0: GHSA-38r7-794h-5758", "shortDescription": {"text": "Vulnerable dependency webpack 5.91.0: GHSA-38r7-794h-5758"}, "fullDescription": {"text": "OSV.dev reports `webpack` at version `5.91.0` (declared in `archive/kt-sft/ktransformers/website/package.json`) is affected by GHSA-38r7-794h-5758 (aka CVE-2025-68157).\nNote: `5.91.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nwebpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects \u2192 SSRF + cache persistence\n\nAliases: CVE-2025-68157\nAdvisory: https://osv.dev/vulnerability/GHSA-38r7-794h-5758\nFix: upgrade `webpack` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.7}}, {"id": "scanner-f1cb376ecd9c8876", "name": "Vulnerable dependency webpack 5.91.0: GHSA-4vvj-4cpr-p986", "shortDescription": {"text": "Vulnerable dependency webpack 5.91.0: GHSA-4vvj-4cpr-p986"}, "fullDescription": {"text": "OSV.dev reports `webpack` at version `5.91.0` (declared in `archive/kt-sft/ktransformers/website/package.json`) is affected by GHSA-4vvj-4cpr-p986 (aka CVE-2024-43788).\nNote: `5.91.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nWebpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS\n\nAliases: CVE-2024-43788\nAdvisory: https://osv.dev/vulnerability/GHSA-4vvj-4cpr-p986\nFix: upgrade `webpack` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-bf891a6538687acb", "name": "Vulnerable dependency webpack 5.91.0: GHSA-8fgc-7cc6-rx7x", "shortDescription": {"text": "Vulnerable dependency webpack 5.91.0: GHSA-8fgc-7cc6-rx7x"}, "fullDescription": {"text": "OSV.dev reports `webpack` at version `5.91.0` (declared in `archive/kt-sft/ktransformers/website/package.json`) is affected by GHSA-8fgc-7cc6-rx7x.\nNote: `5.91.0` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8fgc-7cc6-rx7x\nFix: upgrade `webpack` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-a791c1c53e30e388", "name": "Vulnerable dependency torch 2.9.1: GHSA-qfhq-4f3w-5fph", "shortDescription": {"text": "Vulnerable dependency torch 2.9.1: GHSA-qfhq-4f3w-5fph"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.1` (declared in `kt-kernel/pyproject.toml`) is affected by GHSA-qfhq-4f3w-5fph.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qfhq-4f3w-5fph\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9bb52a3144b432a5", "name": "Vulnerable dependency torch 2.9.1: GHSA-rrmf-rvhw-rf47", "shortDescription": {"text": "Vulnerable dependency torch 2.9.1: GHSA-rrmf-rvhw-rf47"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.1` (declared in `kt-kernel/pyproject.toml`) is affected by GHSA-rrmf-rvhw-rf47.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4cefa5d23d3cb6bb", "name": "Vulnerable dependency torch 2.9.1: PYSEC-2026-139", "shortDescription": {"text": "Vulnerable dependency torch 2.9.1: PYSEC-2026-139"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.1` (declared in `kt-kernel/pyproject.toml`) is affected by PYSEC-2026-139.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-139\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e0383f6448433b4", "name": "Vulnerable dependency torch 2.9.1: PYSEC-2026-2286", "shortDescription": {"text": "Vulnerable dependency torch 2.9.1: PYSEC-2026-2286"}, "fullDescription": {"text": "OSV.dev reports `torch` at version `2.9.1` (declared in `kt-kernel/pyproject.toml`) is affected by PYSEC-2026-2286.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2286\nFix: upgrade `torch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-710a4bd96f5d8077", "name": "Vulnerable dependency @babel/core 7.24.5: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "Vulnerable dependency @babel/core 7.24.5: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "OSV.dev reports `@babel/core` at version `7.24.5` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-4x5r-pxfx-6jf8 (aka CVE-2026-49356).\nNote: `@babel/core` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@babel/core: Arbitrary File Read via sourceMappingURL Comment\n\nAliases: CVE-2026-49356\nAdvisory: https://osv.dev/vulnerability/GHSA-4x5r-pxfx-6jf8\nFix: upgrade `@babel/core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-af5850f9d312ad45", "name": "Vulnerable dependency @babel/helpers 7.24.5: GHSA-968p-4wvh-cqc8", "shortDescription": {"text": "Vulnerable dependency @babel/helpers 7.24.5: GHSA-968p-4wvh-cqc8"}, "fullDescription": {"text": "OSV.dev reports `@babel/helpers` at version `7.24.5` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-968p-4wvh-cqc8 (aka CVE-2025-27789).\nNote: `@babel/helpers` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nBabel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups\n\nAliases: CVE-2025-27789\nAdvisory: https://osv.dev/vulnerability/GHSA-968p-4wvh-cqc8\nFix: upgrade `@babel/helpers` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-114bdfcf7d6def16", "name": "Vulnerable dependency @babel/plugin-transform-modules-systemjs 7.24.1: GHSA-fv7c-fp4j-7gwp", "shortDescription": {"text": "Vulnerable dependency @babel/plugin-transform-modules-systemjs 7.24.1: GHSA-fv7c-fp4j-7gwp"}, "fullDescription": {"text": "OSV.dev reports `@babel/plugin-transform-modules-systemjs` at version `7.24.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-fv7c-fp4j-7gwp.\nNote: `@babel/plugin-transform-modules-systemjs` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fv7c-fp4j-7gwp\nFix: upgrade `@babel/plugin-transform-modules-systemjs` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9274999eee291813", "name": "Vulnerable dependency @babel/runtime 7.24.5: GHSA-968p-4wvh-cqc8", "shortDescription": {"text": "Vulnerable dependency @babel/runtime 7.24.5: GHSA-968p-4wvh-cqc8"}, "fullDescription": {"text": "OSV.dev reports `@babel/runtime` at version `7.24.5` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-968p-4wvh-cqc8 (aka CVE-2025-27789).\nNote: `@babel/runtime` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nBabel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups\n\nAliases: CVE-2025-27789\nAdvisory: https://osv.dev/vulnerability/GHSA-968p-4wvh-cqc8\nFix: upgrade `@babel/runtime` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-bba457a2fef05961", "name": "Vulnerable dependency js-yaml 3.14.1: GHSA-52cp-r559-cp3m", "shortDescription": {"text": "Vulnerable dependency js-yaml 3.14.1: GHSA-52cp-r559-cp3m"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `3.14.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869).\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\njs-yaml: YAML merge-key chains can force quadratic CPU consumption\n\nAliases: CVE-2026-59869\nAdvisory: https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-cf795c572dcfc761", "name": "Vulnerable dependency js-yaml 3.14.1: GHSA-h67p-54hq-rp68", "shortDescription": {"text": "Vulnerable dependency js-yaml 3.14.1: GHSA-h67p-54hq-rp68"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `3.14.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-h67p-54hq-rp68.\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h67p-54hq-rp68\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-773d8219903843e4", "name": "Vulnerable dependency js-yaml 3.14.1: GHSA-mh29-5h37-fv8m", "shortDescription": {"text": "Vulnerable dependency js-yaml 3.14.1: GHSA-mh29-5h37-fv8m"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `3.14.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-mh29-5h37-fv8m.\nNote: `js-yaml` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mh29-5h37-fv8m\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-079385dcf0afabc4", "name": "Vulnerable dependency @intlify/core-base 9.13.1: GHSA-9r9m-ffp6-9x4v", "shortDescription": {"text": "Vulnerable dependency @intlify/core-base 9.13.1: GHSA-9r9m-ffp6-9x4v"}, "fullDescription": {"text": "OSV.dev reports `@intlify/core-base` at version `9.13.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-9r9m-ffp6-9x4v (aka CVE-2024-52809).\nNote: `@intlify/core-base` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nvue-i18n has cross-site scripting vulnerability with prototype pollution\n\nAliases: CVE-2024-52809\nAdvisory: https://osv.dev/vulnerability/GHSA-9r9m-ffp6-9x4v\nFix: upgrade `@intlify/core-base` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-82bdd90a44825ff9", "name": "Vulnerable dependency @intlify/core-base 9.13.1: GHSA-x8qp-wqqm-57ph", "shortDescription": {"text": "Vulnerable dependency @intlify/core-base 9.13.1: GHSA-x8qp-wqqm-57ph"}, "fullDescription": {"text": "OSV.dev reports `@intlify/core-base` at version `9.13.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-x8qp-wqqm-57ph (aka CVE-2025-53892).\nNote: `@intlify/core-base` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nvue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes\n\nAliases: CVE-2025-53892\nAdvisory: https://osv.dev/vulnerability/GHSA-x8qp-wqqm-57ph\nFix: upgrade `@intlify/core-base` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-758b0e7b3708276f", "name": "Vulnerable dependency @intlify/shared 9.13.1: GHSA-hjwq-mjwj-4x6c", "shortDescription": {"text": "Vulnerable dependency @intlify/shared 9.13.1: GHSA-hjwq-mjwj-4x6c"}, "fullDescription": {"text": "OSV.dev reports `@intlify/shared` at version `9.13.1` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-hjwq-mjwj-4x6c (aka CVE-2024-52810).\nNote: `@intlify/shared` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@intlify/shared Prototype Pollution vulnerability\n\nAliases: CVE-2024-52810\nAdvisory: https://osv.dev/vulnerability/GHSA-hjwq-mjwj-4x6c\nFix: upgrade `@intlify/shared` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7e88bc65dce12d94", "name": "Vulnerable dependency @protobufjs/utf8 1.1.0: GHSA-q6x5-8v7m-xcrf", "shortDescription": {"text": "Vulnerable dependency @protobufjs/utf8 1.1.0: GHSA-q6x5-8v7m-xcrf"}, "fullDescription": {"text": "OSV.dev reports `@protobufjs/utf8` at version `1.1.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-q6x5-8v7m-xcrf.\nNote: `@protobufjs/utf8` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q6x5-8v7m-xcrf\nFix: upgrade `@protobufjs/utf8` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-fcbcd5e05eb3e27f", "name": "Vulnerable dependency @tootallnate/once 1.1.2: GHSA-vpq2-c234-7xj6", "shortDescription": {"text": "Vulnerable dependency @tootallnate/once 1.1.2: GHSA-vpq2-c234-7xj6"}, "fullDescription": {"text": "OSV.dev reports `@tootallnate/once` at version `1.1.2` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-vpq2-c234-7xj6.\nNote: `@tootallnate/once` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vpq2-c234-7xj6\nFix: upgrade `@tootallnate/once` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-00a7e20f9c92bffd", "name": "Vulnerable dependency postcss 7.0.39: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 7.0.39: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `7.0.39` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-6g55-p6wh-862q.\nNote: `postcss` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1547444ca61491fa", "name": "Vulnerable dependency postcss 7.0.39: GHSA-7fh5-64p2-3v2j", "shortDescription": {"text": "Vulnerable dependency postcss 7.0.39: GHSA-7fh5-64p2-3v2j"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `7.0.39` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-7fh5-64p2-3v2j.\nNote: `postcss` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7fh5-64p2-3v2j\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-703c5d57adcd1ad4", "name": "Vulnerable dependency postcss 7.0.39: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 7.0.39: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `7.0.39` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93.\nNote: `postcss` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1f353b173e0eeec9", "name": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6", "shortDescription": {"text": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6"}, "fullDescription": {"text": "OSV.dev reports `ajv` at version `6.12.6` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-2g4f-4pwh-qvx6 (aka CVE-2025-69873).\nNote: `ajv` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\najv has ReDoS when using `$data` option\n\nAliases: CVE-2025-69873\nAdvisory: https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6\nFix: upgrade `ajv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e9710770ed17d7a0", "name": "Vulnerable dependency ajv 8.13.0: GHSA-2g4f-4pwh-qvx6", "shortDescription": {"text": "Vulnerable dependency ajv 8.13.0: GHSA-2g4f-4pwh-qvx6"}, "fullDescription": {"text": "OSV.dev reports `ajv` at version `8.13.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-2g4f-4pwh-qvx6 (aka CVE-2025-69873).\nNote: `ajv` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\najv has ReDoS when using `$data` option\n\nAliases: CVE-2025-69873\nAdvisory: https://osv.dev/vulnerability/GHSA-2g4f-4pwh-qvx6\nFix: upgrade `ajv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f1df84c7bbf9ed61", "name": "Vulnerable dependency apollo-server-core 3.13.0: GHSA-9q82-xgwf-vj6h", "shortDescription": {"text": "Vulnerable dependency apollo-server-core 3.13.0: GHSA-9q82-xgwf-vj6h"}, "fullDescription": {"text": "OSV.dev reports `apollo-server-core` at version `3.13.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-9q82-xgwf-vj6h.\nNote: `apollo-server-core` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9q82-xgwf-vj6h\nFix: upgrade `apollo-server-core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-914325ba776288b3", "name": "Vulnerable dependency form-data 4.0.0: GHSA-fjxv-7rqg-78g4", "shortDescription": {"text": "Vulnerable dependency form-data 4.0.0: GHSA-fjxv-7rqg-78g4"}, "fullDescription": {"text": "OSV.dev reports `form-data` at version `4.0.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-fjxv-7rqg-78g4.\nNote: `form-data` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fjxv-7rqg-78g4\nFix: upgrade `form-data` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-117619d599f2bb0c", "name": "Vulnerable dependency form-data 4.0.0: GHSA-hmw2-7cc7-3qxx", "shortDescription": {"text": "Vulnerable dependency form-data 4.0.0: GHSA-hmw2-7cc7-3qxx"}, "fullDescription": {"text": "OSV.dev reports `form-data` at version `4.0.0` (resolved in `archive/kt-sft/ktransformers/website/package-lock.json`) is affected by GHSA-hmw2-7cc7-3qxx.\nNote: `form-data` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hmw2-7cc7-3qxx\nFix: upgrade `form-data` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d5cd919ab61dcd7b", "name": "Dependency apexcharts is two or more major versions behind", "shortDescription": {"text": "Dependency apexcharts is two or more major versions behind"}, "fullDescription": {"text": "`apexcharts` is pinned at `3.49.1` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `6.5.0` \u2014 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `apexcharts` to `6.5.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7effd068b162a8f4", "name": "Dependency axios-extensions is a major version behind", "shortDescription": {"text": "Dependency axios-extensions is a major version behind"}, "fullDescription": {"text": "`axios-extensions` is pinned at `3.1.6` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `4.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `axios-extensions` to `4.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-1b5e55edd96239e6", "name": "Dependency marked is two or more major versions behind", "shortDescription": {"text": "Dependency marked is two or more major versions behind"}, "fullDescription": {"text": "`marked` is pinned at `12.0.2` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `18.0.7` \u2014 6 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `marked` to `18.0.7`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1869db3875ce3ab3", "name": "Dependency vue-i18n is two or more major versions behind", "shortDescription": {"text": "Dependency vue-i18n is two or more major versions behind"}, "fullDescription": {"text": "`vue-i18n` is pinned at `9.13.1` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `11.4.7` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `vue-i18n` to `11.4.7`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5b960afcc020ede1", "name": "Dependency vue-router is a major version behind", "shortDescription": {"text": "Dependency vue-router is a major version behind"}, "fullDescription": {"text": "`vue-router` is pinned at `4.0.3` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `5.2.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `vue-router` to `5.2.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-7e61d9a189d85b10", "name": "Dependency webpack-cli is two or more major versions behind", "shortDescription": {"text": "Dependency webpack-cli is two or more major versions behind"}, "fullDescription": {"text": "`webpack-cli` is pinned at `5.1.4` in `archive/kt-sft/ktransformers/website/package.json` while the latest release on the npm registry is `7.2.1` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `webpack-cli` to `7.2.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30793"}, "properties": {"repository": "kvcache-ai/ktransformers", "repoUrl": "https://github.com/kvcache-ai/ktransformers", "branch": "main"}, "results": [{"ruleId": "scanner-57ca406d5f84905e", "level": "note", "message": {"text": "Possibly dead Python function: preprocess_function"}, "properties": {"repobilityId": "2a3f348340aeac8d", "scanner": "scanner-primary", "fingerprint": "57ca406d5f84905e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/withoutKT_PEFT.py:21"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-03df420c6a24fde6", "level": "note", "message": {"text": "Possibly dead Python function: save_model"}, "properties": {"repobilityId": "d97ce97f7f34726d", "scanner": "scanner-primary", "fingerprint": "03df420c6a24fde6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/withoutKT_PEFT.py:134"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-268b7e6d9ece87fe", "level": "note", "message": {"text": "Possibly dead Python function: is_marlin_supported"}, "properties": {"repobilityId": "e433b2a4ffd7276c", "scanner": "scanner-primary", "fingerprint": "268b7e6d9ece87fe", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/marlin_utils.py:31"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-937a7928ef2c6cf9", "level": "note", "message": {"text": "Possibly dead Python function: check_24"}, "properties": {"repobilityId": "e84caa269f4414b4", "scanner": "scanner-primary", "fingerprint": "937a7928ef2c6cf9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/marlin_utils.py:127"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b33532ee51957914", "level": "note", "message": {"text": "Possibly dead Python function: marlin_24_quantize"}, "properties": {"repobilityId": "07ee198dddc51732", "scanner": "scanner-primary", "fingerprint": "b33532ee51957914", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/marlin_utils.py:177"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f4ded60f49239cc", "level": "note", "message": {"text": "Possibly dead Python function: compute_max_diff"}, "properties": {"repobilityId": "6517a3b9b1fcf306", "scanner": "scanner-primary", "fingerprint": "6f4ded60f49239cc", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/marlin_utils.py:218"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8c0fb148e4fc7251", "level": "note", "message": {"text": "Possibly dead Python function: sparse_semi_structured_to_dense_cutlass"}, "properties": {"repobilityId": "c243fcfcb00e5e64", "scanner": "scanner-primary", "fingerprint": "8c0fb148e4fc7251", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/format24.py:184"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a4378d27419ed12", "level": "note", "message": {"text": "Possibly dead Python function: dequantize_weights"}, "properties": {"repobilityId": "9cf99cda679d688f", "scanner": "scanner-primary", "fingerprint": "5a4378d27419ed12", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/quant_utils.py:40"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d4548f2c9952aa80", "level": "note", "message": {"text": "Possibly dead Python function: gptq_pack"}, "properties": {"repobilityId": "12f2437913ba642f", "scanner": "scanner-primary", "fingerprint": "d4548f2c9952aa80", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/quant_utils.py:153"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47de50b3241525ad", "level": "note", "message": {"text": "Possibly dead Python function: gptq_unpack"}, "properties": {"repobilityId": "6a3f8329a8c6129d", "scanner": "scanner-primary", "fingerprint": "47de50b3241525ad", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/csrc/custom_marlin/utils/quant_utils.py:176"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ecc8cf16484992e", "level": "note", "message": {"text": "Possibly dead Python function: write_to_file"}, "properties": {"repobilityId": "310aa1868802e0d2", "scanner": "scanner-primary", "fingerprint": "4ecc8cf16484992e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/local_chat.py:56"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c06758092646cf1d", "level": "note", "message": {"text": "Possibly dead Python function: set_input_embeddings"}, "properties": {"repobilityId": "49aa28cb7753431c", "scanner": "scanner-primary", "fingerprint": "c06758092646cf1d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_llama.py:1689"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa98d735a261a7cb", "level": "note", "message": {"text": "Possibly dead Python function: set_output_embeddings"}, "properties": {"repobilityId": "c2a5ca175b75bcf3", "scanner": "scanner-primary", "fingerprint": "aa98d735a261a7cb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_llama.py:1258"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d011dafc5622b5a", "level": "note", "message": {"text": "Possibly dead Python function: set_decoder"}, "properties": {"repobilityId": "01c8702d16528ba3", "scanner": "scanner-primary", "fingerprint": "2d011dafc5622b5a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_llama.py:1261"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-673887be97fd2cce", "level": "note", "message": {"text": "Possibly dead Python function: prepare_inputs_for_generation"}, "properties": {"repobilityId": "3d9da7a4adb0729f", "scanner": "scanner-primary", "fingerprint": "673887be97fd2cce", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_llama.py:1377"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50464cdcc18d9fa3", "level": "note", "message": {"text": "Possibly dead Python function: set_input_embeddings"}, "properties": {"repobilityId": "49aa28cb7753431c", "scanner": "scanner-primary", "fingerprint": "50464cdcc18d9fa3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek.py:1895"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-200a8f65341aa795", "level": "note", "message": {"text": "Possibly dead Python function: set_output_embeddings"}, "properties": {"repobilityId": "c2a5ca175b75bcf3", "scanner": "scanner-primary", "fingerprint": "200a8f65341aa795", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek.py:1666"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ff80e4869752ad6", "level": "note", "message": {"text": "Possibly dead Python function: set_decoder"}, "properties": {"repobilityId": "01c8702d16528ba3", "scanner": "scanner-primary", "fingerprint": "5ff80e4869752ad6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek.py:1669"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a448bf1408984a2", "level": "note", "message": {"text": "Possibly dead Python function: prepare_inputs_for_generation"}, "properties": {"repobilityId": "3d9da7a4adb0729f", "scanner": "scanner-primary", "fingerprint": "7a448bf1408984a2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek.py:1777"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c9cf69711843afb5", "level": "note", "message": {"text": "Possibly dead Python function: set_input_embeddings"}, "properties": {"repobilityId": "49aa28cb7753431c", "scanner": "scanner-primary", "fingerprint": "c9cf69711843afb5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek_v3.py:1840"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f5501fd18dde796", "level": "note", "message": {"text": "Possibly dead Python function: set_output_embeddings"}, "properties": {"repobilityId": "c2a5ca175b75bcf3", "scanner": "scanner-primary", "fingerprint": "5f5501fd18dde796", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek_v3.py:1625"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-955c2c601bb9c0c0", "level": "note", "message": {"text": "Possibly dead Python function: set_decoder"}, "properties": {"repobilityId": "01c8702d16528ba3", "scanner": "scanner-primary", "fingerprint": "955c2c601bb9c0c0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek_v3.py:1628"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86deb946b3e43ace", "level": "note", "message": {"text": "Possibly dead Python function: prepare_inputs_for_generation"}, "properties": {"repobilityId": "3d9da7a4adb0729f", "scanner": "scanner-primary", "fingerprint": "86deb946b3e43ace", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/models/modeling_deepseek_v3.py:1735"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8ff39877efe08aad", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/components/chat/index.vue:339"}, "properties": {"repobilityId": "26acca3e1eed0b98", "scanner": "scanner-primary", "fingerprint": "8ff39877efe08aad", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/src/components/chat/index.vue"}, "region": {"startLine": 339}}}]}, {"ruleId": "scanner-4610b033ff33dcc4", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "properties": {"repobilityId": "51522fc4ac7cb2fd", "scanner": "scanner-primary", "fingerprint": "4610b033ff33dcc4", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b881236d2d688787", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/kt-sft/ktransformers/website/src/views/home.vue:367"}, "properties": {"repobilityId": "169624557e854ff5", "scanner": "scanner-primary", "fingerprint": "b881236d2d688787", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/src/views/home.vue"}, "region": {"startLine": 367}}}]}, {"ruleId": "scanner-947299ff378a92a5", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/components/chat/index.vue:339"}, "properties": {"repobilityId": "98ad25fbc8fcbb24", "scanner": "scanner-primary", "fingerprint": "947299ff378a92a5", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/website/src/components/chat/index.vue"}, "region": {"startLine": 339}}}]}, {"ruleId": "scanner-0f438f16f5df192e", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "properties": {"repobilityId": "b274f363c5bb1fde", "scanner": "scanner-primary", "fingerprint": "0f438f16f5df192e", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/website/src/assets/iconfont/iconfont.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0d6f096367bbe912", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 archive/ktransformers/website/src/views/home.vue:367"}, "properties": {"repobilityId": "064447ccf602e083", "scanner": "scanner-primary", "fingerprint": "0d6f096367bbe912", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/website/src/views/home.vue"}, "region": {"startLine": 367}}}]}, {"ruleId": "scanner-dd717848b5ceb0bb", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py:322"}, "properties": {"repobilityId": "8dd07f4ee335c494", "scanner": "scanner-primary", "fingerprint": "dd717848b5ceb0bb", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py"}, "region": {"startLine": 322}}}]}, {"ruleId": "scanner-ca31cc2573007266", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237"}, "properties": {"repobilityId": "82a58efb3864b5dc", "scanner": "scanner-primary", "fingerprint": "ca31cc2573007266", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py"}, "region": {"startLine": 237}}}]}, {"ruleId": "scanner-51538ea96f00399c", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567"}, "properties": {"repobilityId": "670803424a4e2673", "scanner": "scanner-primary", "fingerprint": "51538ea96f00399c", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py"}, "region": {"startLine": 567}}}]}, {"ruleId": "scanner-ac8b6b8216d5b525", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/utils.py:123"}, "properties": {"repobilityId": "7bf08b2de3a4a743", "scanner": "scanner-primary", "fingerprint": "ac8b6b8216d5b525", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/utils.py"}, "region": {"startLine": 123}}}]}, {"ruleId": "scanner-a11ea51dd2c423ec", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/kt-sft/ktransformers/server/balance_serve/sched_rpc.py:51"}, "properties": {"repobilityId": "7887ac0ef17d5d82", "scanner": "scanner-primary", "fingerprint": "a11ea51dd2c423ec", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/balance_serve/sched_rpc.py"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-ce52891c64b0d224", "level": "note", "message": {"text": "avoid bind to all interfaces \u2014 archive/kt-sft/ktransformers/sft/metrics_utils/misc.py:318"}, "properties": {"repobilityId": "fe3da92940ef26c6", "scanner": "scanner-primary", "fingerprint": "ce52891c64b0d224", "layer": "security", "severity": "low", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/sft/metrics_utils/misc.py"}, "region": {"startLine": 318}}}]}, {"ruleId": "scanner-208b487dfa3a109f", "level": "note", "message": {"text": "avoid bind to all interfaces \u2014 archive/kt-sft/ktransformers/util/utils.py:101"}, "properties": {"repobilityId": "3cb7640a9f489858", "scanner": "scanner-primary", "fingerprint": "208b487dfa3a109f", "layer": "security", "severity": "low", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/util/utils.py"}, "region": {"startLine": 101}}}]}, {"ruleId": "scanner-ba0afbd44f8c6332", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 archive/kt-sft/setup.py:300"}, "properties": {"repobilityId": "79a9fb6194b8904e", "scanner": "scanner-primary", "fingerprint": "ba0afbd44f8c6332", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/setup.py"}, "region": {"startLine": 300}}}]}, {"ruleId": "scanner-13fac8d572d83861", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/ktransformers/server/backend/interfaces/balance_serve.py:489"}, "properties": {"repobilityId": "895da82619081b30", "scanner": "scanner-primary", "fingerprint": "13fac8d572d83861", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/backend/interfaces/balance_serve.py"}, "region": {"startLine": 489}}}]}, {"ruleId": "scanner-5ed4ec0d74fd055c", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py:237"}, "properties": {"repobilityId": "0a17ec5b91ce555f", "scanner": "scanner-primary", "fingerprint": "5ed4ec0d74fd055c", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/balance_serve/inference/distributed/custom_all_reduce_utils.py"}, "region": {"startLine": 237}}}]}, {"ruleId": "scanner-250ca500c3377931", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:567"}, "properties": {"repobilityId": "50a81c1b123e5171", "scanner": "scanner-primary", "fingerprint": "250ca500c3377931", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py"}, "region": {"startLine": 567}}}]}, {"ruleId": "scanner-a7a08784f1ac16b8", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/inference/distributed/utils.py:123"}, "properties": {"repobilityId": "aaa7f65a0b4f7bcb", "scanner": "scanner-primary", "fingerprint": "a7a08784f1ac16b8", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/balance_serve/inference/distributed/utils.py"}, "region": {"startLine": 123}}}]}, {"ruleId": "scanner-b39c73aa25b314d5", "level": "warning", "message": {"text": "avoid pickle \u2014 archive/ktransformers/server/balance_serve/sched_rpc.py:70"}, "properties": {"repobilityId": "780b0eaffcfd5e3c", "scanner": "scanner-primary", "fingerprint": "b39c73aa25b314d5", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/balance_serve/sched_rpc.py"}, "region": {"startLine": 70}}}]}, {"ruleId": "scanner-48f0da5b4b2322b9", "level": "note", "message": {"text": "avoid bind to all interfaces \u2014 archive/ktransformers/util/utils.py:161"}, "properties": {"repobilityId": "eaae0b8b217d030d", "scanner": "scanner-primary", "fingerprint": "48f0da5b4b2322b9", "layer": "security", "severity": "low", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/util/utils.py"}, "region": {"startLine": 161}}}]}, {"ruleId": "scanner-bd687a30d4500527", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 archive/setup.py:281"}, "properties": {"repobilityId": "c67223d1937e753f", "scanner": "scanner-primary", "fingerprint": "bd687a30d4500527", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/setup.py"}, "region": {"startLine": 281}}}]}, {"ruleId": "scanner-058dd35b68de1bff", "level": "error", "message": {"text": "subprocess shell true \u2014 kt-kernel/bench/compare_moe_performance.py:825"}, "properties": {"repobilityId": "66d5374151ce089d", "scanner": "scanner-primary", "fingerprint": "058dd35b68de1bff", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/compare_moe_performance.py"}, "region": {"startLine": 825}}}]}, {"ruleId": "scanner-d46c8a405d9b692b", "level": "warning", "message": {"text": "exec detected \u2014 kt-kernel/python/__init__.py:80"}, "properties": {"repobilityId": "0f31711b3f86fda4", "scanner": "scanner-primary", "fingerprint": "d46c8a405d9b692b", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/python/__init__.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-4f444a2280df58fb", "level": "warning", "message": {"text": "exec detected \u2014 kt-kernel/python/cli/__init__.py:18"}, "properties": {"repobilityId": "dc44052d64e7abb2", "scanner": "scanner-primary", "fingerprint": "4f444a2280df58fb", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/python/cli/__init__.py"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-f3b14a44169dec28", "level": "warning", "message": {"text": "exec detected \u2014 kt-kernel/setup.py:753"}, "properties": {"repobilityId": "e2e6f0e41f241746", "scanner": "scanner-primary", "fingerprint": "f3b14a44169dec28", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/setup.py"}, "region": {"startLine": 753}}}]}, {"ruleId": "scanner-21653d74bfba8079", "level": "warning", "message": {"text": "exec detected \u2014 ktransformers.py:17"}, "properties": {"repobilityId": "a6033a853c9fa50d", "scanner": "scanner-primary", "fingerprint": "21653d74bfba8079", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ktransformers.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-5506e741c2d2b408", "level": "warning", "message": {"text": "exec detected \u2014 setup.py:12"}, "properties": {"repobilityId": "2d6c941a7196eb47", "scanner": "scanner-primary", "fingerprint": "5506e741c2d2b408", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "setup.py"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-b97870def601f7d1", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "70fe52f653bce7c3", "scanner": "scanner-primary", "fingerprint": "b97870def601f7d1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-3bff8607c5600a4b", "level": "warning", "message": {"text": "CVE-2025-27789: @babel/helpers 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "0c2706079e17cf3a", "scanner": "scanner-primary", "fingerprint": "3bff8607c5600a4b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27789"]}}, {"ruleId": "scanner-cf1231fa36fe81dd", "level": "error", "message": {"text": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "644f4fe27d0b7802", "scanner": "scanner-primary", "fingerprint": "cf1231fa36fe81dd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44728"]}}, {"ruleId": "scanner-9454849e71ae494a", "level": "warning", "message": {"text": "CVE-2025-27789: @babel/runtime 7.24.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fc911f84ede9d56c", "scanner": "scanner-primary", "fingerprint": "9454849e71ae494a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27789"]}}, {"ruleId": "scanner-8489e84fda8f961b", "level": "warning", "message": {"text": "CVE-2024-52809: @intlify/core-base 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "01575d5df0f6bdb6", "scanner": "scanner-primary", "fingerprint": "8489e84fda8f961b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52809"]}}, {"ruleId": "scanner-9436c06ffe1bd87c", "level": "warning", "message": {"text": "CVE-2025-53892: @intlify/core-base 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "505f9345309e0894", "scanner": "scanner-primary", "fingerprint": "9436c06ffe1bd87c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53892"]}}, {"ruleId": "scanner-0cecac97a9d57449", "level": "warning", "message": {"text": "CVE-2024-52810: @intlify/shared 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "93dfa77f6019f46c", "scanner": "scanner-primary", "fingerprint": "0cecac97a9d57449", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52810"]}}, {"ruleId": "scanner-210acfe48b4def43", "level": "warning", "message": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8ea81c093a71f473", "scanner": "scanner-primary", "fingerprint": "210acfe48b4def43", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44288"]}}, {"ruleId": "scanner-41273e776bcd453a", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 6.12.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cfcb0b2cdd595942", "scanner": "scanner-primary", "fingerprint": "41273e776bcd453a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-e4d335545da333bb", "level": "warning", "message": {"text": "GHSA-9q82-xgwf-vj6h: apollo-server-core 3.13.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2cd1a127627f5950", "scanner": "scanner-primary", "fingerprint": "e4d335545da333bb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-9q82-xgwf-vj6h"]}}, {"ruleId": "scanner-2e7a59a09a4bce68", "level": "error", "message": {"text": "CVE-2024-39338: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "06485098e1b3abb0", "scanner": "scanner-primary", "fingerprint": "2e7a59a09a4bce68", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-39338"]}}, {"ruleId": "scanner-03cd8cf632b8ffb8", "level": "error", "message": {"text": "CVE-2025-27152: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f7b0bdea25c84fa8", "scanner": "scanner-primary", "fingerprint": "03cd8cf632b8ffb8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27152"]}}, {"ruleId": "scanner-2d048346e089f70c", "level": "error", "message": {"text": "CVE-2025-58754: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "df8ed8692f5f8c4e", "scanner": "scanner-primary", "fingerprint": "2d048346e089f70c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-58754"]}}, {"ruleId": "scanner-40222fa32de80e47", "level": "error", "message": {"text": "CVE-2026-25639: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "459303deebead796", "scanner": "scanner-primary", "fingerprint": "40222fa32de80e47", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25639"]}}, {"ruleId": "scanner-2d3b8b7b11e4e4be", "level": "error", "message": {"text": "CVE-2026-42033: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fc4511ab6c2dc4d2", "scanner": "scanner-primary", "fingerprint": "2d3b8b7b11e4e4be", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42033"]}}, {"ruleId": "scanner-437dc476cd133b8c", "level": "error", "message": {"text": "CVE-2026-42035: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a2b5902a598ab5f4", "scanner": "scanner-primary", "fingerprint": "437dc476cd133b8c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42035"]}}, {"ruleId": "scanner-969022c2aae42ef1", "level": "error", "message": {"text": "CVE-2026-42043: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "23c96939b22fb1bc", "scanner": "scanner-primary", "fingerprint": "969022c2aae42ef1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42043"]}}, {"ruleId": "scanner-4cb0e4e6e138d043", "level": "error", "message": {"text": "CVE-2026-42264: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "eb11ac0574af6683", "scanner": "scanner-primary", "fingerprint": "4cb0e4e6e138d043", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42264"]}}, {"ruleId": "scanner-83d0534013e9f434", "level": "error", "message": {"text": "CVE-2026-44486: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6a5779b228ea7357", "scanner": "scanner-primary", "fingerprint": "83d0534013e9f434", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44486"]}}, {"ruleId": "scanner-20b161116aa02b09", "level": "error", "message": {"text": "CVE-2026-44487: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "77c726c9e9158860", "scanner": "scanner-primary", "fingerprint": "20b161116aa02b09", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44487"]}}, {"ruleId": "scanner-5c23c74d30db155c", "level": "error", "message": {"text": "CVE-2026-44488: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3e15612a3e3cd9a3", "scanner": "scanner-primary", "fingerprint": "5c23c74d30db155c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44488"]}}, {"ruleId": "scanner-54aff46017b4e433", "level": "error", "message": {"text": "CVE-2026-44494: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "01e469b8d10663f1", "scanner": "scanner-primary", "fingerprint": "54aff46017b4e433", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44494"]}}, {"ruleId": "scanner-8170b2bbf87b9f36", "level": "error", "message": {"text": "CVE-2026-44495: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "99dc41a50d736ef9", "scanner": "scanner-primary", "fingerprint": "8170b2bbf87b9f36", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44495"]}}, {"ruleId": "scanner-b1531b0251daacdf", "level": "error", "message": {"text": "CVE-2026-44496: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "94ed356e1ec49ef5", "scanner": "scanner-primary", "fingerprint": "b1531b0251daacdf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44496"]}}, {"ruleId": "scanner-9f1750743221ce5e", "level": "warning", "message": {"text": "CVE-2025-62718: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "655a4931cd6fa5c7", "scanner": "scanner-primary", "fingerprint": "9f1750743221ce5e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62718"]}}, {"ruleId": "scanner-087617e068887180", "level": "warning", "message": {"text": "CVE-2026-40175: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2bc0111bebb4f718", "scanner": "scanner-primary", "fingerprint": "087617e068887180", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40175"]}}, {"ruleId": "scanner-13044fb062bb9002", "level": "warning", "message": {"text": "CVE-2026-42034: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3b5bf0438bbc8f6e", "scanner": "scanner-primary", "fingerprint": "13044fb062bb9002", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42034"]}}, {"ruleId": "scanner-baeb0e9f9c979011", "level": "warning", "message": {"text": "CVE-2026-42036: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1f2a2be9e4d0a60a", "scanner": "scanner-primary", "fingerprint": "baeb0e9f9c979011", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42036"]}}, {"ruleId": "scanner-6e14dea92143251e", "level": "warning", "message": {"text": "CVE-2026-42037: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "20340e3667be1693", "scanner": "scanner-primary", "fingerprint": "6e14dea92143251e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42037"]}}, {"ruleId": "scanner-3d8288920289f9d8", "level": "warning", "message": {"text": "CVE-2026-42038: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2037ad9df38ac906", "scanner": "scanner-primary", "fingerprint": "3d8288920289f9d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42038"]}}, {"ruleId": "scanner-4406d50a3657102e", "level": "warning", "message": {"text": "CVE-2026-42039: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d18b0937cf5bd479", "scanner": "scanner-primary", "fingerprint": "4406d50a3657102e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42039"]}}, {"ruleId": "scanner-9da4e9ac6b9eaa2e", "level": "warning", "message": {"text": "CVE-2026-42041: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6f97eac720d1ec84", "scanner": "scanner-primary", "fingerprint": "9da4e9ac6b9eaa2e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42041"]}}, {"ruleId": "scanner-5f5fcd457d7e8999", "level": "warning", "message": {"text": "CVE-2026-42042: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "34907d80acf7bd1c", "scanner": "scanner-primary", "fingerprint": "5f5fcd457d7e8999", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42042"]}}, {"ruleId": "scanner-a7be920a797f2e7d", "level": "warning", "message": {"text": "CVE-2026-42044: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "245ec373c15a6985", "scanner": "scanner-primary", "fingerprint": "a7be920a797f2e7d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42044"]}}, {"ruleId": "scanner-57816ac5abc98cf2", "level": "warning", "message": {"text": "CVE-2026-44490: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "060cffeec1499238", "scanner": "scanner-primary", "fingerprint": "57816ac5abc98cf2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44490"]}}, {"ruleId": "scanner-354e4eb241d857f2", "level": "warning", "message": {"text": "GHSA-42h9-826w-cgv3: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "528413adb42ab37a", "scanner": "scanner-primary", "fingerprint": "354e4eb241d857f2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-42h9-826w-cgv3"]}}, {"ruleId": "scanner-8493a66e1a9c3b99", "level": "warning", "message": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e39ec1a81b9e79eb", "scanner": "scanner-primary", "fingerprint": "8493a66e1a9c3b99", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-7q8q-rj6j-mhjq"]}}, {"ruleId": "scanner-286219ea2194d27e", "level": "warning", "message": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2d5f82a34efd99f2", "scanner": "scanner-primary", "fingerprint": "286219ea2194d27e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-jqh4-m9w3-8hp9"]}}, {"ruleId": "scanner-20094c53bcf5763a", "level": "warning", "message": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e8a9d9001f7a52ee", "scanner": "scanner-primary", "fingerprint": "20094c53bcf5763a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mmx7-hfxf-jppx"]}}, {"ruleId": "scanner-4418693fd1de8763", "level": "warning", "message": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "5d39909d65347ab4", "scanner": "scanner-primary", "fingerprint": "4418693fd1de8763", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-pmv8-rq9r-6j72"]}}, {"ruleId": "scanner-9e618535ae8b58cc", "level": "note", "message": {"text": "CVE-2026-42040: axios 1.7.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fabe09512e2cde28", "scanner": "scanner-primary", "fingerprint": "9e618535ae8b58cc", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42040"]}}, {"ruleId": "scanner-a9c147d7aa47fe04", "level": "warning", "message": {"text": "CVE-2026-2739: bn.js 4.12.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "312233592dc7b795", "scanner": "scanner-primary", "fingerprint": "a9c147d7aa47fe04", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2739"]}}, {"ruleId": "scanner-b2637e6873970732", "level": "warning", "message": {"text": "CVE-2026-2739: bn.js 5.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "312233592dc7b795", "scanner": "scanner-primary", "fingerprint": "b2637e6873970732", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2739"]}}, {"ruleId": "scanner-41ceff131080cbc2", "level": "error", "message": {"text": "CVE-2024-45590: body-parser 1.20.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fd6b9b46e0833574", "scanner": "scanner-primary", "fingerprint": "41ceff131080cbc2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-45590"]}}, {"ruleId": "scanner-203c0f117845dc1d", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c240e9712ca41f00", "scanner": "scanner-primary", "fingerprint": "203c0f117845dc1d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-70cfc3642247ad9d", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "795ce13b248dcc4e", "scanner": "scanner-primary", "fingerprint": "70cfc3642247ad9d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-f82fb10dd98a9eea", "level": "warning", "message": {"text": "CVE-2026-33750: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f6a9cd44f39e17a8", "scanner": "scanner-primary", "fingerprint": "f82fb10dd98a9eea", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33750"]}}, {"ruleId": "scanner-f949ae8d82bb5355", "level": "note", "message": {"text": "CVE-2025-5889: brace-expansion 1.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "efe8159aa4a9f73f", "scanner": "scanner-primary", "fingerprint": "f949ae8d82bb5355", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5889"]}}, {"ruleId": "scanner-eea59c2830416434", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "795ce13b248dcc4e", "scanner": "scanner-primary", "fingerprint": "eea59c2830416434", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-1cf26c7ead5adddd", "level": "warning", "message": {"text": "CVE-2026-33750: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f6a9cd44f39e17a8", "scanner": "scanner-primary", "fingerprint": "1cf26c7ead5adddd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33750"]}}, {"ruleId": "scanner-94d7fe32df0dffbf", "level": "note", "message": {"text": "CVE-2025-5889: brace-expansion 2.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "efe8159aa4a9f73f", "scanner": "scanner-primary", "fingerprint": "94d7fe32df0dffbf", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5889"]}}, {"ruleId": "scanner-7564c1a20370d6b7", "level": "error", "message": {"text": "CVE-2024-4068: braces 2.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2c4cb64bb8e34158", "scanner": "scanner-primary", "fingerprint": "7564c1a20370d6b7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4068"]}}, {"ruleId": "scanner-e3785378cdd08b3d", "level": "error", "message": {"text": "CVE-2024-4068: braces 3.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2c4cb64bb8e34158", "scanner": "scanner-primary", "fingerprint": "e3785378cdd08b3d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4068"]}}, {"ruleId": "scanner-f560c2ec6501ed38", "level": "error", "message": {"text": "CVE-2025-9287: cipher-base 1.0.4 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b93c574d3531917a", "scanner": "scanner-primary", "fingerprint": "f560c2ec6501ed38", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-9287"]}}, {"ruleId": "scanner-6478b66ae8df1fa5", "level": "note", "message": {"text": "CVE-2024-47764: cookie 0.6.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "742c50e9343618c6", "scanner": "scanner-primary", "fingerprint": "6478b66ae8df1fa5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47764"]}}, {"ruleId": "scanner-65f60c3cc5338e28", "level": "error", "message": {"text": "CVE-2024-21538: cross-spawn 6.0.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d912111f29333e36", "scanner": "scanner-primary", "fingerprint": "65f60c3cc5338e28", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-21538"]}}, {"ruleId": "scanner-5411c2bce63c1a25", "level": "error", "message": {"text": "CVE-2024-21538: cross-spawn 7.0.3 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d912111f29333e36", "scanner": "scanner-primary", "fingerprint": "5411c2bce63c1a25", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-21538"]}}, {"ruleId": "scanner-0199a09e32c73ea2", "level": "error", "message": {"text": "CVE-2026-53486: decompress 4.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2788777beb9be8fb", "scanner": "scanner-primary", "fingerprint": "0199a09e32c73ea2", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53486"]}}, {"ruleId": "scanner-291cac5262f3cea9", "level": "warning", "message": {"text": "CVE-2025-57665: element-plus 2.7.3 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4d5e9eea7b162a17", "scanner": "scanner-primary", "fingerprint": "291cac5262f3cea9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57665"]}}, {"ruleId": "scanner-818bb4f37908d3f4", "level": "error", "message": {"text": "GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c6ff7ba31a24bd87", "scanner": "scanner-primary", "fingerprint": "818bb4f37908d3f4", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vjh7-7g9h-fjfh"]}}, {"ruleId": "scanner-f5581b5d86696eaa", "level": "note", "message": {"text": "CVE-2024-42459: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "15cfbfe7fb2c25ed", "scanner": "scanner-primary", "fingerprint": "f5581b5d86696eaa", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-42459"]}}, {"ruleId": "scanner-c48f5da160ef9279", "level": "note", "message": {"text": "CVE-2024-42460: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cc4aae69db4eab1b", "scanner": "scanner-primary", "fingerprint": "c48f5da160ef9279", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-42460"]}}, {"ruleId": "scanner-8a0f08fbc519ed65", "level": "note", "message": {"text": "CVE-2024-42461: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "18c66ae53c52947e", "scanner": "scanner-primary", "fingerprint": "8a0f08fbc519ed65", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-42461"]}}, {"ruleId": "scanner-ff8970f5ad11d230", "level": "note", "message": {"text": "CVE-2024-48948: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "006e654e96f7408f", "scanner": "scanner-primary", "fingerprint": "ff8970f5ad11d230", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-48948"]}}, {"ruleId": "scanner-d0c9d6ecc74928cd", "level": "note", "message": {"text": "CVE-2024-48949: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "03d9363cdf65e734", "scanner": "scanner-primary", "fingerprint": "d0c9d6ecc74928cd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-48949"]}}, {"ruleId": "scanner-058b4f1bb7dc6eb3", "level": "note", "message": {"text": "CVE-2025-14505: elliptic 6.5.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "31f696c5962dfa44", "scanner": "scanner-primary", "fingerprint": "058b4f1bb7dc6eb3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-14505"]}}, {"ruleId": "scanner-c7778d57e25bf100", "level": "note", "message": {"text": "CVE-2024-43796: express 4.19.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "aa7664cb17329fee", "scanner": "scanner-primary", "fingerprint": "c7778d57e25bf100", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43796"]}}, {"ruleId": "scanner-a55613ab4bb6d9aa", "level": "warning", "message": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ae6fe7ff6eb3a36e", "scanner": "scanner-primary", "fingerprint": "a55613ab4bb6d9aa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-r4q5-vmmm-2653"]}}, {"ruleId": "scanner-9e3378da60a68c43", "level": "error", "message": {"text": "CVE-2025-7783: form-data 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a6c8ffebedfd65ea", "scanner": "scanner-primary", "fingerprint": "9e3378da60a68c43", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-7783"]}}, {"ruleId": "scanner-02e4efdf86668863", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "03d33228549b475d", "scanner": "scanner-primary", "fingerprint": "02e4efdf86668863", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-6508943c638d451d", "level": "error", "message": {"text": "CVE-2022-25900: git-clone 0.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "0daaaf9859c0ca3d", "scanner": "scanner-primary", "fingerprint": "6508943c638d451d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2022-25900"]}}, {"ruleId": "scanner-11ac06ff22880c1f", "level": "warning", "message": {"text": "CVE-2022-33987: got 8.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1b7de906aaff566a", "scanner": "scanner-primary", "fingerprint": "11ac06ff22880c1f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2022-33987"]}}, {"ruleId": "scanner-74950c41c70ba2e9", "level": "error", "message": {"text": "CVE-2022-25881: http-cache-semantics 3.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6197c95fd7963913", "scanner": "scanner-primary", "fingerprint": "74950c41c70ba2e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2022-25881"]}}, {"ruleId": "scanner-1dc120afddfc8989", "level": "warning", "message": {"text": "CVE-2026-48038: joi 17.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6d97b00340ee4472", "scanner": "scanner-primary", "fingerprint": "1dc120afddfc8989", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48038"]}}, {"ruleId": "scanner-5a1365e3792e29a3", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3b798864569f2977", "scanner": "scanner-primary", "fingerprint": "5a1365e3792e29a3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-b08a737c57fc03ee", "level": "warning", "message": {"text": "CVE-2025-64718: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8496dac6889ac549", "scanner": "scanner-primary", "fingerprint": "b08a737c57fc03ee", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-64718"]}}, {"ruleId": "scanner-8cee7bd48dffc46e", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 3.14.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "22e453682c64b179", "scanner": "scanner-primary", "fingerprint": "8cee7bd48dffc46e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-4817c6ecbd96b539", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3b798864569f2977", "scanner": "scanner-primary", "fingerprint": "4817c6ecbd96b539", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-bce7ca9cb3b0a86d", "level": "warning", "message": {"text": "CVE-2025-64718: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8496dac6889ac549", "scanner": "scanner-primary", "fingerprint": "bce7ca9cb3b0a86d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-64718"]}}, {"ruleId": "scanner-0e91dcc81e879e8f", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "22e453682c64b179", "scanner": "scanner-primary", "fingerprint": "0e91dcc81e879e8f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-a46f429441755131", "level": "error", "message": {"text": "CVE-2024-52011: launch-editor 2.6.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c4e77c3e86772a05", "scanner": "scanner-primary", "fingerprint": "a46f429441755131", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52011"]}}, {"ruleId": "scanner-baadf3fd0041bbbc", "level": "warning", "message": {"text": "CVE-2026-53632: launch-editor 2.6.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "df962329aa2601f9", "scanner": "scanner-primary", "fingerprint": "baadf3fd0041bbbc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-ba7c2a5a2cf4ee61", "level": "error", "message": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1fe0d9d9220685ad", "scanner": "scanner-primary", "fingerprint": "ba7c2a5a2cf4ee61", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-f7a3b45e35a307dc", "level": "warning", "message": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d12ec12b4c0f87dd", "scanner": "scanner-primary", "fingerprint": "f7a3b45e35a307dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-29ed3173bbdab352", "level": "warning", "message": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3c799b5d3fa5a677", "scanner": "scanner-primary", "fingerprint": "29ed3173bbdab352", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-857de1a1dd904756", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "afde964962da4c69", "scanner": "scanner-primary", "fingerprint": "857de1a1dd904756", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-27028985745e1a2f", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8aff54654c7c6e1e", "scanner": "scanner-primary", "fingerprint": "27028985745e1a2f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-a458940504012007", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d5ce68108ad01fe6", "scanner": "scanner-primary", "fingerprint": "a458940504012007", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-011dd8fa34e638b3", "level": "warning", "message": {"text": "CVE-2024-4067: micromatch 3.1.10 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "338392d840fb8c46", "scanner": "scanner-primary", "fingerprint": "011dd8fa34e638b3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4067"]}}, {"ruleId": "scanner-6f7943cc41ff39a1", "level": "warning", "message": {"text": "CVE-2024-4067: micromatch 4.0.5 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "338392d840fb8c46", "scanner": "scanner-primary", "fingerprint": "6f7943cc41ff39a1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4067"]}}, {"ruleId": "scanner-d1a272788e485f37", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d8e24619bfb3bde7", "scanner": "scanner-primary", "fingerprint": "d1a272788e485f37", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-9ff8dade712bbb5c", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8935f6717405fa82", "scanner": "scanner-primary", "fingerprint": "9ff8dade712bbb5c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-6fe518a3a6f4e36d", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ce4190713eedcc4d", "scanner": "scanner-primary", "fingerprint": "6fe518a3a6f4e36d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-c80494aff42fe89a", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d8e24619bfb3bde7", "scanner": "scanner-primary", "fingerprint": "c80494aff42fe89a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-730dfc387c6fd43d", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8935f6717405fa82", "scanner": "scanner-primary", "fingerprint": "730dfc387c6fd43d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-964fbeb044e0ff30", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 5.1.6 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ce4190713eedcc4d", "scanner": "scanner-primary", "fingerprint": "964fbeb044e0ff30", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-f38bf7635947984c", "level": "warning", "message": {"text": "CVE-2024-55565: nanoid 2.1.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6e03bbdb55c00da5", "scanner": "scanner-primary", "fingerprint": "f38bf7635947984c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-55565"]}}, {"ruleId": "scanner-e95b6f0891bdb9e7", "level": "warning", "message": {"text": "CVE-2024-55565: nanoid 3.3.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6e03bbdb55c00da5", "scanner": "scanner-primary", "fingerprint": "e95b6f0891bdb9e7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-55565"]}}, {"ruleId": "scanner-08182652afb4af5c", "level": "error", "message": {"text": "CVE-2025-25975: parse-git-config 3.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2f43dec29584afb5", "scanner": "scanner-primary", "fingerprint": "08182652afb4af5c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-25975"]}}, {"ruleId": "scanner-edabfb51fcd83e6d", "level": "error", "message": {"text": "CVE-2024-45296: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e034ecc14557302e", "scanner": "scanner-primary", "fingerprint": "edabfb51fcd83e6d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-45296"]}}, {"ruleId": "scanner-b682201d8f66b821", "level": "error", "message": {"text": "CVE-2024-52798: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "01b4f795b6c5627d", "scanner": "scanner-primary", "fingerprint": "b682201d8f66b821", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52798"]}}, {"ruleId": "scanner-189c73853995cfd6", "level": "error", "message": {"text": "CVE-2026-4867: path-to-regexp 0.1.7 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "7f8b68bba2cc38fb", "scanner": "scanner-primary", "fingerprint": "189c73853995cfd6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4867"]}}, {"ruleId": "scanner-a81dc8f35de358ad", "level": "error", "message": {"text": "CVE-2025-6545: pbkdf2 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "47b1d2cdec0d2e3b", "scanner": "scanner-primary", "fingerprint": "a81dc8f35de358ad", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6545"]}}, {"ruleId": "scanner-88c61cecb5b8ca49", "level": "error", "message": {"text": "CVE-2025-6547: pbkdf2 3.1.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "dc06aa1f2ac9a4d5", "scanner": "scanner-primary", "fingerprint": "88c61cecb5b8ca49", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6547"]}}, {"ruleId": "scanner-70bfc2840e418ae3", "level": "error", "message": {"text": "CVE-2024-4367: pdfjs-dist 2.6.347 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "76703d96416393ed", "scanner": "scanner-primary", "fingerprint": "70bfc2840e418ae3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4367"]}}, {"ruleId": "scanner-1089be8b3e698ef7", "level": "error", "message": {"text": "CVE-2024-4367: pdfjs-dist 3.5.141 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "76703d96416393ed", "scanner": "scanner-primary", "fingerprint": "1089be8b3e698ef7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4367"]}}, {"ruleId": "scanner-e0a299fac3395bb6", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e839e0c5701d7124", "scanner": "scanner-primary", "fingerprint": "e0a299fac3395bb6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-295cf74d0dd553ff", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "bec7fd4f45677f72", "scanner": "scanner-primary", "fingerprint": "295cf74d0dd553ff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-e8a4ccba36b54be5", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.38 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4da6775dcbdc00cc", "scanner": "scanner-primary", "fingerprint": "e8a4ccba36b54be5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-b69fc47d00680aab", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.29.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c7ed60d3e7895f08", "scanner": "scanner-primary", "fingerprint": "b69fc47d00680aab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-70e2041e293e7e48", "level": "warning", "message": {"text": "CVE-2025-15284: qs 6.11.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1317bf85904f1ded", "scanner": "scanner-primary", "fingerprint": "70e2041e293e7e48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-15284"]}}, {"ruleId": "scanner-9ab1ecf3a7c41161", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.11.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ae7b9cfd723e68a8", "scanner": "scanner-primary", "fingerprint": "9ab1ecf3a7c41161", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-ef915955d39d009e", "level": "warning", "message": {"text": "CVE-2025-15284: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1317bf85904f1ded", "scanner": "scanner-primary", "fingerprint": "ef915955d39d009e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-15284"]}}, {"ruleId": "scanner-9567d4e2f3bd1216", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4d5d7a31db2a3b70", "scanner": "scanner-primary", "fingerprint": "9567d4e2f3bd1216", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-27e3f60904ecb2f4", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.12.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ae7b9cfd723e68a8", "scanner": "scanner-primary", "fingerprint": "27e3f60904ecb2f4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-ab92d670448c2bd8", "level": "note", "message": {"text": "CVE-2024-43799: send 0.18.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "191234e19431fe10", "scanner": "scanner-primary", "fingerprint": "ab92d670448c2bd8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43799"]}}, {"ruleId": "scanner-e6ad799bd3b8358c", "level": "error", "message": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d5f6405f674730ba", "scanner": "scanner-primary", "fingerprint": "e6ad799bd3b8358c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-5c6j-r48x-rmvq"]}}, {"ruleId": "scanner-5cc7487b1b836706", "level": "error", "message": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d5f6405f674730ba", "scanner": "scanner-primary", "fingerprint": "5cc7487b1b836706", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-5c6j-r48x-rmvq"]}}, {"ruleId": "scanner-b42f348bd2fb432d", "level": "warning", "message": {"text": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a2398327dc077771", "scanner": "scanner-primary", "fingerprint": "b42f348bd2fb432d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34043"]}}, {"ruleId": "scanner-461e401ebf9a57aa", "level": "note", "message": {"text": "CVE-2024-43800: serve-static 1.15.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "7cdfb380ac5c2d23", "scanner": "scanner-primary", "fingerprint": "461e401ebf9a57aa", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43800"]}}, {"ruleId": "scanner-d082d0c77dafc977", "level": "error", "message": {"text": "CVE-2025-9288: sha.js 2.4.11 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "da34687ad6367734", "scanner": "scanner-primary", "fingerprint": "d082d0c77dafc977", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-9288"]}}, {"ruleId": "scanner-fe754672f28824cc", "level": "error", "message": {"text": "CVE-2026-9277: shell-quote 1.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8ca3459e3ac1b609", "scanner": "scanner-primary", "fingerprint": "fe754672f28824cc", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9277"]}}, {"ruleId": "scanner-5af47bd4ec8df1d3", "level": "error", "message": {"text": "CVE-2026-13311: shell-quote 1.8.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ff24bff92a4cb162", "scanner": "scanner-primary", "fingerprint": "5af47bd4ec8df1d3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13311"]}}, {"ruleId": "scanner-2c0d6e4eb625f370", "level": "error", "message": {"text": "CVE-2026-59873: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ab9b3132a9b9c89e", "scanner": "scanner-primary", "fingerprint": "2c0d6e4eb625f370", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59873"]}}, {"ruleId": "scanner-fee1755c8b9fbc7b", "level": "error", "message": {"text": "CVE-2026-23745: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a32ad822fccda194", "scanner": "scanner-primary", "fingerprint": "fee1755c8b9fbc7b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23745"]}}, {"ruleId": "scanner-b764c833ab5f9585", "level": "error", "message": {"text": "CVE-2026-23950: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1f8db7ed40f23aa9", "scanner": "scanner-primary", "fingerprint": "b764c833ab5f9585", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23950"]}}, {"ruleId": "scanner-78778d0b4ad7680d", "level": "error", "message": {"text": "CVE-2026-24842: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "403bb5e757429559", "scanner": "scanner-primary", "fingerprint": "78778d0b4ad7680d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24842"]}}, {"ruleId": "scanner-cf3f7677f8ce8433", "level": "error", "message": {"text": "CVE-2026-26960: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "bf4f32441959858f", "scanner": "scanner-primary", "fingerprint": "cf3f7677f8ce8433", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26960"]}}, {"ruleId": "scanner-4ac1f51bae6d5a67", "level": "error", "message": {"text": "CVE-2026-29786: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "56ebd55da56cd03c", "scanner": "scanner-primary", "fingerprint": "4ac1f51bae6d5a67", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29786"]}}, {"ruleId": "scanner-0146cea8ec32c7df", "level": "error", "message": {"text": "CVE-2026-31802: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3dca9d6652054ed1", "scanner": "scanner-primary", "fingerprint": "0146cea8ec32c7df", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31802"]}}, {"ruleId": "scanner-d756f80dfa11ac7e", "level": "error", "message": {"text": "CVE-2026-59874: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "df0470518adc66e8", "scanner": "scanner-primary", "fingerprint": "d756f80dfa11ac7e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59874"]}}, {"ruleId": "scanner-e81920a6628ebe25", "level": "warning", "message": {"text": "CVE-2026-53655: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a3a21b7118e66767", "scanner": "scanner-primary", "fingerprint": "e81920a6628ebe25", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53655"]}}, {"ruleId": "scanner-f5131f2d0f0854cc", "level": "warning", "message": {"text": "CVE-2026-59871: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3ad2a94806c9fd13", "scanner": "scanner-primary", "fingerprint": "f5131f2d0f0854cc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59871"]}}, {"ruleId": "scanner-f019ce49be0cb3e8", "level": "warning", "message": {"text": "CVE-2026-59875: tar 6.2.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b6e06e9a856cb44d", "scanner": "scanner-primary", "fingerprint": "f019ce49be0cb3e8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59875"]}}, {"ruleId": "scanner-677e4affbb010d69", "level": "error", "message": {"text": "CVE-2026-44705: tmp 0.0.33 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8f1c443d614b44a0", "scanner": "scanner-primary", "fingerprint": "677e4affbb010d69", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44705"]}}, {"ruleId": "scanner-bac6a1c5d9159815", "level": "note", "message": {"text": "CVE-2025-54798: tmp 0.0.33 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ebb80efebcd4fae4", "scanner": "scanner-primary", "fingerprint": "bac6a1c5d9159815", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-54798"]}}, {"ruleId": "scanner-4b7433bb08a06b53", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a693aa0be37ecbb0", "scanner": "scanner-primary", "fingerprint": "4b7433bb08a06b53", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-dc6e0ced8855c06d", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a693aa0be37ecbb0", "scanner": "scanner-primary", "fingerprint": "dc6e0ced8855c06d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-4ddd5052a8691938", "level": "note", "message": {"text": "CVE-2024-9506: vue 2.7.16 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c7a28d6f1d79845a", "scanner": "scanner-primary", "fingerprint": "4ddd5052a8691938", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-9506"]}}, {"ruleId": "scanner-f0debd7897f8450a", "level": "error", "message": {"text": "CVE-2025-27597: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fe1aae8b8aaa42dc", "scanner": "scanner-primary", "fingerprint": "f0debd7897f8450a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27597"]}}, {"ruleId": "scanner-400549ac70acf431", "level": "warning", "message": {"text": "CVE-2024-52809: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "930cfa2b2ffe8fbd", "scanner": "scanner-primary", "fingerprint": "400549ac70acf431", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52809"]}}, {"ruleId": "scanner-0c1686713ba79f97", "level": "warning", "message": {"text": "CVE-2024-52810: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ffadc10e3ce830dc", "scanner": "scanner-primary", "fingerprint": "0c1686713ba79f97", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52810"]}}, {"ruleId": "scanner-f2e565710cc0fc04", "level": "warning", "message": {"text": "CVE-2025-53892: vue-i18n 9.13.1 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b971b983105704b5", "scanner": "scanner-primary", "fingerprint": "f2e565710cc0fc04", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53892"]}}, {"ruleId": "scanner-06304a0528a9013a", "level": "warning", "message": {"text": "CVE-2024-43788: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6896fdeb991fb356", "scanner": "scanner-primary", "fingerprint": "06304a0528a9013a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43788"]}}, {"ruleId": "scanner-a430daae123a8817", "level": "note", "message": {"text": "CVE-2025-68157: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "667ed42f90049c85", "scanner": "scanner-primary", "fingerprint": "a430daae123a8817", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68157"]}}, {"ruleId": "scanner-ed2ce49888cda742", "level": "note", "message": {"text": "CVE-2025-68458: webpack 5.91.0 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6c7c070b1267e829", "scanner": "scanner-primary", "fingerprint": "ed2ce49888cda742", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68458"]}}, {"ruleId": "scanner-f909497092c44f4a", "level": "error", "message": {"text": "CVE-2024-37890: ws 7.5.9 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a73bd5f777819aca", "scanner": "scanner-primary", "fingerprint": "f909497092c44f4a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-37890"]}}, {"ruleId": "scanner-8724c57681087597", "level": "error", "message": {"text": "CVE-2026-48779: ws 7.5.9 \u2014 archive/kt-sft/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d63ea64bb8c50333", "scanner": "scanner-primary", "fingerprint": "8724c57681087597", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-48de6843214cf0aa", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.24.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "3fda3b723e6fb9b4", "scanner": "scanner-primary", "fingerprint": "48de6843214cf0aa", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-fd2e68d60dd582ad", "level": "warning", "message": {"text": "CVE-2025-27789: @babel/helpers 7.24.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "13ffcc2c750d0219", "scanner": "scanner-primary", "fingerprint": "fd2e68d60dd582ad", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27789"]}}, {"ruleId": "scanner-c142bf74bf2f61b0", "level": "error", "message": {"text": "CVE-2026-44728: @babel/plugin-transform-modules-systemjs 7.24.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4f41a814cb387e0b", "scanner": "scanner-primary", "fingerprint": "c142bf74bf2f61b0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44728"]}}, {"ruleId": "scanner-520a523287f6372f", "level": "warning", "message": {"text": "CVE-2025-27789: @babel/runtime 7.24.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f38f27f734782af2", "scanner": "scanner-primary", "fingerprint": "520a523287f6372f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27789"]}}, {"ruleId": "scanner-7382f4e949db04bb", "level": "warning", "message": {"text": "CVE-2024-52809: @intlify/core-base 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b77107805f15ba12", "scanner": "scanner-primary", "fingerprint": "7382f4e949db04bb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52809"]}}, {"ruleId": "scanner-4f6212dc4954467e", "level": "warning", "message": {"text": "CVE-2025-53892: @intlify/core-base 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "86783621f9d1ab7c", "scanner": "scanner-primary", "fingerprint": "4f6212dc4954467e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53892"]}}, {"ruleId": "scanner-6232fc13b77d82bb", "level": "warning", "message": {"text": "CVE-2024-52810: @intlify/shared 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "059398607094b191", "scanner": "scanner-primary", "fingerprint": "6232fc13b77d82bb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52810"]}}, {"ruleId": "scanner-2e97a382ed73b802", "level": "warning", "message": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ccd5e3299f0d1686", "scanner": "scanner-primary", "fingerprint": "2e97a382ed73b802", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44288"]}}, {"ruleId": "scanner-2a54ea989f4db767", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 6.12.6 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "59d6d6dd05a244bb", "scanner": "scanner-primary", "fingerprint": "2a54ea989f4db767", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-035b7994f8f26f5f", "level": "warning", "message": {"text": "GHSA-9q82-xgwf-vj6h: apollo-server-core 3.13.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e404bfb73fc991a7", "scanner": "scanner-primary", "fingerprint": "035b7994f8f26f5f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-9q82-xgwf-vj6h"]}}, {"ruleId": "scanner-556838da5eafe399", "level": "error", "message": {"text": "CVE-2024-39338: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b4b26dadc84742d1", "scanner": "scanner-primary", "fingerprint": "556838da5eafe399", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-39338"]}}, {"ruleId": "scanner-e53ffbb6622f9072", "level": "error", "message": {"text": "CVE-2025-27152: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "0466883dee8173fc", "scanner": "scanner-primary", "fingerprint": "e53ffbb6622f9072", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27152"]}}, {"ruleId": "scanner-74578cd6ba4c512d", "level": "error", "message": {"text": "CVE-2025-58754: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "20132588a365b8da", "scanner": "scanner-primary", "fingerprint": "74578cd6ba4c512d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-58754"]}}, {"ruleId": "scanner-34e4558d3c078c07", "level": "error", "message": {"text": "CVE-2026-25639: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "252f0adf90f3a44d", "scanner": "scanner-primary", "fingerprint": "34e4558d3c078c07", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25639"]}}, {"ruleId": "scanner-db1bba77e5567a88", "level": "error", "message": {"text": "CVE-2026-42033: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4b46e6d29d11258f", "scanner": "scanner-primary", "fingerprint": "db1bba77e5567a88", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42033"]}}, {"ruleId": "scanner-c8206852131fe6db", "level": "error", "message": {"text": "CVE-2026-42035: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "34511b74b77f90be", "scanner": "scanner-primary", "fingerprint": "c8206852131fe6db", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42035"]}}, {"ruleId": "scanner-1d0d934af9ef4742", "level": "error", "message": {"text": "CVE-2026-42043: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d9787903184510f4", "scanner": "scanner-primary", "fingerprint": "1d0d934af9ef4742", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42043"]}}, {"ruleId": "scanner-1915bb304b2df785", "level": "error", "message": {"text": "CVE-2026-42264: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8a0b1c2ea1e7c500", "scanner": "scanner-primary", "fingerprint": "1915bb304b2df785", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42264"]}}, {"ruleId": "scanner-858014d6850b81e9", "level": "error", "message": {"text": "CVE-2026-44486: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fb736baf1d02ad2f", "scanner": "scanner-primary", "fingerprint": "858014d6850b81e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44486"]}}, {"ruleId": "scanner-6ab36798ab560bf4", "level": "error", "message": {"text": "CVE-2026-44487: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "364351ca3c6bc139", "scanner": "scanner-primary", "fingerprint": "6ab36798ab560bf4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44487"]}}, {"ruleId": "scanner-670a2142ab536d5e", "level": "error", "message": {"text": "CVE-2026-44488: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c06d52e27a864d78", "scanner": "scanner-primary", "fingerprint": "670a2142ab536d5e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44488"]}}, {"ruleId": "scanner-bb0d147883a54e42", "level": "error", "message": {"text": "CVE-2026-44494: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f1152e07af8edf17", "scanner": "scanner-primary", "fingerprint": "bb0d147883a54e42", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44494"]}}, {"ruleId": "scanner-93eae9a9be1fe156", "level": "error", "message": {"text": "CVE-2026-44495: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "7d78fd1fdaad4371", "scanner": "scanner-primary", "fingerprint": "93eae9a9be1fe156", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44495"]}}, {"ruleId": "scanner-0dcc16a006b5c97d", "level": "error", "message": {"text": "CVE-2026-44496: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "21bb53f9146d5f25", "scanner": "scanner-primary", "fingerprint": "0dcc16a006b5c97d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44496"]}}, {"ruleId": "scanner-5e27403edc4234c0", "level": "warning", "message": {"text": "CVE-2025-62718: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e81eaa5be8de1417", "scanner": "scanner-primary", "fingerprint": "5e27403edc4234c0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62718"]}}, {"ruleId": "scanner-61329ed2afb25393", "level": "warning", "message": {"text": "CVE-2026-40175: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cbfba236b657e54a", "scanner": "scanner-primary", "fingerprint": "61329ed2afb25393", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40175"]}}, {"ruleId": "scanner-366947cc0f6851b7", "level": "warning", "message": {"text": "CVE-2026-42034: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "da0ba22efa0d86cd", "scanner": "scanner-primary", "fingerprint": "366947cc0f6851b7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42034"]}}, {"ruleId": "scanner-ebe484f24f310fd7", "level": "warning", "message": {"text": "CVE-2026-42036: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "140a51c07ae2a334", "scanner": "scanner-primary", "fingerprint": "ebe484f24f310fd7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42036"]}}, {"ruleId": "scanner-f130720a1f28b7fe", "level": "warning", "message": {"text": "CVE-2026-42037: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "424552814245f352", "scanner": "scanner-primary", "fingerprint": "f130720a1f28b7fe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42037"]}}, {"ruleId": "scanner-f605ce0bb2f97725", "level": "warning", "message": {"text": "CVE-2026-42038: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b5df395124fce25b", "scanner": "scanner-primary", "fingerprint": "f605ce0bb2f97725", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42038"]}}, {"ruleId": "scanner-a420180cd6f0fc49", "level": "warning", "message": {"text": "CVE-2026-42039: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6a37c0732e7c484a", "scanner": "scanner-primary", "fingerprint": "a420180cd6f0fc49", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42039"]}}, {"ruleId": "scanner-f4e380e19f2f7ab3", "level": "warning", "message": {"text": "CVE-2026-42041: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f6509145ccfb6037", "scanner": "scanner-primary", "fingerprint": "f4e380e19f2f7ab3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42041"]}}, {"ruleId": "scanner-a9e189291225c298", "level": "warning", "message": {"text": "CVE-2026-42042: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cf93ad10c93b1b6c", "scanner": "scanner-primary", "fingerprint": "a9e189291225c298", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42042"]}}, {"ruleId": "scanner-ba677091ab0c793d", "level": "warning", "message": {"text": "CVE-2026-42044: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "bff9f8a3003aed20", "scanner": "scanner-primary", "fingerprint": "ba677091ab0c793d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42044"]}}, {"ruleId": "scanner-ef56a36f194d9b1b", "level": "warning", "message": {"text": "CVE-2026-44490: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fe4ec8a85249a5c4", "scanner": "scanner-primary", "fingerprint": "ef56a36f194d9b1b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44490"]}}, {"ruleId": "scanner-634c3c21fabc60c5", "level": "warning", "message": {"text": "GHSA-42h9-826w-cgv3: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "65f24cea87456cdd", "scanner": "scanner-primary", "fingerprint": "634c3c21fabc60c5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-42h9-826w-cgv3"]}}, {"ruleId": "scanner-c5ba7d03e8e399c9", "level": "warning", "message": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e3eacdbe51d72d4e", "scanner": "scanner-primary", "fingerprint": "c5ba7d03e8e399c9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-7q8q-rj6j-mhjq"]}}, {"ruleId": "scanner-1a42a512d751498b", "level": "warning", "message": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "aa2cc255c10d7ad0", "scanner": "scanner-primary", "fingerprint": "1a42a512d751498b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-jqh4-m9w3-8hp9"]}}, {"ruleId": "scanner-d9697aa75a986abd", "level": "warning", "message": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "abd44f7ba1ca3794", "scanner": "scanner-primary", "fingerprint": "d9697aa75a986abd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mmx7-hfxf-jppx"]}}, {"ruleId": "scanner-004e946ecec65e3f", "level": "warning", "message": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "48e26f731e1ca598", "scanner": "scanner-primary", "fingerprint": "004e946ecec65e3f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-pmv8-rq9r-6j72"]}}, {"ruleId": "scanner-60a22ddd0e88750a", "level": "note", "message": {"text": "CVE-2026-42040: axios 1.7.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "581c15f2c293e674", "scanner": "scanner-primary", "fingerprint": "60a22ddd0e88750a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42040"]}}, {"ruleId": "scanner-959f7a8f194318de", "level": "warning", "message": {"text": "CVE-2026-2739: bn.js 4.12.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4511d41c0aa06044", "scanner": "scanner-primary", "fingerprint": "959f7a8f194318de", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2739"]}}, {"ruleId": "scanner-25afec95b0279d56", "level": "warning", "message": {"text": "CVE-2026-2739: bn.js 5.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4511d41c0aa06044", "scanner": "scanner-primary", "fingerprint": "25afec95b0279d56", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2739"]}}, {"ruleId": "scanner-c22fc7c8cb27b9ed", "level": "error", "message": {"text": "CVE-2024-45590: body-parser 1.20.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b489a6cc836f96db", "scanner": "scanner-primary", "fingerprint": "c22fc7c8cb27b9ed", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-45590"]}}, {"ruleId": "scanner-6acfb7291d8a5921", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "168abde798c76c63", "scanner": "scanner-primary", "fingerprint": "6acfb7291d8a5921", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-e031f71f0a778eee", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d49c0466842941e5", "scanner": "scanner-primary", "fingerprint": "e031f71f0a778eee", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-0743551610c20ebf", "level": "warning", "message": {"text": "CVE-2026-33750: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d8f569f5373189ed", "scanner": "scanner-primary", "fingerprint": "0743551610c20ebf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33750"]}}, {"ruleId": "scanner-0b7e3b0dac68fb04", "level": "note", "message": {"text": "CVE-2025-5889: brace-expansion 1.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "be7baef46f9073bd", "scanner": "scanner-primary", "fingerprint": "0b7e3b0dac68fb04", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5889"]}}, {"ruleId": "scanner-fb409be30d2e8845", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d49c0466842941e5", "scanner": "scanner-primary", "fingerprint": "fb409be30d2e8845", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-73a9a7f4b72f158b", "level": "warning", "message": {"text": "CVE-2026-33750: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d8f569f5373189ed", "scanner": "scanner-primary", "fingerprint": "73a9a7f4b72f158b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33750"]}}, {"ruleId": "scanner-e338abbe8726a576", "level": "note", "message": {"text": "CVE-2025-5889: brace-expansion 2.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "be7baef46f9073bd", "scanner": "scanner-primary", "fingerprint": "e338abbe8726a576", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-5889"]}}, {"ruleId": "scanner-06a92ce6dc1ed278", "level": "error", "message": {"text": "CVE-2024-4068: braces 2.3.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c5fb044b9f7a1923", "scanner": "scanner-primary", "fingerprint": "06a92ce6dc1ed278", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4068"]}}, {"ruleId": "scanner-4b2cd767e53ca073", "level": "error", "message": {"text": "CVE-2024-4068: braces 3.0.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c5fb044b9f7a1923", "scanner": "scanner-primary", "fingerprint": "4b2cd767e53ca073", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4068"]}}, {"ruleId": "scanner-418d4a5d97cc034e", "level": "error", "message": {"text": "CVE-2025-9287: cipher-base 1.0.4 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fc20ac0baca80e40", "scanner": "scanner-primary", "fingerprint": "418d4a5d97cc034e", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-9287"]}}, {"ruleId": "scanner-0a232bf0ff77a9fd", "level": "note", "message": {"text": "CVE-2024-47764: cookie 0.6.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ff540467fa94d588", "scanner": "scanner-primary", "fingerprint": "0a232bf0ff77a9fd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-47764"]}}, {"ruleId": "scanner-0cbf7c92d8cbf747", "level": "error", "message": {"text": "CVE-2024-21538: cross-spawn 6.0.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2b05d2973a3c0895", "scanner": "scanner-primary", "fingerprint": "0cbf7c92d8cbf747", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-21538"]}}, {"ruleId": "scanner-ad7bf98f8378bc50", "level": "error", "message": {"text": "CVE-2024-21538: cross-spawn 7.0.3 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2b05d2973a3c0895", "scanner": "scanner-primary", "fingerprint": "ad7bf98f8378bc50", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-21538"]}}, {"ruleId": "scanner-f63871d5be5903a9", "level": "error", "message": {"text": "CVE-2026-53486: decompress 4.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fcb6d9711e63f575", "scanner": "scanner-primary", "fingerprint": "f63871d5be5903a9", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53486"]}}, {"ruleId": "scanner-e8b9eed7385eae85", "level": "warning", "message": {"text": "CVE-2025-57665: element-plus 2.7.3 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e1cce3bf831dad44", "scanner": "scanner-primary", "fingerprint": "e8b9eed7385eae85", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-57665"]}}, {"ruleId": "scanner-d5e2039e7c2f94e4", "level": "error", "message": {"text": "GHSA-vjh7-7g9h-fjfh: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "223cbacc1317d4ca", "scanner": "scanner-primary", "fingerprint": "d5e2039e7c2f94e4", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vjh7-7g9h-fjfh"]}}, {"ruleId": "scanner-c33d7b4293a7286c", "level": "note", "message": {"text": "CVE-2024-42459: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1b72e9f7abc3d42a", "scanner": "scanner-primary", "fingerprint": "c33d7b4293a7286c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-42459"]}}, {"ruleId": "scanner-ed2ab25aa296c14d", "level": "note", "message": {"text": "CVE-2024-42460: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8501de763835eb41", "scanner": "scanner-primary", "fingerprint": "ed2ab25aa296c14d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-42460"]}}, {"ruleId": "scanner-6a7715af16179dec", "level": "note", "message": {"text": "CVE-2024-42461: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ffcb784243803c5b", "scanner": "scanner-primary", "fingerprint": "6a7715af16179dec", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-42461"]}}, {"ruleId": "scanner-d7900233c77bc74f", "level": "note", "message": {"text": "CVE-2024-48948: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cb5d4898638d5d36", "scanner": "scanner-primary", "fingerprint": "d7900233c77bc74f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-48948"]}}, {"ruleId": "scanner-ef3580b49c25ac78", "level": "note", "message": {"text": "CVE-2024-48949: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "94d102e795c026a8", "scanner": "scanner-primary", "fingerprint": "ef3580b49c25ac78", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-48949"]}}, {"ruleId": "scanner-3b585f2ada50e5cc", "level": "note", "message": {"text": "CVE-2025-14505: elliptic 6.5.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c75bcb970b39e3f0", "scanner": "scanner-primary", "fingerprint": "3b585f2ada50e5cc", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-14505"]}}, {"ruleId": "scanner-5eb39be20a7f3622", "level": "note", "message": {"text": "CVE-2024-43796: express 4.19.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "2106d5bab97a2d73", "scanner": "scanner-primary", "fingerprint": "5eb39be20a7f3622", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43796"]}}, {"ruleId": "scanner-467bce10e59a0743", "level": "warning", "message": {"text": "GHSA-r4q5-vmmm-2653: follow-redirects 1.15.6 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4e5688aebc06582a", "scanner": "scanner-primary", "fingerprint": "467bce10e59a0743", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-r4q5-vmmm-2653"]}}, {"ruleId": "scanner-bc3c8700f12de0ad", "level": "error", "message": {"text": "CVE-2025-7783: form-data 4.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ac479f71d29c2ce4", "scanner": "scanner-primary", "fingerprint": "bc3c8700f12de0ad", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-7783"]}}, {"ruleId": "scanner-e460781466755821", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4a5731d8859d63da", "scanner": "scanner-primary", "fingerprint": "e460781466755821", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-067e60b37b41449c", "level": "error", "message": {"text": "CVE-2022-25900: git-clone 0.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "9925447fb67cc944", "scanner": "scanner-primary", "fingerprint": "067e60b37b41449c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2022-25900"]}}, {"ruleId": "scanner-4dfa2692e20940ae", "level": "warning", "message": {"text": "CVE-2022-33987: got 8.3.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cf1eafdd3106b557", "scanner": "scanner-primary", "fingerprint": "4dfa2692e20940ae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2022-33987"]}}, {"ruleId": "scanner-a5f756f682587b8a", "level": "error", "message": {"text": "CVE-2022-25881: http-cache-semantics 3.8.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "71b634e83803d367", "scanner": "scanner-primary", "fingerprint": "a5f756f682587b8a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2022-25881"]}}, {"ruleId": "scanner-0c7f388699d73ca7", "level": "warning", "message": {"text": "CVE-2026-48038: joi 17.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a1e5b2553ffdf3c0", "scanner": "scanner-primary", "fingerprint": "0c7f388699d73ca7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48038"]}}, {"ruleId": "scanner-3a7f5b7b8c970555", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4c91981761cd96a7", "scanner": "scanner-primary", "fingerprint": "3a7f5b7b8c970555", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-c2fcb6067e24ed3f", "level": "warning", "message": {"text": "CVE-2025-64718: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e6e57b913d15a0ba", "scanner": "scanner-primary", "fingerprint": "c2fcb6067e24ed3f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-64718"]}}, {"ruleId": "scanner-a422ddde33da1cae", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 3.14.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8dbc7a74e32e0bcc", "scanner": "scanner-primary", "fingerprint": "a422ddde33da1cae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-99f92ac312dcccc4", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "4c91981761cd96a7", "scanner": "scanner-primary", "fingerprint": "99f92ac312dcccc4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-6807e87c4d44eff0", "level": "warning", "message": {"text": "CVE-2025-64718: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e6e57b913d15a0ba", "scanner": "scanner-primary", "fingerprint": "6807e87c4d44eff0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-64718"]}}, {"ruleId": "scanner-6ab31fadec361b80", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8dbc7a74e32e0bcc", "scanner": "scanner-primary", "fingerprint": "6ab31fadec361b80", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-7e3874b726441b54", "level": "error", "message": {"text": "CVE-2024-52011: launch-editor 2.6.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a8a3241367941386", "scanner": "scanner-primary", "fingerprint": "7e3874b726441b54", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52011"]}}, {"ruleId": "scanner-d9b00b53939d81cd", "level": "warning", "message": {"text": "CVE-2026-53632: launch-editor 2.6.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "5ab54c3d225e800f", "scanner": "scanner-primary", "fingerprint": "d9b00b53939d81cd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-08e1960dee695ba2", "level": "error", "message": {"text": "CVE-2026-4800: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "0dc7602c97c90135", "scanner": "scanner-primary", "fingerprint": "08e1960dee695ba2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-fd1141aadca181b3", "level": "warning", "message": {"text": "CVE-2025-13465: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a8aebd2a30f4b337", "scanner": "scanner-primary", "fingerprint": "fd1141aadca181b3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-e4c4ca61e123053a", "level": "warning", "message": {"text": "CVE-2026-2950: lodash 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d2e69a5bee12a2eb", "scanner": "scanner-primary", "fingerprint": "e4c4ca61e123053a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-6faecbfe0f4a3ec2", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "7e14a79ff6f5720a", "scanner": "scanner-primary", "fingerprint": "6faecbfe0f4a3ec2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-3f89bf0191d18f18", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "568368a35b011522", "scanner": "scanner-primary", "fingerprint": "3f89bf0191d18f18", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-dc1fc60b6261dd0b", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "61ee2ef0be9c76ab", "scanner": "scanner-primary", "fingerprint": "dc1fc60b6261dd0b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-b2e05ead1e0a3af6", "level": "warning", "message": {"text": "CVE-2024-4067: micromatch 3.1.10 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "64fc1417d7c8b994", "scanner": "scanner-primary", "fingerprint": "b2e05ead1e0a3af6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4067"]}}, {"ruleId": "scanner-44f1e4d00c533930", "level": "warning", "message": {"text": "CVE-2024-4067: micromatch 4.0.5 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "64fc1417d7c8b994", "scanner": "scanner-primary", "fingerprint": "44f1e4d00c533930", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4067"]}}, {"ruleId": "scanner-0b97a9287eedcd99", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "aa9372d6d76496da", "scanner": "scanner-primary", "fingerprint": "0b97a9287eedcd99", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-4aa3a8a3c29f9b0b", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "62c75e59e95f341c", "scanner": "scanner-primary", "fingerprint": "4aa3a8a3c29f9b0b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-e3d0f6f84303a97d", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f4a04e159d5c2209", "scanner": "scanner-primary", "fingerprint": "e3d0f6f84303a97d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-89e151cbdcfac4ac", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "aa9372d6d76496da", "scanner": "scanner-primary", "fingerprint": "89e151cbdcfac4ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-39520f7f4587fa3b", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "62c75e59e95f341c", "scanner": "scanner-primary", "fingerprint": "39520f7f4587fa3b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-a2b466e60f48cd5d", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 5.1.6 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f4a04e159d5c2209", "scanner": "scanner-primary", "fingerprint": "a2b466e60f48cd5d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-250abafcdd7a7048", "level": "warning", "message": {"text": "CVE-2024-55565: nanoid 2.1.11 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8a65abc3f3af1113", "scanner": "scanner-primary", "fingerprint": "250abafcdd7a7048", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-55565"]}}, {"ruleId": "scanner-370748266a09a7ab", "level": "warning", "message": {"text": "CVE-2024-55565: nanoid 3.3.7 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "8a65abc3f3af1113", "scanner": "scanner-primary", "fingerprint": "370748266a09a7ab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-55565"]}}, {"ruleId": "scanner-16bff9f079a3b2cc", "level": "error", "message": {"text": "CVE-2025-25975: parse-git-config 3.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "47e7d63d08dbf2e4", "scanner": "scanner-primary", "fingerprint": "16bff9f079a3b2cc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-25975"]}}, {"ruleId": "scanner-d3e037ec0bf00072", "level": "error", "message": {"text": "CVE-2024-45296: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "fe1db9c85ad60ebb", "scanner": "scanner-primary", "fingerprint": "d3e037ec0bf00072", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-45296"]}}, {"ruleId": "scanner-ae847b7babf71822", "level": "error", "message": {"text": "CVE-2024-52798: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "5809388c502f5d29", "scanner": "scanner-primary", "fingerprint": "ae847b7babf71822", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52798"]}}, {"ruleId": "scanner-c310bb690eb1a9d5", "level": "error", "message": {"text": "CVE-2026-4867: path-to-regexp 0.1.7 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "9b2684f117750ec4", "scanner": "scanner-primary", "fingerprint": "c310bb690eb1a9d5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4867"]}}, {"ruleId": "scanner-6361044321b3b5f5", "level": "error", "message": {"text": "CVE-2025-6545: pbkdf2 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a2beaaf9c78a8fca", "scanner": "scanner-primary", "fingerprint": "6361044321b3b5f5", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6545"]}}, {"ruleId": "scanner-058c40d32441ba28", "level": "error", "message": {"text": "CVE-2025-6547: pbkdf2 3.1.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "71dd526220c122b4", "scanner": "scanner-primary", "fingerprint": "058c40d32441ba28", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-6547"]}}, {"ruleId": "scanner-43752afd4a9c7e66", "level": "error", "message": {"text": "CVE-2024-4367: pdfjs-dist 2.6.347 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "493c0ecb51f8f874", "scanner": "scanner-primary", "fingerprint": "43752afd4a9c7e66", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4367"]}}, {"ruleId": "scanner-76fa9d930a700c54", "level": "error", "message": {"text": "CVE-2024-4367: pdfjs-dist 3.5.141 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "493c0ecb51f8f874", "scanner": "scanner-primary", "fingerprint": "76fa9d930a700c54", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-4367"]}}, {"ruleId": "scanner-dc454d1512caa955", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e6107d37f224cdd8", "scanner": "scanner-primary", "fingerprint": "dc454d1512caa955", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-1592c702e7685c8c", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "6c188e1b0c22e539", "scanner": "scanner-primary", "fingerprint": "1592c702e7685c8c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-1f81ee1e159514aa", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.38 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "52d0491077dc4d98", "scanner": "scanner-primary", "fingerprint": "1f81ee1e159514aa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-7b3249c1232669ad", "level": "warning", "message": {"text": "CVE-2024-53382: prismjs 1.29.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "609bf6ad5ed8b85b", "scanner": "scanner-primary", "fingerprint": "7b3249c1232669ad", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-53382"]}}, {"ruleId": "scanner-d79c22ca4aa4195d", "level": "warning", "message": {"text": "CVE-2025-15284: qs 6.11.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f347d8edfea384fd", "scanner": "scanner-primary", "fingerprint": "d79c22ca4aa4195d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-15284"]}}, {"ruleId": "scanner-cdf06edd6a91ac09", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.11.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "30f931add67e5ae1", "scanner": "scanner-primary", "fingerprint": "cdf06edd6a91ac09", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-c029abf160b1d926", "level": "warning", "message": {"text": "CVE-2025-15284: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "f347d8edfea384fd", "scanner": "scanner-primary", "fingerprint": "c029abf160b1d926", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-15284"]}}, {"ruleId": "scanner-98c6b9034b24a418", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "1483e2cd96dadb10", "scanner": "scanner-primary", "fingerprint": "98c6b9034b24a418", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-9e962d86de05cb60", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.12.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "30f931add67e5ae1", "scanner": "scanner-primary", "fingerprint": "9e962d86de05cb60", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-5e1c629f230ccdcb", "level": "note", "message": {"text": "CVE-2024-43799: send 0.18.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "956d44ab5383619c", "scanner": "scanner-primary", "fingerprint": "5e1c629f230ccdcb", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43799"]}}, {"ruleId": "scanner-65d441ec7c27b309", "level": "error", "message": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 4.0.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "668aa5d2614ffbb3", "scanner": "scanner-primary", "fingerprint": "65d441ec7c27b309", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-5c6j-r48x-rmvq"]}}, {"ruleId": "scanner-bdb36b2a3a4e8f64", "level": "error", "message": {"text": "GHSA-5c6j-r48x-rmvq: serialize-javascript 6.0.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "668aa5d2614ffbb3", "scanner": "scanner-primary", "fingerprint": "bdb36b2a3a4e8f64", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-5c6j-r48x-rmvq"]}}, {"ruleId": "scanner-6f1bd69cf8319d1f", "level": "warning", "message": {"text": "CVE-2026-34043: serialize-javascript 6.0.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d4969f51fec4adf6", "scanner": "scanner-primary", "fingerprint": "6f1bd69cf8319d1f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34043"]}}, {"ruleId": "scanner-a24dcbd31340cccd", "level": "note", "message": {"text": "CVE-2024-43800: serve-static 1.15.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "32487d29a2d86345", "scanner": "scanner-primary", "fingerprint": "a24dcbd31340cccd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43800"]}}, {"ruleId": "scanner-61a1e9e84b129cfb", "level": "error", "message": {"text": "CVE-2025-9288: sha.js 2.4.11 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "002f207c40f1a72b", "scanner": "scanner-primary", "fingerprint": "61a1e9e84b129cfb", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-9288"]}}, {"ruleId": "scanner-fdd8532e36b4e4e5", "level": "error", "message": {"text": "CVE-2026-9277: shell-quote 1.8.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "9408f3de73b3c497", "scanner": "scanner-primary", "fingerprint": "fdd8532e36b4e4e5", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9277"]}}, {"ruleId": "scanner-167a4f730d379a8b", "level": "error", "message": {"text": "CVE-2026-13311: shell-quote 1.8.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c4737686ae6d4911", "scanner": "scanner-primary", "fingerprint": "167a4f730d379a8b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13311"]}}, {"ruleId": "scanner-538dc6f071316881", "level": "error", "message": {"text": "CVE-2026-59873: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "5ed863b0042e84bf", "scanner": "scanner-primary", "fingerprint": "538dc6f071316881", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59873"]}}, {"ruleId": "scanner-6bb682832c15660a", "level": "error", "message": {"text": "CVE-2026-23745: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "78bba141fab12218", "scanner": "scanner-primary", "fingerprint": "6bb682832c15660a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23745"]}}, {"ruleId": "scanner-c5f13fec4b265428", "level": "error", "message": {"text": "CVE-2026-23950: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a0beb7fe68fdb28a", "scanner": "scanner-primary", "fingerprint": "c5f13fec4b265428", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23950"]}}, {"ruleId": "scanner-2b4cf5b6ed31b696", "level": "error", "message": {"text": "CVE-2026-24842: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "41b12e5923c6a7d2", "scanner": "scanner-primary", "fingerprint": "2b4cf5b6ed31b696", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24842"]}}, {"ruleId": "scanner-af511a02c4ec1c40", "level": "error", "message": {"text": "CVE-2026-26960: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b1085b58e37f83b8", "scanner": "scanner-primary", "fingerprint": "af511a02c4ec1c40", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26960"]}}, {"ruleId": "scanner-11bb63a25ef9fb4c", "level": "error", "message": {"text": "CVE-2026-29786: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "90e946e5c11f4b07", "scanner": "scanner-primary", "fingerprint": "11bb63a25ef9fb4c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29786"]}}, {"ruleId": "scanner-90c90ac7d88e2a4c", "level": "error", "message": {"text": "CVE-2026-31802: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "d8a29b2bf3bf8b88", "scanner": "scanner-primary", "fingerprint": "90c90ac7d88e2a4c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31802"]}}, {"ruleId": "scanner-3aceeb2b5e26f0f8", "level": "error", "message": {"text": "CVE-2026-59874: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "e75ecd2ce6257ba3", "scanner": "scanner-primary", "fingerprint": "3aceeb2b5e26f0f8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59874"]}}, {"ruleId": "scanner-a7f8290d198c79d2", "level": "warning", "message": {"text": "CVE-2026-53655: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cfc93aff9a0ec061", "scanner": "scanner-primary", "fingerprint": "a7f8290d198c79d2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53655"]}}, {"ruleId": "scanner-d213454d3f39e1c1", "level": "warning", "message": {"text": "CVE-2026-59871: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "536ce6bef191fd45", "scanner": "scanner-primary", "fingerprint": "d213454d3f39e1c1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59871"]}}, {"ruleId": "scanner-2694ea824638a8bd", "level": "warning", "message": {"text": "CVE-2026-59875: tar 6.2.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "57801b8a6f89072d", "scanner": "scanner-primary", "fingerprint": "2694ea824638a8bd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59875"]}}, {"ruleId": "scanner-41e433416f3f024e", "level": "error", "message": {"text": "CVE-2026-44705: tmp 0.0.33 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "ed81069ed0516e0c", "scanner": "scanner-primary", "fingerprint": "41e433416f3f024e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44705"]}}, {"ruleId": "scanner-f052bbdcc44e4d20", "level": "note", "message": {"text": "CVE-2025-54798: tmp 0.0.33 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "01d20cfa5a9e2c10", "scanner": "scanner-primary", "fingerprint": "f052bbdcc44e4d20", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-54798"]}}, {"ruleId": "scanner-4948c080f294ecc4", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c636f116be8e0115", "scanner": "scanner-primary", "fingerprint": "4948c080f294ecc4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-89c1e2d55d362bcf", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c636f116be8e0115", "scanner": "scanner-primary", "fingerprint": "89c1e2d55d362bcf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-a6c5896611da0c66", "level": "note", "message": {"text": "CVE-2024-9506: vue 2.7.16 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "149014b04c7a9a3b", "scanner": "scanner-primary", "fingerprint": "a6c5896611da0c66", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-9506"]}}, {"ruleId": "scanner-705590938c9fa6d8", "level": "error", "message": {"text": "CVE-2025-27597: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a1ef2f044eadd182", "scanner": "scanner-primary", "fingerprint": "705590938c9fa6d8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-27597"]}}, {"ruleId": "scanner-4129bad75d05a56e", "level": "warning", "message": {"text": "CVE-2024-52809: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "32afc655dc187a08", "scanner": "scanner-primary", "fingerprint": "4129bad75d05a56e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52809"]}}, {"ruleId": "scanner-15150ddd6b3a3e19", "level": "warning", "message": {"text": "CVE-2024-52810: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "cad82b5d9ca2932e", "scanner": "scanner-primary", "fingerprint": "15150ddd6b3a3e19", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-52810"]}}, {"ruleId": "scanner-a11ba25b8be738a2", "level": "warning", "message": {"text": "CVE-2025-53892: vue-i18n 9.13.1 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "49f66f0ef6546387", "scanner": "scanner-primary", "fingerprint": "a11ba25b8be738a2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-53892"]}}, {"ruleId": "scanner-f0db9d2c9e113a6a", "level": "warning", "message": {"text": "CVE-2024-43788: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "a67c8cf47762f54c", "scanner": "scanner-primary", "fingerprint": "f0db9d2c9e113a6a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-43788"]}}, {"ruleId": "scanner-aa06edcb5abdc111", "level": "note", "message": {"text": "CVE-2025-68157: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "b0ab691818ec1772", "scanner": "scanner-primary", "fingerprint": "aa06edcb5abdc111", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68157"]}}, {"ruleId": "scanner-b58dc387b73025f6", "level": "note", "message": {"text": "CVE-2025-68458: webpack 5.91.0 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "baa7b38e967694d3", "scanner": "scanner-primary", "fingerprint": "b58dc387b73025f6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68458"]}}, {"ruleId": "scanner-b860885f46e9aae7", "level": "error", "message": {"text": "CVE-2024-37890: ws 7.5.9 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "c2d9d26978ef022e", "scanner": "scanner-primary", "fingerprint": "b860885f46e9aae7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-37890"]}}, {"ruleId": "scanner-a243ec813c793d56", "level": "error", "message": {"text": "CVE-2026-48779: ws 7.5.9 \u2014 archive/ktransformers/website/package-lock.json"}, "properties": {"repobilityId": "9579a043a3f651d6", "scanner": "scanner-primary", "fingerprint": "a243ec813c793d56", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-3ee598ca43700591", "level": "note", "message": {"text": "CVE-2025-3000: torch 2.9.1 \u2014 kt-kernel/requirements.txt"}, "properties": {"repobilityId": "1cfc5caea03aa3b8", "scanner": "scanner-primary", "fingerprint": "3ee598ca43700591", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3000"]}}, {"ruleId": "scanner-a080ae058f069d02", "level": "note", "message": {"text": "CVE-2025-3001: torch 2.9.1 \u2014 kt-kernel/requirements.txt"}, "properties": {"repobilityId": "13c759b0521177e7", "scanner": "scanner-primary", "fingerprint": "a080ae058f069d02", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-3001"]}}, {"ruleId": "scanner-38ac2599b07e36d6", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/.devcontainer/Dockerfile"}, "properties": {"repobilityId": "702437007fdd4a41", "scanner": "scanner-primary", "fingerprint": "38ac2599b07e36d6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-4ffa53f2e58b1568", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/.devcontainer/Dockerfile"}, "properties": {"repobilityId": "f06b19aa073137bc", "scanner": "scanner-primary", "fingerprint": "4ffa53f2e58b1568", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-259523e79aab68f6", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/Dockerfile"}, "properties": {"repobilityId": "b4bbf0a9c1805990", "scanner": "scanner-primary", "fingerprint": "259523e79aab68f6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-c1a502253fb1443b", "level": "error", "message": {"text": "DS-0017: 'RUN <package-manager> update' instruction alone \u2014 archive/Dockerfile"}, "properties": {"repobilityId": "d76fa9a7ae5a6825", "scanner": "scanner-primary", "fingerprint": "c1a502253fb1443b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-42919ec3ef201587", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/Dockerfile"}, "properties": {"repobilityId": "c256fe359380410f", "scanner": "scanner-primary", "fingerprint": "42919ec3ef201587", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-65e1ffe71dc8a797", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/Dockerfile.xpu"}, "properties": {"repobilityId": "00ed8a68f63b9dfd", "scanner": "scanner-primary", "fingerprint": "65e1ffe71dc8a797", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-f4d0c266c5bbb06b", "level": "warning", "message": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 archive/Dockerfile.xpu"}, "properties": {"repobilityId": "aefec0ecab934b97", "scanner": "scanner-primary", "fingerprint": "f4d0c266c5bbb06b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-5380bc1a49bf5899", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/Dockerfile.xpu"}, "properties": {"repobilityId": "f9dbc593321727b4", "scanner": "scanner-primary", "fingerprint": "5380bc1a49bf5899", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-02009d509ce3a631", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 archive/Dockerfile.xpu"}, "properties": {"repobilityId": "a70a58e5ae79f6e0", "scanner": "scanner-primary", "fingerprint": "02009d509ce3a631", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-e74b7ffc67c4fc0d", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/kt-sft/Dockerfile"}, "properties": {"repobilityId": "cf893f5cf50984d1", "scanner": "scanner-primary", "fingerprint": "e74b7ffc67c4fc0d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-a728d3fea5697f77", "level": "error", "message": {"text": "DS-0017: 'RUN <package-manager> update' instruction alone \u2014 archive/kt-sft/Dockerfile"}, "properties": {"repobilityId": "62c7eb6710020693", "scanner": "scanner-primary", "fingerprint": "a728d3fea5697f77", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-9da7bf9c8c5d0217", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/kt-sft/Dockerfile"}, "properties": {"repobilityId": "cb4980e89376f340", "scanner": "scanner-primary", "fingerprint": "9da7bf9c8c5d0217", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-61186b19d7d38d3b", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 archive/kt-sft/Dockerfile.xpu"}, "properties": {"repobilityId": "9cc0c5325e0e4308", "scanner": "scanner-primary", "fingerprint": "61186b19d7d38d3b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-1bd7ec4c3bd6c06a", "level": "warning", "message": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 archive/kt-sft/Dockerfile.xpu"}, "properties": {"repobilityId": "6b2eeb7a65c0edf8", "scanner": "scanner-primary", "fingerprint": "1bd7ec4c3bd6c06a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-aff6d2a52d666ed5", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 archive/kt-sft/Dockerfile.xpu"}, "properties": {"repobilityId": "731243a93d37d6bd", "scanner": "scanner-primary", "fingerprint": "aff6d2a52d666ed5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-f5ae22e92d075176", "level": "error", "message": {"text": "DS-0029: 'apt-get' missing '--no-install-recommends' \u2014 archive/kt-sft/Dockerfile.xpu"}, "properties": {"repobilityId": "c8683e1f8dc29235", "scanner": "scanner-primary", "fingerprint": "f5ae22e92d075176", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-5233dbedff634681", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 docker/Dockerfile"}, "properties": {"repobilityId": "229ba94b94bcf851", "scanner": "scanner-primary", "fingerprint": "5233dbedff634681", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-c5fc0f19b37712e2", "level": "warning", "message": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 docker/Dockerfile"}, "properties": {"repobilityId": "5e3eb4732a0d88c6", "scanner": "scanner-primary", "fingerprint": "c5fc0f19b37712e2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-10db0d8457b5093d", "level": "note", "message": {"text": "DS-0014: RUN using 'wget' and 'curl' \u2014 docker/Dockerfile"}, "properties": {"repobilityId": "34da71911306ebba", "scanner": "scanner-primary", "fingerprint": "10db0d8457b5093d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-055d03fec591276a", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 docker/Dockerfile"}, "properties": {"repobilityId": "2554eb2133f8c3ad", "scanner": "scanner-primary", "fingerprint": "055d03fec591276a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-47636e33caef255d", "level": "warning", "message": {"text": "Dockerfile runs as root: docker/Dockerfile"}, "properties": {"repobilityId": "8a345ba4198453bd", "scanner": "scanner-primary", "fingerprint": "47636e33caef255d", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-30a2e0d374af3108", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.1ms.run/nvidia/cuda:${CUDA_VERSION}-cudnn-devel-ubuntu24.04"}, "properties": {"repobilityId": "8de96890838bc6d4", "scanner": "scanner-primary", "fingerprint": "30a2e0d374af3108", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-1728a10eb12732aa", "level": "warning", "message": {"text": "Dockerfile runs as root: archive/Dockerfile"}, "properties": {"repobilityId": "cc4b4aeb20dd207b", "scanner": "scanner-primary", "fingerprint": "1728a10eb12732aa", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-e925d93358cd73c5", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel"}, "properties": {"repobilityId": "3a6cc45e9ce3a29d", "scanner": "scanner-primary", "fingerprint": "e925d93358cd73c5", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8e29d3e75117b262", "level": "warning", "message": {"text": "Dockerfile runs as root: archive/.devcontainer/Dockerfile"}, "properties": {"repobilityId": "2bfcc11da2c8641a", "scanner": "scanner-primary", "fingerprint": "8e29d3e75117b262", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-605fced2016697c3", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel"}, "properties": {"repobilityId": "83ce317b8693b01e", "scanner": "scanner-primary", "fingerprint": "605fced2016697c3", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/.devcontainer/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3395a3e45d370088", "level": "warning", "message": {"text": "Dockerfile runs as root: archive/kt-sft/Dockerfile"}, "properties": {"repobilityId": "10aa4ebce04f1e32", "scanner": "scanner-primary", "fingerprint": "3395a3e45d370088", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-60d8137c87d754a4", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: pytorch/pytorch:2.5.1-cuda12.1-cudnn9-devel"}, "properties": {"repobilityId": "1e4125e2d10ce317", "scanner": "scanner-primary", "fingerprint": "60d8137c87d754a4", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a3fdef7be6d3a8c3", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in ktransformers.py:17"}, "properties": {"repobilityId": "1b9bd299df08ccdf", "scanner": "scanner-primary", "fingerprint": "a3fdef7be6d3a8c3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "ktransformers.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-40b2742ab36d1c93", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in install.sh:73"}, "properties": {"repobilityId": "3c6be23442a56e63", "scanner": "scanner-primary", "fingerprint": "40b2742ab36d1c93", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "install.sh"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-57e993a9c63dae8e", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in setup.py:12"}, "properties": {"repobilityId": "850e38b7c3babe65", "scanner": "scanner-primary", "fingerprint": "57e993a9c63dae8e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "setup.py"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-b8c88088be40fe75", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in docker/Dockerfile:270"}, "properties": {"repobilityId": "6bf5bc036edc3ac5", "scanner": "scanner-primary", "fingerprint": "b8c88088be40fe75", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/Dockerfile"}, "region": {"startLine": 270}}}]}, {"ruleId": "scanner-6928e946cbe72734", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in archive/kt-sft/ktransformers/website/src/components/chat/index.vue:40"}, "properties": {"repobilityId": "5a2f7ec61778b7cb", "scanner": "scanner-primary", "fingerprint": "6928e946cbe72734", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/src/components/chat/index.vue"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-c29d4c4fce26c314", "level": "note", "message": {"text": "Insecure pattern 'document_write' in archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "properties": {"repobilityId": "aa194d87e3e5d485", "scanner": "scanner-primary", "fingerprint": "c29d4c4fce26c314", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8484ea576eba0f3c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "properties": {"repobilityId": "6e5d9ddcd1294b03", "scanner": "scanner-primary", "fingerprint": "8484ea576eba0f3c", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/src/assets/iconfont/iconfont.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6164b92fc7497e2a", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in archive/kt-sft/ktransformers/server/main.py:38"}, "properties": {"repobilityId": "662df178f0975000", "scanner": "scanner-primary", "fingerprint": "6164b92fc7497e2a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/main.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-d9c0ae1661d9c873", "level": "error", "message": {"text": "Insecure pattern 'python_os_system' in archive/ktransformers/local_chat_test.py:131"}, "properties": {"repobilityId": "2b93b3cc5acd5fcc", "scanner": "scanner-primary", "fingerprint": "d9c0ae1661d9c873", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "python_os_system"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/local_chat_test.py"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-59409e24e4b07723", "level": "error", "message": {"text": "Insecure pattern 'python_os_system' in archive/ktransformers/local_chat.py:161"}, "properties": {"repobilityId": "7a27376ab589d500", "scanner": "scanner-primary", "fingerprint": "59409e24e4b07723", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "python_os_system"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/local_chat.py"}, "region": {"startLine": 161}}}]}, {"ruleId": "scanner-38444494b3af6247", "level": "warning", "message": {"text": "Insecure pattern 'vue_v_html' in archive/ktransformers/website/src/components/chat/index.vue:40"}, "properties": {"repobilityId": "0626247deecfdee6", "scanner": "scanner-primary", "fingerprint": "38444494b3af6247", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "vue_v_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/website/src/components/chat/index.vue"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-4569d61f1b6a8553", "level": "note", "message": {"text": "Insecure pattern 'document_write' in archive/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "properties": {"repobilityId": "e7e2559b6460e294", "scanner": "scanner-primary", "fingerprint": "4569d61f1b6a8553", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/website/src/assets/iconfont/iconfont.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-16a973f714251f32", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in archive/ktransformers/website/src/assets/iconfont/iconfont.js:1"}, "properties": {"repobilityId": "995c3076cb4c4b6c", "scanner": "scanner-primary", "fingerprint": "16a973f714251f32", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/website/src/assets/iconfont/iconfont.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29468091f27dc786", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in archive/ktransformers/server/main.py:46"}, "properties": {"repobilityId": "82024add30e040d3", "scanner": "scanner-primary", "fingerprint": "29468091f27dc786", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/main.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-27afcd178c85ea26", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in kt-kernel/setup.py:753"}, "properties": {"repobilityId": "81dcd3e50adbaae5", "scanner": "scanner-primary", "fingerprint": "27afcd178c85ea26", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/setup.py"}, "region": {"startLine": 753}}}]}, {"ruleId": "scanner-c69f045e2bd2f75c", "level": "error", "message": {"text": "Insecure pattern 'subprocess_shell_true' in kt-kernel/bench/compare_moe_performance.py:825"}, "properties": {"repobilityId": "230f1bfdad409ef2", "scanner": "scanner-primary", "fingerprint": "c69f045e2bd2f75c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "subprocess_shell_true"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/compare_moe_performance.py"}, "region": {"startLine": 825}}}]}, {"ruleId": "scanner-c49da81e64ee1a07", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in kt-kernel/python/__init__.py:80"}, "properties": {"repobilityId": "657e824cf711d8e7", "scanner": "scanner-primary", "fingerprint": "c49da81e64ee1a07", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/python/__init__.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-3770298887aaea9d", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in kt-kernel/python/cli/__init__.py:18"}, "properties": {"repobilityId": "3059c7f0e4be5968", "scanner": "scanner-primary", "fingerprint": "3770298887aaea9d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/python/cli/__init__.py"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-65116d685636e1dd", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in .github/workflows/sync-sglang-submodule.yml:49"}, "properties": {"repobilityId": "b1a0a089ce056d8f", "scanner": "scanner-primary", "fingerprint": "65116d685636e1dd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/sync-sglang-submodule.yml"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-f907e1362801558d", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in .github/workflows/release-sglang-kt.yml:48"}, "properties": {"repobilityId": "a334b4ef54a07b7f", "scanner": "scanner-primary", "fingerprint": "f907e1362801558d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-sglang-kt.yml"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-8ef7f635008ae87d", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in .github/workflows/release-pypi.yml:53"}, "properties": {"repobilityId": "7e5d3143f7ba0c1a", "scanner": "scanner-primary", "fingerprint": "8ef7f635008ae87d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-pypi.yml"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-93afed2afb1d3d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e4fe1b94683db6d9", "scanner": "scanner-primary", "fingerprint": "93afed2afb1d3d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-image.yml"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-e8f4cf73c7733319", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7c37b111662c0086", "scanner": "scanner-primary", "fingerprint": "e8f4cf73c7733319", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/kt-kernel-tests.yml"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "564a6bf5267d57ef", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-ad6701f0a8405e22", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "8384c23520d55657", "scanner": "scanner-primary", "fingerprint": "ad6701f0a8405e22", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0d7426ae81ce844e", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1eb0dc312138477d", "scanner": "scanner-primary", "fingerprint": "0d7426ae81ce844e", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/sync-sglang-submodule.yml"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-7eff9ff1697123c4", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "4eb5f6d0a85c3394", "scanner": "scanner-primary", "fingerprint": "7eff9ff1697123c4", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/sync-sglang-submodule.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e57343c0bee0f9c0", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5815c3999916f3a2", "scanner": "scanner-primary", "fingerprint": "e57343c0bee0f9c0", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-sglang-kt.yml"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-1e29504e3d50d6f3", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "55ec952a9cc41966", "scanner": "scanner-primary", "fingerprint": "1e29504e3d50d6f3", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-sglang-kt.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-211f7d3f743a10c1", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5b3948f6faee31f1", "scanner": "scanner-primary", "fingerprint": "211f7d3f743a10c1", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/book-ci.yml"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-350bc90d555d8dff", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f34ec45d32593523", "scanner": "scanner-primary", "fingerprint": "350bc90d555d8dff", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-fake-tag.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-45a16c3ce361bbca", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "cc41c01a8732f4ee", "scanner": "scanner-primary", "fingerprint": "45a16c3ce361bbca", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-fake-tag.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f9f974bb8fb136e5", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7b13b989bde32e62", "scanner": "scanner-primary", "fingerprint": "f9f974bb8fb136e5", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-pypi.yml"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-b126c22a1b9b8a46", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "7d1cfa42b6c3c917", "scanner": "scanner-primary", "fingerprint": "b126c22a1b9b8a46", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-pypi.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff3ea4f0d78df150", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_llama.py (1745 lines)"}, "properties": {"repobilityId": "b7895db516133a18", "scanner": "scanner-primary", "fingerprint": "ff3ea4f0d78df150", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-dc6cccd69c16d411", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_deepseek.py (1996 lines)"}, "properties": {"repobilityId": "809a43fcf7e34486", "scanner": "scanner-primary", "fingerprint": "dc6cccd69c16d411", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-362ec68e5ef8b69c", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_deepseek_v3.py (1941 lines)"}, "properties": {"repobilityId": "0d5a31883a3aa578", "scanner": "scanner-primary", "fingerprint": "362ec68e5ef8b69c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3351f648ad9ddfd9", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_mixtral.py (1735 lines)"}, "properties": {"repobilityId": "d3fccfdec5b3d040", "scanner": "scanner-primary", "fingerprint": "3351f648ad9ddfd9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-097d89b14bdd5c89", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_qwen3_moe.py (1472 lines)"}, "properties": {"repobilityId": "18f758354900d061", "scanner": "scanner-primary", "fingerprint": "097d89b14bdd5c89", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c06b68ead597fa8d", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/models/modeling_qwen2_moe.py (1766 lines)"}, "properties": {"repobilityId": "c3121bd5b6189f68", "scanner": "scanner-primary", "fingerprint": "c06b68ead597fa8d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c96f482afc258a73", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/operators/experts.py (2310 lines)"}, "properties": {"repobilityId": "1a110432093c47b5", "scanner": "scanner-primary", "fingerprint": "c96f482afc258a73", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-da40c71c75ff4ef8", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/operators/models.py (1756 lines)"}, "properties": {"repobilityId": "c61fccccd5f7a3a7", "scanner": "scanner-primary", "fingerprint": "da40c71c75ff4ef8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-515c5877d2bc6f8b", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/operators/attention.py (1083 lines)"}, "properties": {"repobilityId": "3d33a0185badd024", "scanner": "scanner-primary", "fingerprint": "515c5877d2bc6f8b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-21f1a82d4e6e41f2", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/sft/metrics_utils/constants.py (3464 lines)"}, "properties": {"repobilityId": "0fb602390c221a27", "scanner": "scanner-primary", "fingerprint": "21f1a82d4e6e41f2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-aa79900433db2a11", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/sft/peft_utils/peft_model.py (1920 lines)"}, "properties": {"repobilityId": "cec51d80fc16c0bf", "scanner": "scanner-primary", "fingerprint": "aa79900433db2a11", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a2bbea6dd490087c", "level": "note", "message": {"text": "Very large file: archive/kt-sft/ktransformers/sft/peft_utils/lora_layer.py (1161 lines)"}, "properties": {"repobilityId": "25c7066f88999560", "scanner": "scanner-primary", "fingerprint": "a2bbea6dd490087c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-180d1dbcf986a262", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_llama.py (1744 lines)"}, "properties": {"repobilityId": "c5525a9b233ef343", "scanner": "scanner-primary", "fingerprint": "180d1dbcf986a262", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-28dc1c925d63a06b", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_deepseek.py (1992 lines)"}, "properties": {"repobilityId": "784416556725ae0b", "scanner": "scanner-primary", "fingerprint": "28dc1c925d63a06b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-632de071b11210ab", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_deepseek_v3.py (1955 lines)"}, "properties": {"repobilityId": "1d78351567182dd1", "scanner": "scanner-primary", "fingerprint": "632de071b11210ab", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c469391679bedd6d", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_mixtral.py (1734 lines)"}, "properties": {"repobilityId": "2a9a184449bd6eda", "scanner": "scanner-primary", "fingerprint": "c469391679bedd6d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-538efa3b7a913d50", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_qwen3_next.py (1286 lines)"}, "properties": {"repobilityId": "c88aaea09e08f439", "scanner": "scanner-primary", "fingerprint": "538efa3b7a913d50", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f3c61ffe56fa1322", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_qwen3_moe.py (1471 lines)"}, "properties": {"repobilityId": "dcf159ebaed51aae", "scanner": "scanner-primary", "fingerprint": "f3c61ffe56fa1322", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2e74196b9fee42a6", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_smallthinker.py (1235 lines)"}, "properties": {"repobilityId": "23d087ddfc6b5872", "scanner": "scanner-primary", "fingerprint": "2e74196b9fee42a6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f50c9936c0e5fbd2", "level": "note", "message": {"text": "Very large file: archive/ktransformers/models/modeling_qwen2_moe.py (1765 lines)"}, "properties": {"repobilityId": "4f13fdccdccebde6", "scanner": "scanner-primary", "fingerprint": "f50c9936c0e5fbd2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8b5a05c149bd227b", "level": "note", "message": {"text": "Very large file: archive/ktransformers/operators/experts.py (2096 lines)"}, "properties": {"repobilityId": "92b14dec0716c557", "scanner": "scanner-primary", "fingerprint": "8b5a05c149bd227b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ad13f8e24d67385b", "level": "note", "message": {"text": "Very large file: archive/ktransformers/operators/models.py (1395 lines)"}, "properties": {"repobilityId": "7fd98a9d67b2eb72", "scanner": "scanner-primary", "fingerprint": "ad13f8e24d67385b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4c0024492cd56d7d", "level": "note", "message": {"text": "Very large file: archive/ktransformers/operators/ascend/ascend_attention.py (1263 lines)"}, "properties": {"repobilityId": "70cd1a6f8d073dc5", "scanner": "scanner-primary", "fingerprint": "4c0024492cd56d7d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0c5581ce9223613b", "level": "note", "message": {"text": "Very large file: kt-kernel/scripts/convert_cpu_weights.py (1236 lines)"}, "properties": {"repobilityId": "1b01670c94382035", "scanner": "scanner-primary", "fingerprint": "0c5581ce9223613b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b41b3e4d8b4d6578", "level": "note", "message": {"text": "Very large file: kt-kernel/scripts/convert_cpu_weights_ds4.py (1396 lines)"}, "properties": {"repobilityId": "0d2e00250550be1c", "scanner": "scanner-primary", "fingerprint": "b41b3e4d8b4d6578", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4a3ec4e091a72280", "level": "note", "message": {"text": "Very large file: kt-kernel/bench/compare_moe_performance.py (1370 lines)"}, "properties": {"repobilityId": "e37d63027c239255", "scanner": "scanner-primary", "fingerprint": "4a3ec4e091a72280", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7bfbd8cd64e199a9", "level": "note", "message": {"text": "Very large file: kt-kernel/examples/modeling_deepseek_v3.py (1937 lines)"}, "properties": {"repobilityId": "57b31d6fb49f647e", "scanner": "scanner-primary", "fingerprint": "7bfbd8cd64e199a9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8fb23bfce5484b41", "level": "note", "message": {"text": "Very large file: kt-kernel/python/cli/i18n.py (1345 lines)"}, "properties": {"repobilityId": "433efe84adf7ac1f", "scanner": "scanner-primary", "fingerprint": "8fb23bfce5484b41", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-382f3272db7c7827", "level": "note", "message": {"text": "Very large file: kt-kernel/python/cli/commands/model.py (2810 lines)"}, "properties": {"repobilityId": "96669963e53bf480", "scanner": "scanner-primary", "fingerprint": "382f3272db7c7827", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b9b4d93b2c9715b0", "level": "note", "message": {"text": "Very large file: kt-kernel/python/utils/loader.py (1349 lines)"}, "properties": {"repobilityId": "3884896dfd439267", "scanner": "scanner-primary", "fingerprint": "b9b4d93b2c9715b0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-63818d01d879149b", "level": "note", "message": {"text": "312 TODO/FIXME markers"}, "properties": {"repobilityId": "4b38c118003e07d2", "scanner": "scanner-primary", "fingerprint": "63818d01d879149b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["maintenance"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "09b4e887c22fb746", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "3d591197159a4faa", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "f9f4764750da2353", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-bc924c18fbe69d69", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 archive/setup.py:81"}, "properties": {"repobilityId": "764c7d8f74837b2f", "scanner": "scanner-primary", "fingerprint": "bc924c18fbe69d69", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/setup.py"}, "region": {"startLine": 81}}}]}, {"ruleId": "scanner-fd5403f93bbdd080", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 archive/kt-sft/setup.py:106"}, "properties": {"repobilityId": "e2ccd526f769a193", "scanner": "scanner-primary", "fingerprint": "fd5403f93bbdd080", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/setup.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-1cca08e5cc1a3321", "level": "none", "message": {"text": "Commented-code block (7 lines) in archive/kt-sft/withoutKT_PEFT.py:95"}, "properties": {"repobilityId": "d1f7a6e3cc3ad401", "scanner": "scanner-primary", "fingerprint": "1cca08e5cc1a3321", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/withoutKT_PEFT.py"}, "region": {"startLine": 95}}}]}, {"ruleId": "scanner-68954f7ecb775321", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/kt-sft/merge_tensors/merge_safetensor_gguf.py:42"}, "properties": {"repobilityId": "acc84c09d694feb6", "scanner": "scanner-primary", "fingerprint": "68954f7ecb775321", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/merge_tensors/merge_safetensor_gguf.py"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-f409b4d6702c46f2", "level": "none", "message": {"text": "Commented-code block (8 lines) in archive/kt-sft/ktransformers/local_chat.py:238"}, "properties": {"repobilityId": "80dbb4858a77d2c2", "scanner": "scanner-primary", "fingerprint": "f409b4d6702c46f2", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/local_chat.py"}, "region": {"startLine": 238}}}]}, {"ruleId": "scanner-233cb8a09137b632", "level": "none", "message": {"text": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/moe_test_module_old.py:37"}, "properties": {"repobilityId": "33aaeac22fc94f23", "scanner": "scanner-primary", "fingerprint": "233cb8a09137b632", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/moe_test_module_old.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-93b12239c9c9b40b", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/lora_test_module.py:106"}, "properties": {"repobilityId": "6b8a74fc22a5ee8f", "scanner": "scanner-primary", "fingerprint": "93b12239c9c9b40b", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/lora_test_module.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-9c7ea6687298ce63", "level": "note", "message": {"text": "Legacy-named symbol `deepseek_v2` in archive/kt-sft/ktransformers/models/configuration_deepseek.py:110"}, "properties": {"repobilityId": "6c4ee035675d620c", "scanner": "scanner-primary", "fingerprint": "9c7ea6687298ce63", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-633108877b12fc21", "level": "none", "message": {"text": "Commented-code block (16 lines) in archive/kt-sft/ktransformers/util/custom_gguf.py:715"}, "properties": {"repobilityId": "40322aa9382d7c3c", "scanner": "scanner-primary", "fingerprint": "633108877b12fc21", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/util/custom_gguf.py"}, "region": {"startLine": 715}}}]}, {"ruleId": "scanner-d915b9b2afb648f8", "level": "note", "message": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/gate.py:32"}, "properties": {"repobilityId": "e0b4c91a75d0d958", "scanner": "scanner-primary", "fingerprint": "d915b9b2afb648f8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-a28e044e064c95ff", "level": "none", "message": {"text": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/operators/experts.py:643"}, "properties": {"repobilityId": "cf825dc1f51ba150", "scanner": "scanner-primary", "fingerprint": "a28e044e064c95ff", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/operators/experts.py"}, "region": {"startLine": 643}}}]}, {"ruleId": "scanner-0d20c4178b684818", "level": "note", "message": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/experts.py:77"}, "properties": {"repobilityId": "bc9ae3100f91cadb", "scanner": "scanner-primary", "fingerprint": "0d20c4178b684818", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-a5517967c9268c95", "level": "note", "message": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/operators/linear.py:80"}, "properties": {"repobilityId": "85aba44eeef02ccd", "scanner": "scanner-primary", "fingerprint": "a5517967c9268c95", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-eecf1254a792bb5b", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/operators/RoPE.py:213"}, "properties": {"repobilityId": "d6e86edfa8753644", "scanner": "scanner-primary", "fingerprint": "eecf1254a792bb5b", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/operators/RoPE.py"}, "region": {"startLine": 213}}}]}, {"ruleId": "scanner-a6520ad9062e9baa", "level": "none", "message": {"text": "Commented-code block (7 lines) in archive/kt-sft/ktransformers/operators/models.py:1570"}, "properties": {"repobilityId": "869220aa9906a974", "scanner": "scanner-primary", "fingerprint": "a6520ad9062e9baa", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/operators/models.py"}, "region": {"startLine": 1570}}}]}, {"ruleId": "scanner-c7c0b4f7adaf0051", "level": "none", "message": {"text": "Commented-code block (13 lines) in archive/kt-sft/ktransformers/sft/flops_utils/lora_test_utils.py:142"}, "properties": {"repobilityId": "cbb06bcafd344987", "scanner": "scanner-primary", "fingerprint": "c7c0b4f7adaf0051", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/sft/flops_utils/lora_test_utils.py"}, "region": {"startLine": 142}}}]}, {"ruleId": "scanner-0c14025ad5530cb5", "level": "none", "message": {"text": "Commented-code block (10 lines) in archive/kt-sft/ktransformers/sft/peft_utils/lora_model.py:415"}, "properties": {"repobilityId": "bbd027c25312248c", "scanner": "scanner-primary", "fingerprint": "0c14025ad5530cb5", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/sft/peft_utils/lora_model.py"}, "region": {"startLine": 415}}}]}, {"ruleId": "scanner-0d35448c24c1cad6", "level": "note", "message": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/kt-sft/ktransformers/server/balance_serve/inference/model_runner.py:29"}, "properties": {"repobilityId": "52fb50510ccebb14", "scanner": "scanner-primary", "fingerprint": "0d35448c24c1cad6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b10bedc69f284652", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:241"}, "properties": {"repobilityId": "de62e39800e4d292", "scanner": "scanner-primary", "fingerprint": "b10bedc69f284652", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py"}, "region": {"startLine": 241}}}]}, {"ruleId": "scanner-6878c6c2a0e083f9", "level": "note", "message": {"text": "Stub function `inplace_all_reduce_fake` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:108"}, "properties": {"repobilityId": "33fa97befedf2d25", "scanner": "scanner-primary", "fingerprint": "6878c6c2a0e083f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-a231b6598cdfd7ab", "level": "note", "message": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/frequency_penalty.py:53"}, "properties": {"repobilityId": "62bfd8f3ac9c08ab", "scanner": "scanner-primary", "fingerprint": "a231b6598cdfd7ab", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-2e1921deb923ca57", "level": "note", "message": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/presence_penalty.py:53"}, "properties": {"repobilityId": "50f882b77d76c260", "scanner": "scanner-primary", "fingerprint": "2e1921deb923ca57", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-fcc87f50808740b5", "level": "note", "message": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/min_new_tokens.py:81"}, "properties": {"repobilityId": "a64f373287a686bd", "scanner": "scanner-primary", "fingerprint": "fcc87f50808740b5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-0228540b431a56e5", "level": "note", "message": {"text": "Stub function `get_interface` (body is just `pass`/`return`) \u2014 archive/kt-sft/ktransformers/server/backend/interfaces/exllamav2.py:18"}, "properties": {"repobilityId": "add57896190daae4", "scanner": "scanner-primary", "fingerprint": "0228540b431a56e5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-dda2a71d1087876e", "level": "note", "message": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/kt-sft/ktransformers/server/backend/interfaces/balance_serve.py:24"}, "properties": {"repobilityId": "b5ece897caefcecd", "scanner": "scanner-primary", "fingerprint": "dda2a71d1087876e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-277cbf993e5614c4", "level": "none", "message": {"text": "Commented-code block (6 lines) in archive/kt-sft/ktransformers/server/backend/interfaces/transformers.py:189"}, "properties": {"repobilityId": "6e7a6543234118e5", "scanner": "scanner-primary", "fingerprint": "277cbf993e5614c4", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/backend/interfaces/transformers.py"}, "region": {"startLine": 189}}}]}, {"ruleId": "scanner-4857a7314e813b11", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in archive/kt-sft/ktransformers/server/schemas/assistants/assistants.py:164"}, "properties": {"repobilityId": "7a1bcee7f9ba5521", "scanner": "scanner-primary", "fingerprint": "4857a7314e813b11", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-169dbc860b62ca2d", "level": "note", "message": {"text": "Legacy-named symbol `deepseek_v2` in archive/kt-sft/ktransformers/configs/model_config/configuration_deepseek.py:112"}, "properties": {"repobilityId": "62bd31241b4939b3", "scanner": "scanner-primary", "fingerprint": "169dbc860b62ca2d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-5ae25c9c15c87cbc", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/merge_tensors/merge_safetensor_gguf.py:42"}, "properties": {"repobilityId": "fa4cc421317ef7f3", "scanner": "scanner-primary", "fingerprint": "5ae25c9c15c87cbc", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/merge_tensors/merge_safetensor_gguf.py"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-be356b926917af8d", "level": "note", "message": {"text": "Legacy-named symbol `deepseek_v2` in archive/ktransformers/models/configuration_deepseek.py:110"}, "properties": {"repobilityId": "6ca1b46456fb3b69", "scanner": "scanner-primary", "fingerprint": "be356b926917af8d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7c3f85de074ee86d", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/ktransformers/models/modeling_qwen3_moe.py:208"}, "properties": {"repobilityId": "1707ca6559c300a8", "scanner": "scanner-primary", "fingerprint": "7c3f85de074ee86d", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/models/modeling_qwen3_moe.py"}, "region": {"startLine": 208}}}]}, {"ruleId": "scanner-58a983279476a924", "level": "none", "message": {"text": "Commented-code block (6 lines) in archive/ktransformers/models/modeling_smallthinker.py:983"}, "properties": {"repobilityId": "465d9107fb4bf49c", "scanner": "scanner-primary", "fingerprint": "58a983279476a924", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/models/modeling_smallthinker.py"}, "region": {"startLine": 983}}}]}, {"ruleId": "scanner-99eb7ad2395ca9a4", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/ktransformers/util/utils.py:76"}, "properties": {"repobilityId": "bfc57f34c252ee3d", "scanner": "scanner-primary", "fingerprint": "99eb7ad2395ca9a4", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/util/utils.py"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-abbfecfda35a231b", "level": "note", "message": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/gate.py:32"}, "properties": {"repobilityId": "fe029d93fd577d84", "scanner": "scanner-primary", "fingerprint": "abbfecfda35a231b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-deabf0aaf67afb82", "level": "note", "message": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/experts.py:77"}, "properties": {"repobilityId": "ed0550a99b2a6bc7", "scanner": "scanner-primary", "fingerprint": "deabf0aaf67afb82", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-339b80d19b697d79", "level": "note", "message": {"text": "Stub function `forward` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/linear.py:89"}, "properties": {"repobilityId": "96bcbe260f2abf76", "scanner": "scanner-primary", "fingerprint": "339b80d19b697d79", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-d661054182fd27a5", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/ktransformers/operators/RoPE.py:214"}, "properties": {"repobilityId": "b93dc47a08963ea6", "scanner": "scanner-primary", "fingerprint": "d661054182fd27a5", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/operators/RoPE.py"}, "region": {"startLine": 214}}}]}, {"ruleId": "scanner-e34140c672f70a9c", "level": "note", "message": {"text": "Stub function `load` (body is just `pass`/`return`) \u2014 archive/ktransformers/operators/ascend/ascend_linear.py:102"}, "properties": {"repobilityId": "5982e86709212100", "scanner": "scanner-primary", "fingerprint": "e34140c672f70a9c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-a61bfa66fa7f81cb", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/ktransformers/server/utils/serve_profiling.py:17"}, "properties": {"repobilityId": "325d602369063339", "scanner": "scanner-primary", "fingerprint": "a61bfa66fa7f81cb", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/utils/serve_profiling.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-33c80d115ac2a112", "level": "note", "message": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/ktransformers/server/balance_serve/inference/model_runner.py:34"}, "properties": {"repobilityId": "fcc0b7b5d71f71d0", "scanner": "scanner-primary", "fingerprint": "33c80d115ac2a112", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-cff5ae421135624e", "level": "none", "message": {"text": "Commented-code block (5 lines) in archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:241"}, "properties": {"repobilityId": "9b479ec1ec393bd8", "scanner": "scanner-primary", "fingerprint": "cff5ae421135624e", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py"}, "region": {"startLine": 241}}}]}, {"ruleId": "scanner-349e003981fe1c86", "level": "note", "message": {"text": "Stub function `inplace_all_reduce_fake` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/distributed/parallel_state.py:108"}, "properties": {"repobilityId": "ea5199705bbca996", "scanner": "scanner-primary", "fingerprint": "349e003981fe1c86", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-aa4b19d8179eeed5", "level": "note", "message": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/frequency_penalty.py:53"}, "properties": {"repobilityId": "993a13fc8c32bb3d", "scanner": "scanner-primary", "fingerprint": "aa4b19d8179eeed5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-ede51115d46ca57a", "level": "note", "message": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/presence_penalty.py:53"}, "properties": {"repobilityId": "0faff4d40546c051", "scanner": "scanner-primary", "fingerprint": "ede51115d46ca57a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-c4a29a4c5ebd0b72", "level": "note", "message": {"text": "Stub function `_cumulate_input_tokens` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/balance_serve/inference/sampling/penaltylib/penalizers/min_new_tokens.py:81"}, "properties": {"repobilityId": "3c73692cf65ef1c4", "scanner": "scanner-primary", "fingerprint": "c4a29a4c5ebd0b72", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-e1fd6874d532030d", "level": "note", "message": {"text": "Stub function `get_interface` (body is just `pass`/`return`) \u2014 archive/ktransformers/server/backend/interfaces/exllamav2.py:18"}, "properties": {"repobilityId": "57954b7deea79964", "scanner": "scanner-primary", "fingerprint": "e1fd6874d532030d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-9593318b44281f97", "level": "note", "message": {"text": "Legacy-named symbol `custom_modeling_deepseek_v2` in archive/ktransformers/server/backend/interfaces/balance_serve.py:25"}, "properties": {"repobilityId": "a1eecc1686bdc783", "scanner": "scanner-primary", "fingerprint": "9593318b44281f97", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-5ae7a232b13195cc", "level": "none", "message": {"text": "Commented-code block (11 lines) in archive/ktransformers/server/backend/interfaces/transformers.py:199"}, "properties": {"repobilityId": "3212bdd898c5e50a", "scanner": "scanner-primary", "fingerprint": "5ae7a232b13195cc", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/backend/interfaces/transformers.py"}, "region": {"startLine": 199}}}]}, {"ruleId": "scanner-8c70a85bc43bacde", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in archive/ktransformers/server/schemas/assistants/assistants.py:164"}, "properties": {"repobilityId": "7c2f5edb575071e7", "scanner": "scanner-primary", "fingerprint": "8c70a85bc43bacde", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-cf05d94f17f527f6", "level": "note", "message": {"text": "Legacy-named symbol `env_backup` in kt-kernel/setup.py:302"}, "properties": {"repobilityId": "c4eaf8787ceea853", "scanner": "scanner-primary", "fingerprint": "cf05d94f17f527f6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4919da0e66aecd28", "level": "none", "message": {"text": "Commented-code block (5 lines) in kt-kernel/setup.py:566"}, "properties": {"repobilityId": "2b9a04e030d08686", "scanner": "scanner-primary", "fingerprint": "4919da0e66aecd28", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/setup.py"}, "region": {"startLine": 566}}}]}, {"ruleId": "scanner-a9e2c559561b24b2", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/setup.py:721"}, "properties": {"repobilityId": "ca35303d0fd1daa5", "scanner": "scanner-primary", "fingerprint": "a9e2c559561b24b2", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/setup.py"}, "region": {"startLine": 721}}}]}, {"ruleId": "scanner-51c1c7de7b60d363", "level": "none", "message": {"text": "Commented-code block (5 lines) in kt-kernel/scripts/check.py:69"}, "properties": {"repobilityId": "cf69253b1e1ab8ab", "scanner": "scanner-primary", "fingerprint": "51c1c7de7b60d363", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/scripts/check.py"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-3ec47686874e7b5f", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_k2_moe_amx.py:49"}, "properties": {"repobilityId": "98c3bda75805b7e4", "scanner": "scanner-primary", "fingerprint": "3ec47686874e7b5f", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_k2_moe_amx.py"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-de2e3e459cac3612", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_bf16_moe.py:52"}, "properties": {"repobilityId": "c0ff4ed28e693280", "scanner": "scanner-primary", "fingerprint": "de2e3e459cac3612", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_bf16_moe.py"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-141ae60397c5e707", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_mla.py:78"}, "properties": {"repobilityId": "508f11400f8e04da", "scanner": "scanner-primary", "fingerprint": "141ae60397c5e707", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_mla.py"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-91c1a439f39dc332", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_write_buffer.py:57"}, "properties": {"repobilityId": "f2c74b1a41f82342", "scanner": "scanner-primary", "fingerprint": "91c1a439f39dc332", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_write_buffer.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-765636b64d666518", "level": "none", "message": {"text": "Commented-code block (7 lines) in kt-kernel/bench/bench_moe_kml.py:38"}, "properties": {"repobilityId": "356963913aa7c79f", "scanner": "scanner-primary", "fingerprint": "765636b64d666518", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe_kml.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-62ca7b95c3482b81", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_kml.py:60"}, "properties": {"repobilityId": "35a4b64c4bf335ba", "scanner": "scanner-primary", "fingerprint": "62ca7b95c3482b81", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe_kml.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-fb5ab28bb63c12cc", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_fp8_perchannel_moe.py:52"}, "properties": {"repobilityId": "5bc6bae98994dd19", "scanner": "scanner-primary", "fingerprint": "fb5ab28bb63c12cc", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_fp8_perchannel_moe.py"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-e731547ce98d6147", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_k2_write_buffer.py:49"}, "properties": {"repobilityId": "a9c23b5d80b05790", "scanner": "scanner-primary", "fingerprint": "e731547ce98d6147", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_k2_write_buffer.py"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-c1b74deb4fb9dfdb", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_amx.py:101"}, "properties": {"repobilityId": "4c3923e0caf5bd80", "scanner": "scanner-primary", "fingerprint": "c1b74deb4fb9dfdb", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe_amx.py"}, "region": {"startLine": 101}}}]}, {"ruleId": "scanner-f8b1eccd391fbc43", "level": "none", "message": {"text": "Commented-code block (11 lines) in kt-kernel/bench/bench_moe.py:343"}, "properties": {"repobilityId": "8b4177f5efb5ac0b", "scanner": "scanner-primary", "fingerprint": "f8b1eccd391fbc43", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe.py"}, "region": {"startLine": 343}}}]}, {"ruleId": "scanner-6f514df5146c60df", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe.py:54"}, "properties": {"repobilityId": "b8a7413877147c60", "scanner": "scanner-primary", "fingerprint": "6f514df5146c60df", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe.py"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-6c8d87eeaa361549", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_amx_k.py:60"}, "properties": {"repobilityId": "0714738696686c35", "scanner": "scanner-primary", "fingerprint": "6c8d87eeaa361549", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe_amx_k.py"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-21d2b47e39bf4114", "level": "none", "message": {"text": "Commented-code block (7 lines) in kt-kernel/bench/bench_moe_kernel.py:44"}, "properties": {"repobilityId": "a313256e8faba640", "scanner": "scanner-primary", "fingerprint": "21d2b47e39bf4114", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe_kernel.py"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-72cb4694b013ba09", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_moe_kernel.py:66"}, "properties": {"repobilityId": "ded919837ee1949a", "scanner": "scanner-primary", "fingerprint": "72cb4694b013ba09", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_moe_kernel.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-1d9fb9b1884f46b5", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/bench/bench_fp8_moe.py:53"}, "properties": {"repobilityId": "98bfcf00a2157723", "scanner": "scanner-primary", "fingerprint": "1d9fb9b1884f46b5", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/bench/bench_fp8_moe.py"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-a27042c5d4cec608", "level": "note", "message": {"text": "Legacy-named symbol `_deep_copy` in kt-kernel/python/cli/config/settings.py:95"}, "properties": {"repobilityId": "19d6cad0000f7f09", "scanner": "scanner-primary", "fingerprint": "a27042c5d4cec608", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-df3d4b4c5250b7b8", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/python/cli/commands/quant.py:368"}, "properties": {"repobilityId": "0065d18504b7a0c0", "scanner": "scanner-primary", "fingerprint": "df3d4b4c5250b7b8", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/python/cli/commands/quant.py"}, "region": {"startLine": 368}}}]}, {"ruleId": "scanner-d7396b3f39864cf5", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 kt-kernel/python/cli/commands/config.py:115"}, "properties": {"repobilityId": "12fb0b37ab59b340", "scanner": "scanner-primary", "fingerprint": "d7396b3f39864cf5", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/python/cli/commands/config.py"}, "region": {"startLine": 115}}}]}, {"ruleId": "scanner-2441aed68ba4c848", "level": "note", "message": {"text": "Legacy-named symbol `moe_analysis_v2` in kt-kernel/python/cli/utils/analyze_moe_model.py:67"}, "properties": {"repobilityId": "8aef4fe999eb9eec", "scanner": "scanner-primary", "fingerprint": "2441aed68ba4c848", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "09e650e35fa8a424", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "dad81e22e395c3c6", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-9aa9133a808c09bc", "level": "warning", "message": {"text": "FastAPI POST `chat_completion` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/endpoints/chat.py:135"}, "properties": {"repobilityId": "186a300da5efdb81", "scanner": "scanner-primary", "fingerprint": "9aa9133a808c09bc", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/endpoints/chat.py"}, "region": {"startLine": 135}}}]}, {"ruleId": "scanner-094ac7c5b8dc1238", "level": "warning", "message": {"text": "FastAPI POST `create_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:19"}, "properties": {"repobilityId": "5a03c0f4dfac12a2", "scanner": "scanner-primary", "fingerprint": "094ac7c5b8dc1238", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-c42f5e846e9114eb", "level": "warning", "message": {"text": "FastAPI POST `create_thread_and_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:39"}, "properties": {"repobilityId": "641ff38cf6a7cdf3", "scanner": "scanner-primary", "fingerprint": "c42f5e846e9114eb", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-6204a96c59e6d295", "level": "warning", "message": {"text": "FastAPI POST `modify_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:66"}, "properties": {"repobilityId": "d9c7ed21f781acb4", "scanner": "scanner-primary", "fingerprint": "6204a96c59e6d295", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-1849a0f4cbd50f39", "level": "warning", "message": {"text": "FastAPI POST `submit_tool_outputs_to_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:75"}, "properties": {"repobilityId": "a14cb883eebc4978", "scanner": "scanner-primary", "fingerprint": "1849a0f4cbd50f39", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-85d091ae93b92c6d", "level": "warning", "message": {"text": "FastAPI POST `cancel_run` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py:80"}, "properties": {"repobilityId": "a3c32b1e1581c875", "scanner": "scanner-primary", "fingerprint": "85d091ae93b92c6d", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-d48b22ada310d46e", "level": "warning", "message": {"text": "FastAPI POST `create_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py:13"}, "properties": {"repobilityId": "98f9cdc601cedfb6", "scanner": "scanner-primary", "fingerprint": "d48b22ada310d46e", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-1414dc0137980c36", "level": "warning", "message": {"text": "FastAPI POST `modify_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py:28"}, "properties": {"repobilityId": "d5bebab35951331a", "scanner": "scanner-primary", "fingerprint": "1414dc0137980c36", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-b4ca22a78bfc7028", "level": "warning", "message": {"text": "FastAPI DELETE `delete_thread` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py:33"}, "properties": {"repobilityId": "ce2256838e72f8d0", "scanner": "scanner-primary", "fingerprint": "b4ca22a78bfc7028", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/threads.py"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-4e42fd4899470cbd", "level": "warning", "message": {"text": "FastAPI POST `create_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:15"}, "properties": {"repobilityId": "9b2f950f8f565009", "scanner": "scanner-primary", "fingerprint": "4e42fd4899470cbd", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-c528cb0d6a59c5d8", "level": "warning", "message": {"text": "FastAPI POST `modify_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:42"}, "properties": {"repobilityId": "aede032b09dd3f8d", "scanner": "scanner-primary", "fingerprint": "c528cb0d6a59c5d8", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-935518436fee785e", "level": "warning", "message": {"text": "FastAPI DELETE `delete_message` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py:48"}, "properties": {"repobilityId": "c30930daf8f26201", "scanner": "scanner-primary", "fingerprint": "935518436fee785e", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/messages.py"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-b3ac7cd45500dacd", "level": "warning", "message": {"text": "FastAPI POST `create_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:18"}, "properties": {"repobilityId": "b292cabfd55045a6", "scanner": "scanner-primary", "fingerprint": "b3ac7cd45500dacd", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-3a70091700950312", "level": "warning", "message": {"text": "FastAPI POST `modify_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:54"}, "properties": {"repobilityId": "8041669512522f4d", "scanner": "scanner-primary", "fingerprint": "3a70091700950312", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-46bd6c0ff6840334", "level": "warning", "message": {"text": "FastAPI DELETE `delete_assistant` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py:62"}, "properties": {"repobilityId": "40ba29458cd8e805", "scanner": "scanner-primary", "fingerprint": "46bd6c0ff6840334", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/assistants/assistants.py"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-a99ca61d8f7b4256", "level": "warning", "message": {"text": "FastAPI POST `create_completion` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/openai/legacy/completions.py:14"}, "properties": {"repobilityId": "e3752bd17a1e3f1d", "scanner": "scanner-primary", "fingerprint": "a99ca61d8f7b4256", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/openai/legacy/completions.py"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-fb7c2b97bbf78f81", "level": "warning", "message": {"text": "FastAPI POST `generate` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:57"}, "properties": {"repobilityId": "60eab8f9876d24a9", "scanner": "scanner-primary", "fingerprint": "fb7c2b97bbf78f81", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/ollama/completions.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-aed755fe5d94a523", "level": "warning", "message": {"text": "FastAPI POST `chat` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:139"}, "properties": {"repobilityId": "d63191b6cc093c40", "scanner": "scanner-primary", "fingerprint": "aed755fe5d94a523", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/ollama/completions.py"}, "region": {"startLine": 139}}}]}, {"ruleId": "scanner-39193be4f29bdb19", "level": "warning", "message": {"text": "FastAPI POST `show` without auth dependency \u2014 archive/kt-sft/ktransformers/server/api/ollama/completions.py:266"}, "properties": {"repobilityId": "87cfe2074e69779f", "scanner": "scanner-primary", "fingerprint": "39193be4f29bdb19", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/server/api/ollama/completions.py"}, "region": {"startLine": 266}}}]}, {"ruleId": "scanner-ce68fcc5d5710992", "level": "warning", "message": {"text": "FastAPI POST `chat_completion` without auth dependency \u2014 archive/ktransformers/server/api/openai/endpoints/chat.py:135"}, "properties": {"repobilityId": "a7c0a180341347f7", "scanner": "scanner-primary", "fingerprint": "ce68fcc5d5710992", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/endpoints/chat.py"}, "region": {"startLine": 135}}}]}, {"ruleId": "scanner-c62b61293f1a95af", "level": "warning", "message": {"text": "FastAPI POST `create_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:19"}, "properties": {"repobilityId": "2a48e067217c62cc", "scanner": "scanner-primary", "fingerprint": "c62b61293f1a95af", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-9878e623ca100be9", "level": "warning", "message": {"text": "FastAPI POST `create_thread_and_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:39"}, "properties": {"repobilityId": "159a884b66a43b01", "scanner": "scanner-primary", "fingerprint": "9878e623ca100be9", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-92daebe3c0df88d4", "level": "warning", "message": {"text": "FastAPI POST `modify_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:66"}, "properties": {"repobilityId": "396cff26c9d1e3e6", "scanner": "scanner-primary", "fingerprint": "92daebe3c0df88d4", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-02e95e44e63621d2", "level": "warning", "message": {"text": "FastAPI POST `submit_tool_outputs_to_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:75"}, "properties": {"repobilityId": "56fef8fe99f3c9c4", "scanner": "scanner-primary", "fingerprint": "02e95e44e63621d2", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-d3e977626b1a5fb4", "level": "warning", "message": {"text": "FastAPI POST `cancel_run` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/runs.py:80"}, "properties": {"repobilityId": "31e2a344ff6bcc7f", "scanner": "scanner-primary", "fingerprint": "d3e977626b1a5fb4", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/runs.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-116aee81415df0be", "level": "warning", "message": {"text": "FastAPI POST `create_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:13"}, "properties": {"repobilityId": "7d792fe254e1d241", "scanner": "scanner-primary", "fingerprint": "116aee81415df0be", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/threads.py"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-f31453b764c6eab0", "level": "warning", "message": {"text": "FastAPI POST `modify_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:28"}, "properties": {"repobilityId": "548adc1bca2faed1", "scanner": "scanner-primary", "fingerprint": "f31453b764c6eab0", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/threads.py"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-621caf26f336afc0", "level": "warning", "message": {"text": "FastAPI DELETE `delete_thread` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/threads.py:33"}, "properties": {"repobilityId": "643cba03ac13a66a", "scanner": "scanner-primary", "fingerprint": "621caf26f336afc0", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/threads.py"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-79f7ff081d6b9c03", "level": "warning", "message": {"text": "FastAPI POST `create_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:15"}, "properties": {"repobilityId": "5dcf85d1eb513f68", "scanner": "scanner-primary", "fingerprint": "79f7ff081d6b9c03", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/messages.py"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-820c27a62a2af71f", "level": "warning", "message": {"text": "FastAPI POST `modify_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:42"}, "properties": {"repobilityId": "01c20fbc91d75a47", "scanner": "scanner-primary", "fingerprint": "820c27a62a2af71f", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/messages.py"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-6bba0a534acc7790", "level": "warning", "message": {"text": "FastAPI DELETE `delete_message` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/messages.py:48"}, "properties": {"repobilityId": "737e78460d6fbaee", "scanner": "scanner-primary", "fingerprint": "6bba0a534acc7790", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/messages.py"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-1547148a093d115c", "level": "warning", "message": {"text": "FastAPI POST `create_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.py:18"}, "properties": {"repobilityId": "2f8c012540ab2abb", "scanner": "scanner-primary", "fingerprint": "1547148a093d115c", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/assistants.py"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-a4eaf23dd1de120a", "level": "warning", "message": {"text": "FastAPI POST `modify_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.py:54"}, "properties": {"repobilityId": "ac4805987e600713", "scanner": "scanner-primary", "fingerprint": "a4eaf23dd1de120a", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/assistants.py"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-3d788b6c79bf86ef", "level": "warning", "message": {"text": "FastAPI DELETE `delete_assistant` without auth dependency \u2014 archive/ktransformers/server/api/openai/assistants/assistants.py:62"}, "properties": {"repobilityId": "c1f6439b4c7f3414", "scanner": "scanner-primary", "fingerprint": "3d788b6c79bf86ef", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/assistants/assistants.py"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-c30e97f3864ba2fa", "level": "warning", "message": {"text": "FastAPI POST `create_completion` without auth dependency \u2014 archive/ktransformers/server/api/openai/legacy/completions.py:14"}, "properties": {"repobilityId": "63e492936bfb8eb5", "scanner": "scanner-primary", "fingerprint": "c30e97f3864ba2fa", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/openai/legacy/completions.py"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-6f992371167dd70c", "level": "warning", "message": {"text": "FastAPI POST `generate` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:57"}, "properties": {"repobilityId": "05db2b3016efdcf1", "scanner": "scanner-primary", "fingerprint": "6f992371167dd70c", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/ollama/completions.py"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-944ced08b475a5ce", "level": "warning", "message": {"text": "FastAPI POST `chat` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:139"}, "properties": {"repobilityId": "ccb88761cc0371b0", "scanner": "scanner-primary", "fingerprint": "944ced08b475a5ce", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/ollama/completions.py"}, "region": {"startLine": 139}}}]}, {"ruleId": "scanner-63b3d658d1a19884", "level": "warning", "message": {"text": "FastAPI POST `show` without auth dependency \u2014 archive/ktransformers/server/api/ollama/completions.py:267"}, "properties": {"repobilityId": "045f9705507465e0", "scanner": "scanner-primary", "fingerprint": "63b3d658d1a19884", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/ktransformers/server/api/ollama/completions.py"}, "region": {"startLine": 267}}}]}, {"ruleId": "scanner-4565c1b5d8ea90ad", "level": "warning", "message": {"text": "Vulnerable dependency vue 2.7.16: GHSA-5j4c-8p2g-v4jx"}, "properties": {"repobilityId": "766cd8d75d9f6fc9", "scanner": "scanner-primary", "fingerprint": "4565c1b5d8ea90ad", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5j4c-8p2g-v4jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-52401540afdf487d", "level": "error", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-35jp-ww65-95wh"}, "properties": {"repobilityId": "74ab358b3fdf77db", "scanner": "scanner-primary", "fingerprint": "52401540afdf487d", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-35jp-ww65-95wh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1260a9c0fb073bcb", "level": "error", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-3g43-6gmg-66jw"}, "properties": {"repobilityId": "f6a17fe99d1561f0", "scanner": "scanner-primary", "fingerprint": "1260a9c0fb073bcb", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g43-6gmg-66jw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0e13a129e5df3254", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-3p68-rc4w-qgx5"}, "properties": {"repobilityId": "55c8072736c9bc57", "scanner": "scanner-primary", "fingerprint": "0e13a129e5df3254", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3p68-rc4w-qgx5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b703335c1160961", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-3w6x-2g7m-8v23"}, "properties": {"repobilityId": "82ec8659c1f4dc8a", "scanner": "scanner-primary", "fingerprint": "7b703335c1160961", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3w6x-2g7m-8v23"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-790ef3e1ec01c689", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-42h9-826w-cgv3"}, "properties": {"repobilityId": "691a0bef06552a22", "scanner": "scanner-primary", "fingerprint": "790ef3e1ec01c689", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-42h9-826w-cgv3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa62449923e5afc6", "level": "error", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-43fc-jf86-j433"}, "properties": {"repobilityId": "42c7f090901fd8db", "scanner": "scanner-primary", "fingerprint": "aa62449923e5afc6", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-43fc-jf86-j433"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f5c05d45a740ed69", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-445q-vr5w-6q77"}, "properties": {"repobilityId": "d0477a46659b6eac", "scanner": "scanner-primary", "fingerprint": "f5c05d45a740ed69", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-445q-vr5w-6q77"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-19ec582ed03cc970", "level": "error", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-4hjh-wcwx-xvwj"}, "properties": {"repobilityId": "215c167fe95f43be", "scanner": "scanner-primary", "fingerprint": "19ec582ed03cc970", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4hjh-wcwx-xvwj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4db23c0baefd87ac", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-5c9x-8gcm-mpgx"}, "properties": {"repobilityId": "bf8cca62c3db0d53", "scanner": "scanner-primary", "fingerprint": "4db23c0baefd87ac", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5c9x-8gcm-mpgx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6cbbacea8cc8d4b6", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-62hf-57xw-28j9"}, "properties": {"repobilityId": "dd690d7ff5407ed2", "scanner": "scanner-primary", "fingerprint": "6cbbacea8cc8d4b6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-62hf-57xw-28j9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-52cd910384888415", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-6chq-wfr3-2hj9"}, "properties": {"repobilityId": "a38e44ba11f2f782", "scanner": "scanner-primary", "fingerprint": "52cd910384888415", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6chq-wfr3-2hj9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-645959c4353c262a", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-777c-7fjr-54vf"}, "properties": {"repobilityId": "252f60c8b21b6f01", "scanner": "scanner-primary", "fingerprint": "645959c4353c262a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-777c-7fjr-54vf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a5a21f319a417954", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-7q8q-rj6j-mhjq"}, "properties": {"repobilityId": "4f159227895878d6", "scanner": "scanner-primary", "fingerprint": "a5a21f319a417954", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-7q8q-rj6j-mhjq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-257aaa1d249d75b2", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-898c-q2cr-xwhg"}, "properties": {"repobilityId": "a07a006f33f3178b", "scanner": "scanner-primary", "fingerprint": "257aaa1d249d75b2", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-898c-q2cr-xwhg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ab73eb57063c17c0", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-8hc4-vh64-cxmj"}, "properties": {"repobilityId": "e4faf59fcdea81c8", "scanner": "scanner-primary", "fingerprint": "ab73eb57063c17c0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8hc4-vh64-cxmj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-46c159653bd8e0d3", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-fvcv-3m26-pcqx"}, "properties": {"repobilityId": "5b19e11fd4f70c0a", "scanner": "scanner-primary", "fingerprint": "46c159653bd8e0d3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fvcv-3m26-pcqx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58c7dff9b6c4041d", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-hfxv-24rg-xrqf"}, "properties": {"repobilityId": "d2f5cada835ee8b4", "scanner": "scanner-primary", "fingerprint": "58c7dff9b6c4041d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hfxv-24rg-xrqf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b35a5575c0f5fd56", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-j5f8-grm9-p9fc"}, "properties": {"repobilityId": "8b00a88bff554b31", "scanner": "scanner-primary", "fingerprint": "b35a5575c0f5fd56", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-j5f8-grm9-p9fc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-054001df7101ba2e", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-jqh4-m9w3-8hp9"}, "properties": {"repobilityId": "84a7d57568cf5f79", "scanner": "scanner-primary", "fingerprint": "054001df7101ba2e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jqh4-m9w3-8hp9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-daa07a5d1e3d9e2d", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-jr5f-v2jv-69x6"}, "properties": {"repobilityId": "929eefcc9c40b0a0", "scanner": "scanner-primary", "fingerprint": "daa07a5d1e3d9e2d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jr5f-v2jv-69x6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-78d0a66249a23e0a", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-m7pr-hjqh-92cm"}, "properties": {"repobilityId": "0b28e426426ea5e2", "scanner": "scanner-primary", "fingerprint": "78d0a66249a23e0a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m7pr-hjqh-92cm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cc71b40fe89b7b68", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-mmx7-hfxf-jppx"}, "properties": {"repobilityId": "50bd67f500da5901", "scanner": "scanner-primary", "fingerprint": "cc71b40fe89b7b68", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mmx7-hfxf-jppx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e554c25cb3f12974", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-p92q-9vqr-4j8v"}, "properties": {"repobilityId": "d84d3c74d3b92d03", "scanner": "scanner-primary", "fingerprint": "e554c25cb3f12974", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p92q-9vqr-4j8v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8c10537472335f06", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-pf86-5x62-jrwf"}, "properties": {"repobilityId": "1fe9a216c1ca3c7d", "scanner": "scanner-primary", "fingerprint": "8c10537472335f06", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pf86-5x62-jrwf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2dac33350324e89d", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-pmv8-rq9r-6j72"}, "properties": {"repobilityId": "b92e143c33d3b0fe", "scanner": "scanner-primary", "fingerprint": "2dac33350324e89d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pmv8-rq9r-6j72"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-31f13a3f5daf69ea", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-pmwg-cvhr-8vh7"}, "properties": {"repobilityId": "641ec1479442f77f", "scanner": "scanner-primary", "fingerprint": "31f13a3f5daf69ea", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pmwg-cvhr-8vh7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ed3118abcd81bdda", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-q8qp-cvcw-x6jj"}, "properties": {"repobilityId": "0215dba13932e46b", "scanner": "scanner-primary", "fingerprint": "ed3118abcd81bdda", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8qp-cvcw-x6jj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9039dedc46d6be95", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-vf2m-468p-8v99"}, "properties": {"repobilityId": "667dcb251d1aede0", "scanner": "scanner-primary", "fingerprint": "9039dedc46d6be95", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vf2m-468p-8v99"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8749791bc749977", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-w9j2-pvgh-6h63"}, "properties": {"repobilityId": "d0a7fbae3b46db0f", "scanner": "scanner-primary", "fingerprint": "d8749791bc749977", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w9j2-pvgh-6h63"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e773b57ae5c87186", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-xhjh-pmcv-23jw"}, "properties": {"repobilityId": "e79dc8f948f934ff", "scanner": "scanner-primary", "fingerprint": "e773b57ae5c87186", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xhjh-pmcv-23jw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ff1b73aaab6cefc", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.7.0: GHSA-xx6v-rp6x-q39c"}, "properties": {"repobilityId": "72f98563b6e1413f", "scanner": "scanner-primary", "fingerprint": "4ff1b73aaab6cefc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xx6v-rp6x-q39c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b803dc6092028b65", "level": "warning", "message": {"text": "Vulnerable dependency element-plus 2.7.3: GHSA-5m5x-9j46-h678"}, "properties": {"repobilityId": "043b7073cdff3577", "scanner": "scanner-primary", "fingerprint": "b803dc6092028b65", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5m5x-9j46-h678"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f1fd5f83a61dd37", "level": "warning", "message": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-9r9m-ffp6-9x4v"}, "properties": {"repobilityId": "706b73adaf02acfd", "scanner": "scanner-primary", "fingerprint": "1f1fd5f83a61dd37", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9r9m-ffp6-9x4v"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6bccfd1679510e48", "level": "warning", "message": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-hjwq-mjwj-4x6c"}, "properties": {"repobilityId": "d07fd97872dc8736", "scanner": "scanner-primary", "fingerprint": "6bccfd1679510e48", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hjwq-mjwj-4x6c"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-98c491fec6086609", "level": "warning", "message": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-p2ph-7g93-hw3m"}, "properties": {"repobilityId": "72b786867a850a62", "scanner": "scanner-primary", "fingerprint": "98c491fec6086609", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p2ph-7g93-hw3m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f56f3e2d7611b7d", "level": "warning", "message": {"text": "Vulnerable dependency vue-i18n 9.13.1: GHSA-x8qp-wqqm-57ph"}, "properties": {"repobilityId": "bc5cfa5b07723c90", "scanner": "scanner-primary", "fingerprint": "6f56f3e2d7611b7d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-x8qp-wqqm-57ph"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ee2bb4d308528438", "level": "note", "message": {"text": "Vulnerable dependency webpack 5.91.0: GHSA-38r7-794h-5758"}, "properties": {"repobilityId": "2ad26346afbf8296", "scanner": "scanner-primary", "fingerprint": "ee2bb4d308528438", "layer": "dependencies", "severity": "low", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-38r7-794h-5758"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1cb376ecd9c8876", "level": "warning", "message": {"text": "Vulnerable dependency webpack 5.91.0: GHSA-4vvj-4cpr-p986"}, "properties": {"repobilityId": "a4ef09cd62667f83", "scanner": "scanner-primary", "fingerprint": "f1cb376ecd9c8876", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-4vvj-4cpr-p986"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bf891a6538687acb", "level": "warning", "message": {"text": "Vulnerable dependency webpack 5.91.0: GHSA-8fgc-7cc6-rx7x"}, "properties": {"repobilityId": "de8c6cb2d5694394", "scanner": "scanner-primary", "fingerprint": "bf891a6538687acb", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-8fgc-7cc6-rx7x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a791c1c53e30e388", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.1: GHSA-qfhq-4f3w-5fph"}, "properties": {"repobilityId": "91e3f3c5a467e0c7", "scanner": "scanner-primary", "fingerprint": "a791c1c53e30e388", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qfhq-4f3w-5fph"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9bb52a3144b432a5", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.1: GHSA-rrmf-rvhw-rf47"}, "properties": {"repobilityId": "fd3fa9a32e834d3d", "scanner": "scanner-primary", "fingerprint": "9bb52a3144b432a5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rrmf-rvhw-rf47"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4cefa5d23d3cb6bb", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.1: PYSEC-2026-139"}, "properties": {"repobilityId": "d829a1a3ec997847", "scanner": "scanner-primary", "fingerprint": "4cefa5d23d3cb6bb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-139"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e0383f6448433b4", "level": "warning", "message": {"text": "Vulnerable dependency torch 2.9.1: PYSEC-2026-2286"}, "properties": {"repobilityId": "04b9221b79f5bf58", "scanner": "scanner-primary", "fingerprint": "6e0383f6448433b4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2286"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kt-kernel/pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-710a4bd96f5d8077", "level": "note", "message": {"text": "Vulnerable dependency @babel/core 7.24.5: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": "09937e5883803e6c", "scanner": "scanner-primary", "fingerprint": "710a4bd96f5d8077", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4x5r-pxfx-6jf8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-af5850f9d312ad45", "level": "warning", "message": {"text": "Vulnerable dependency @babel/helpers 7.24.5: GHSA-968p-4wvh-cqc8"}, "properties": {"repobilityId": "86f42c3c2692e05b", "scanner": "scanner-primary", "fingerprint": "af5850f9d312ad45", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-968p-4wvh-cqc8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-114bdfcf7d6def16", "level": "warning", "message": {"text": "Vulnerable dependency @babel/plugin-transform-modules-systemjs 7.24.1: GHSA-fv7c-fp4j-7gwp"}, "properties": {"repobilityId": "00117e0c2d518543", "scanner": "scanner-primary", "fingerprint": "114bdfcf7d6def16", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fv7c-fp4j-7gwp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9274999eee291813", "level": "warning", "message": {"text": "Vulnerable dependency @babel/runtime 7.24.5: GHSA-968p-4wvh-cqc8"}, "properties": {"repobilityId": "7d99a3d131822085", "scanner": "scanner-primary", "fingerprint": "9274999eee291813", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-968p-4wvh-cqc8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bba457a2fef05961", "level": "error", "message": {"text": "Vulnerable dependency js-yaml 3.14.1: GHSA-52cp-r559-cp3m"}, "properties": {"repobilityId": "2c30c7f2691e2a6d", "scanner": "scanner-primary", "fingerprint": "bba457a2fef05961", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-52cp-r559-cp3m", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf795c572dcfc761", "level": "warning", "message": {"text": "Vulnerable dependency js-yaml 3.14.1: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": "ed976a4168e3b88f", "scanner": "scanner-primary", "fingerprint": "cf795c572dcfc761", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h67p-54hq-rp68", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-773d8219903843e4", "level": "warning", "message": {"text": "Vulnerable dependency js-yaml 3.14.1: GHSA-mh29-5h37-fv8m"}, "properties": {"repobilityId": "97b8c011ddf9854f", "scanner": "scanner-primary", "fingerprint": "773d8219903843e4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh29-5h37-fv8m", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-079385dcf0afabc4", "level": "warning", "message": {"text": "Vulnerable dependency @intlify/core-base 9.13.1: GHSA-9r9m-ffp6-9x4v"}, "properties": {"repobilityId": "68497df26baa4ba8", "scanner": "scanner-primary", "fingerprint": "079385dcf0afabc4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-9r9m-ffp6-9x4v", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-82bdd90a44825ff9", "level": "warning", "message": {"text": "Vulnerable dependency @intlify/core-base 9.13.1: GHSA-x8qp-wqqm-57ph"}, "properties": {"repobilityId": "65a3a9cbf321b7ce", "scanner": "scanner-primary", "fingerprint": "82bdd90a44825ff9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-x8qp-wqqm-57ph", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-758b0e7b3708276f", "level": "warning", "message": {"text": "Vulnerable dependency @intlify/shared 9.13.1: GHSA-hjwq-mjwj-4x6c"}, "properties": {"repobilityId": "090ca027bc51479d", "scanner": "scanner-primary", "fingerprint": "758b0e7b3708276f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hjwq-mjwj-4x6c", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7e88bc65dce12d94", "level": "warning", "message": {"text": "Vulnerable dependency @protobufjs/utf8 1.1.0: GHSA-q6x5-8v7m-xcrf"}, "properties": {"repobilityId": "d845ffffe8ff2904", "scanner": "scanner-primary", "fingerprint": "7e88bc65dce12d94", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-q6x5-8v7m-xcrf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fcbcd5e05eb3e27f", "level": "warning", "message": {"text": "Vulnerable dependency @tootallnate/once 1.1.2: GHSA-vpq2-c234-7xj6"}, "properties": {"repobilityId": "dde2d5815aec1ff8", "scanner": "scanner-primary", "fingerprint": "fcbcd5e05eb3e27f", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vpq2-c234-7xj6", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-00a7e20f9c92bffd", "level": "warning", "message": {"text": "Vulnerable dependency postcss 7.0.39: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "b51cdb626cecb37a", "scanner": "scanner-primary", "fingerprint": "00a7e20f9c92bffd", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1547444ca61491fa", "level": "warning", "message": {"text": "Vulnerable dependency postcss 7.0.39: GHSA-7fh5-64p2-3v2j"}, "properties": {"repobilityId": "23f05821b800d72a", "scanner": "scanner-primary", "fingerprint": "1547444ca61491fa", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7fh5-64p2-3v2j", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-703c5d57adcd1ad4", "level": "warning", "message": {"text": "Vulnerable dependency postcss 7.0.39: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "7c50b991b689d98c", "scanner": "scanner-primary", "fingerprint": "703c5d57adcd1ad4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f353b173e0eeec9", "level": "warning", "message": {"text": "Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6"}, "properties": {"repobilityId": "cf8ef5d83527dc1c", "scanner": "scanner-primary", "fingerprint": "1f353b173e0eeec9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2g4f-4pwh-qvx6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e9710770ed17d7a0", "level": "warning", "message": {"text": "Vulnerable dependency ajv 8.13.0: GHSA-2g4f-4pwh-qvx6"}, "properties": {"repobilityId": "d9e7f9f6f853c154", "scanner": "scanner-primary", "fingerprint": "e9710770ed17d7a0", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-2g4f-4pwh-qvx6", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1df84c7bbf9ed61", "level": "warning", "message": {"text": "Vulnerable dependency apollo-server-core 3.13.0: GHSA-9q82-xgwf-vj6h"}, "properties": {"repobilityId": "a1df541dd8f6602b", "scanner": "scanner-primary", "fingerprint": "f1df84c7bbf9ed61", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-9q82-xgwf-vj6h", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-914325ba776288b3", "level": "warning", "message": {"text": "Vulnerable dependency form-data 4.0.0: GHSA-fjxv-7rqg-78g4"}, "properties": {"repobilityId": "7307811b60017fe3", "scanner": "scanner-primary", "fingerprint": "914325ba776288b3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-fjxv-7rqg-78g4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-117619d599f2bb0c", "level": "warning", "message": {"text": "Vulnerable dependency form-data 4.0.0: GHSA-hmw2-7cc7-3qxx"}, "properties": {"repobilityId": "9c3a6da92cbc1d67", "scanner": "scanner-primary", "fingerprint": "117619d599f2bb0c", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hmw2-7cc7-3qxx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d5cd919ab61dcd7b", "level": "warning", "message": {"text": "Dependency apexcharts is two or more major versions behind"}, "properties": {"repobilityId": "0e1c9f97b012220e", "scanner": "scanner-primary", "fingerprint": "d5cd919ab61dcd7b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7effd068b162a8f4", "level": "note", "message": {"text": "Dependency axios-extensions is a major version behind"}, "properties": {"repobilityId": "f583d0bfc98ed4ec", "scanner": "scanner-primary", "fingerprint": "7effd068b162a8f4", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b5e55edd96239e6", "level": "warning", "message": {"text": "Dependency marked is two or more major versions behind"}, "properties": {"repobilityId": "59dbe0206f7a4c93", "scanner": "scanner-primary", "fingerprint": "1b5e55edd96239e6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1869db3875ce3ab3", "level": "warning", "message": {"text": "Dependency vue-i18n is two or more major versions behind"}, "properties": {"repobilityId": "171536395b591d3a", "scanner": "scanner-primary", "fingerprint": "1869db3875ce3ab3", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5b960afcc020ede1", "level": "note", "message": {"text": "Dependency vue-router is a major version behind"}, "properties": {"repobilityId": "b06e83a6a36b6a0a", "scanner": "scanner-primary", "fingerprint": "5b960afcc020ede1", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7e61d9a189d85b10", "level": "warning", "message": {"text": "Dependency webpack-cli is two or more major versions behind"}, "properties": {"repobilityId": "67e843c314850cd2", "scanner": "scanner-primary", "fingerprint": "7e61d9a189d85b10", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "archive/kt-sft/ktransformers/website/package.json"}, "region": {"startLine": 1}}}]}]}]}