Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

MoonshotAI/kimi-cli

https://github.com/MoonshotAI/kimi-cli · scanned 2026-07-23 19:41 UTC (4 days, 20 hours ago)

557 raw signals (0 security + 557 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 4 days, 20 hours ago · v7 · last Δ +5.7 (diff) · 535 actionable findings from 1 signal source. 22 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Scan summary Repository scanned at 57.7/100 with 100.0% coverage. It contains 9632 nodes across 30 cross-layer flows, written primarily in mixed languages. Engine surfaced 557 findings — concentrated in security (292), dependencies (128), quality (53). Risk profile is high: 1 critical, 121 high, 284 medium. Recommended next step: open the security layer findings first — that's where the highest-impact wins live.

Showing 497 of 535 actionable findings. 557 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

critical System graph security Trivy conf 1.00 CVE-2026-27962: authlib 1.6.5 — uv.lock
authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbi…
VulnCve 2026 27962
high System graph security Trivy conf 1.00 CVE-2025-62727: starlette 0.48.0 — uv.lock
starlette: Starlette DoS via Range header merging Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range p…
VulnCve 2025 62727
high System graph security Trivy conf 1.00 CVE-2025-66418: urllib3 2.5.0 — uv.lock
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimi…
VulnCve 2025 66418
high System graph security Trivy conf 1.00 CVE-2025-66471: urllib3 2.5.0 — uv.lock
urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handlin…
VulnCve 2025 66471
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 5.0.4 — vis/package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — vis/package-lock.json
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — web/package-lock.json
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — vis/package-lock.json
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — web/package-lock.json
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-21441: urllib3 2.5.0 — uv.lock
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loadin…
VulnCve 2026 21441
high System graph security Trivy conf 1.00 CVE-2026-23490: pyasn1 0.6.1 — uv.lock
pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnera…
VulnCve 2026 23490
high System graph security Trivy conf 1.00 CVE-2026-24486: python-multipart 0.0.20 — uv.lock
python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=…
VulnCve 2026 24486
high System graph security Trivy conf 1.00 CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 — web/package-lock.json
@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reus…
VulnCve 2026 25536
high System graph security Trivy conf 1.00 CVE-2026-25547: @isaacs/brace-expansion 5.0.0 — docs/bun.lock
brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range e…
VulnCve 2026 25547
high System graph security Trivy conf 1.00 CVE-2026-25547: @isaacs/brace-expansion 5.0.0 — web/package-lock.json
brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range e…
VulnCve 2026 25547
high System graph security Trivy conf 1.00 CVE-2026-26007: cryptography 46.0.2 — uv.lock
cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticC…
VulnCve 2026 26007
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 10.1.1 — docs/bun.lock
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 10.1.1 — web/package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-27606: rollup 4.56.0 — web/package-lock.json
rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal.…
VulnCve 2026 27606
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 10.1.1 — docs/bun.lock
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 10.1.1 — web/package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 10.1.1 — docs/bun.lock
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 10.1.1 — web/package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-28490: authlib 1.6.5 — uv.lock
authlib: Authlib: Information disclosure due to cryptographic padding oracle in JWE RSA1_5 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning the imp…
VulnCve 2026 28490
high System graph security Trivy conf 1.00 CVE-2026-28498: authlib 1.6.5 — uv.lock
authlib: Authlib: Authentication bypass via forged OpenID Connect ID Tokens Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OID…
VulnCve 2026 28498
high System graph security Trivy conf 1.00 CVE-2026-28802: authlib 1.6.5 — uv.lock
authlib: Authlib: Signature verification bypass via malicious JWT allows unauthorized access Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty sig…
VulnCve 2026 28802
high System graph security Trivy conf 1.00 CVE-2026-29045: hono 4.11.6 — web/package-lock.json
Hono vulnerable to arbitrary file access via serveStatic vulnerability Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsiste…
VulnCve 2026 29045
high System graph security Trivy conf 1.00 CVE-2026-29045: hono 4.12.3 — vis/package-lock.json
Hono vulnerable to arbitrary file access via serveStatic vulnerability Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsiste…
VulnCve 2026 29045
high System graph security Trivy conf 1.00 CVE-2026-29087: @hono/node-server 1.19.9 — vis/package-lock.json
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware p…
VulnCve 2026 29087
high System graph security Trivy conf 1.00 CVE-2026-29087: @hono/node-server 1.19.9 — web/package-lock.json
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware p…
VulnCve 2026 29087
high System graph security Trivy conf 1.00 CVE-2026-30827: express-rate-limit 8.2.1 — vis/package-lock.json
express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.3.0, the default keyGenerator in expr…
VulnCve 2026 30827
high System graph security Trivy conf 1.00 CVE-2026-30922: pyasn1 0.6.1 — uv.lock
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An at…
VulnCve 2026 30922
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 2.3.1 — vis/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 2.3.1 — web/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 4.0.3 — vis/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 4.0.3 — web/package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-39363: vite 7.3.1 — vis/package-lock.json
Vite: Vite: Information disclosure via WebSocket connection bypasses access control Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fe…
VulnCve 2026 39363
high System graph security Trivy conf 1.00 CVE-2026-39363: vite 7.3.1 — web/package-lock.json
Vite: Vite: Information disclosure via WebSocket connection bypasses access control Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fe…
VulnCve 2026 39363
high System graph security Trivy conf 1.00 CVE-2026-39364: vite 7.3.1 — vis/package-lock.json
vite: Vite: Information disclosure via query parameter manipulation on the development server Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with …
VulnCve 2026 39364
high System graph security Trivy conf 1.00 CVE-2026-39364: vite 7.3.1 — web/package-lock.json
vite: Vite: Information disclosure via query parameter manipulation on the development server Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with …
VulnCve 2026 39364
high System graph security Trivy conf 1.00 CVE-2026-41066: lxml 6.0.2 — uv.lock
lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input t…
VulnCve 2026 41066
high System graph security Trivy conf 1.00 CVE-2026-42215: gitpython 3.1.45 — uv.lock
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equival…
VulnCve 2026 42215
high System graph security Trivy conf 1.00 CVE-2026-42284: gitpython 3.1.45 — uv.lock
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--bran…
VulnCve 2026 42284
high System graph security Trivy conf 1.00 CVE-2026-42561: python-multipart 0.0.20 — uv.lock
python-multipart: python-multipart: Denial of Service via excessive multipart part headers Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, Multip…
VulnCve 2026 42561
high System graph security Trivy conf 1.00 CVE-2026-44243: gitpython 3.1.45 — uv.lock
GitPython: GitPython: Arbitrary file write via crafted reference paths GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, ov…
VulnCve 2026 44243
high System graph security Trivy conf 1.00 CVE-2026-44244: gitpython 3.1.45 — uv.lock
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() con…
VulnCve 2026 44244
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.5.0 — uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash-es 4.17.21 — web/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash-es 4.17.22 — docs/bun.lock
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash-es 4.17.23 — web/package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-48526: pyjwt 2.12.1 — uv.lock
python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in H…
VulnCve 2026 48526
high System graph security Trivy conf 1.00 CVE-2026-48801: linkify-it 5.0.0 — docs/bun.lock
linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy lin…
VulnCve 2026 48801
high System graph security Trivy conf 1.00 CVE-2026-48818: starlette 0.48.0 — uv.lock
starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initia…
VulnCve 2026 48818
high System graph security Trivy conf 1.00 CVE-2026-4926: path-to-regexp 8.3.0 — vis/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, cau…
VulnCve 2026 4926
high System graph security Trivy conf 1.00 CVE-2026-4926: path-to-regexp 8.3.0 — web/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, cau…
VulnCve 2026 4926
high System graph security Trivy conf 1.00 CVE-2026-49825: lxml-html-clean 0.4.3 — uv.lock
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes # `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`) **Reporter:** Guillem Lefait <[email protected]> · **Date:** 2026-05-10 **Affected:** `lxml` ≤ 6.…
VulnCve 2026 49825
high System graph security Trivy conf 1.00 CVE-2026-52869: mcp 1.27.1 — uv.lock
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTran…
VulnCve 2026 52869
high System graph security Trivy conf 1.00 CVE-2026-52870: mcp 1.27.1 — uv.lock
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() f…
VulnCve 2026 52870
high System graph security Trivy conf 1.00 CVE-2026-53539: python-multipart 0.0.20 — uv.lock
python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it fir…
VulnCve 2026 53539
high System graph security Trivy conf 1.00 CVE-2026-53571: vite 7.3.1 — vis/package-lock.json
vite: `server.fs.deny` bypass on Windows alternate paths Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive…
VulnCve 2026 53571
high System graph security Trivy conf 1.00 CVE-2026-53571: vite 7.3.1 — web/package-lock.json
vite: `server.fs.deny` bypass on Windows alternate paths Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive…
VulnCve 2026 53571
high System graph security Trivy conf 1.00 CVE-2026-54058: pillow 12.2.0 — uv.lock
Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride small…
VulnCve 2026 54058
high System graph security Trivy conf 1.00 CVE-2026-54059: pillow 12.2.0 — uv.lock
python-pillow: Pillow: Denial of Service via crafted PCF font data Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_chec…
VulnCve 2026 54059
high System graph security Trivy conf 1.00 CVE-2026-54060: pillow 12.2.0 — uv.lock
python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._d…
VulnCve 2026 54060
high System graph security Trivy conf 1.00 CVE-2026-54283: starlette 0.48.0 — uv.lock
starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These …
VulnCve 2026 54283
high System graph security Trivy conf 1.00 CVE-2026-54290: hono 4.11.6 — web/package-lock.json
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflec…
VulnCve 2026 54290
high System graph security Trivy conf 1.00 CVE-2026-54290: hono 4.12.3 — vis/package-lock.json
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflec…
VulnCve 2026 54290
high System graph security Trivy conf 1.00 CVE-2026-55379: pillow 12.2.0 — uv.lock
python-pillow: Pillow: Denial of Service via crafted BDF font file Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompressi…
VulnCve 2026 55379
high System graph security Trivy conf 1.00 CVE-2026-55380: pillow 12.2.0 — uv.lock
python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing …
VulnCve 2026 55380
high System graph security Trivy conf 1.00 CVE-2026-59197: pillow 12.2.0 — uv.lock
Pillow: Pillow: Native heap out-of-bounds write Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2…
VulnCve 2026 59197
high System graph security Trivy conf 1.00 CVE-2026-59199: pillow 12.2.0 — uv.lock
Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.…
VulnCve 2026 59199
high System graph security Trivy conf 1.00 CVE-2026-59200: pillow 12.2.0 — uv.lock
Pillow: Pillow: Denial of service via crafted PDF stream Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a c…
VulnCve 2026 59200
high System graph security Trivy conf 1.00 CVE-2026-59204: pillow 12.2.0 — uv.lock
Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 fi…
VulnCve 2026 59204
high System graph security Trivy conf 1.00 CVE-2026-59205: pillow 12.2.0 — uv.lock
Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode …
VulnCve 2026 59205
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 3.14.2 — docs/bun.lock
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 4.1.1 — vis/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59869: js-yaml 4.1.1 — web/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML documents js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where…
VulnCve 2026 59869
high System graph security Trivy conf 1.00 CVE-2026-59885: pyasn1 0.6.1 — uv.lock
pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted p…
VulnCve 2026 59885
high System graph security Trivy conf 1.00 CVE-2026-59886: pyasn1 0.6.1 — uv.lock
pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a f…
VulnCve 2026 59886
high System graph security Trivy conf 1.00 CVE-2026-59887: linkify-it 5.0.0 — docs/bun.lock
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaini…
VulnCve 2026 59887
high System graph security Trivy conf 1.00 CVE-2026-59950: mcp 1.27.1 — uv.lock
MCP Python SDK: WebSocket server transport does not support Host/Origin validation The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes w…
VulnCve 2026 59950
high System graph security Trivy conf 1.00 CVE-2026-6321: fast-uri 3.1.0 — vis/package-lock.json
fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory r…
VulnCve 2026 6321
high System graph security Trivy conf 1.00 CVE-2026-6321: fast-uri 3.1.0 — web/package-lock.json
fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory r…
VulnCve 2026 6321
high System graph security Trivy conf 1.00 CVE-2026-6322: fast-uri 3.1.0 — vis/package-lock.json
fast-uri: fast-uri: URI authority bypass due to improper delimiter handling fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a…
VulnCve 2026 6322
high System graph security Trivy conf 1.00 CVE-2026-6322: fast-uri 3.1.0 — web/package-lock.json
fast-uri: fast-uri: URI authority bypass due to improper delimiter handling fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a…
VulnCve 2026 6322
high System graph api Wiring conf 0.90 Dangling fetch: POST /api/open-in (vis/src/lib/api.ts:263)
`vis/src/lib/api.ts:263` calls `POST /api/open-in` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it. Tool: fetch Normalized path used for matching: `/open-in`
vis/src/lib/api.ts:263 Dangling fetchFetch
high System graph api Wiring conf 0.90 Dangling fetch: POST /api/open-in (web/src/features/chat/open-in-shared.ts:76)
`web/src/features/chat/open-in-shared.ts:76` calls `POST /api/open-in` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it. Tool: fetch Normalized path used for matching: `/open-in`
web/src/features/chat/open-in-shared.ts:76 Dangling fetchFetch
high System graph security auth conf 0.75 FastAPI DELETE `delete_session` without auth dependency — src/kimi_cli/vis/api/sessions.py:673
`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachab…
src/kimi_cli/vis/api/sessions.py:673 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI DELETE `delete_session` without auth dependency — src/kimi_cli/web/api/sessions.py:565
`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachab…
src/kimi_cli/web/api/sessions.py:565 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI PATCH `update_global_config` without auth dependency — src/kimi_cli/web/api/config.py:128
`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachabl…
src/kimi_cli/web/api/config.py:128 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI PATCH `update_session` without auth dependency — src/kimi_cli/web/api/sessions.py:586
`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachabl…
src/kimi_cli/web/api/sessions.py:586 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI POST `create_session` without auth dependency — src/kimi_cli/web/api/sessions.py:299
`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable.
src/kimi_cli/web/api/sessions.py:299 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI POST `fork_session_endpoint` without auth dependency — src/kimi_cli/web/api/sessions.py:684
`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable.
src/kimi_cli/web/api/sessions.py:684 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI POST `generate_session_title` without auth dependency — src/kimi_cli/web/api/sessions.py:749
`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable.
src/kimi_cli/web/api/sessions.py:749 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI POST `import_session` without auth dependency — src/kimi_cli/vis/api/sessions.py:606
`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable.
src/kimi_cli/vis/api/sessions.py:606 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI POST `open_in` without auth dependency — src/kimi_cli/web/api/open_in.py:176
`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable.
src/kimi_cli/web/api/open_in.py:176 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI POST `upload_session_file` without auth dependency — src/kimi_cli/web/api/sessions.py:379
`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable.
src/kimi_cli/web/api/sessions.py:379 securityAuth fastapi unauth mutation
high System graph security auth conf 0.75 FastAPI PUT `update_config_toml` without auth dependency — src/kimi_cli/web/api/config.py:187
`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable.
src/kimi_cli/web/api/config.py:187 securityAuth fastapi unauth mutation
high System graph security Trivy conf 1.00 GHSA-2f96-g7mh-g2hx: gitpython 3.1.45 — uv.lock
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist ## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4) **Component:** gitpython-developers/GitPython …
VulnGhsa 2f96 g7mh g2hx
high System graph security Trivy conf 1.00 GHSA-537c-gmf6-5ccf: cryptography 46.0.2 — uv.lock
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://o…
VulnGhsa 537c gmf6 5ccf
high System graph security Trivy conf 1.00 GHSA-956x-8gvw-wg5v: gitpython 3.1.45 — uv.lock
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()` ## Summary GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument i…
VulnGhsa 956x 8gvw wg5v
high System graph security Trivy conf 1.00 GHSA-mv93-w799-cj2w: gitpython 3.1.45 — uv.lock
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath Summary The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to c…
VulnGhsa mv93 w799 cj2w
high System graph security Trivy conf 1.00 GHSA-rwj8-pgh3-r573: gitpython 3.1.45 — uv.lock
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL ### Summary `Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clon…
VulnGhsa rwj8 pgh3 r573
high System graph cicd CI/CD security conf 1.00 GitHub Action tracks a moving branch
DeterminateSystems/nix-installer-action@main can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA.
.github/workflows/ci-kimi-cli.yml:279 CI/CD securitySupply chainGithub actions
high System graph security Skillspector conf 0.85 SkillSpector RA1 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md
write SKILL Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors. Skill: skill-creator Rule: RA1 Category: rogue-agent Severity: HIGH Confidence: 0.85 Remediati…
src/kimi_cli/skills/skill-creator/SKILL.md:224 Mcp skillRogue agentRa1
high System graph security Semgrep conf 0.55 subprocess shell true — examples/custom-kimi-soul/main.py:79
Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. Rule: py…
examples/custom-kimi-soul/main.py:79 SecurityPythonNon production context
high System graph dependencies dependencies conf 1.00 Vulnerable dependency js-yaml 3.14.2: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `3.14.2` (resolved in `docs/bun.lock`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869). js-yaml: YAML merge-key chains can force quadratic CPU consumption Aliases: CVE-2026-59869 Advisory: https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m Fix: upgrade …
docs/bun.lock ScaOsvGhsa 52cp r559 cp3m
high System graph dependencies dependencies conf 1.00 Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `web/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869). js-yaml: YAML merge-key chains can force quadratic CPU consumption Aliases: CVE-2026-59869 Advisory: https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m Fix: u…
web/package.json ScaOsvGhsa 52cp r559 cp3m
high System graph dependencies dependencies conf 0.90 Vulnerable dependency linkify-it 5.0.0: GHSA-22p9-wv53-3rq4
OSV.dev reports `linkify-it` at version `5.0.0` (resolved in `docs/bun.lock`) is affected by GHSA-22p9-wv53-3rq4 (aka CVE-2026-48801). Note: `linkify-it` is a transitive dependency — pulled in by another package, not declared directly in a manifest. LinkifyIt#match scan loop has quadratic algorith…
docs/bun.lock ScaOsvGhsa 22p9 wv53 3rq4
high System graph dependencies dependencies conf 0.90 Vulnerable dependency lodash-es 4.17.21: GHSA-r5fr-rjxr-66jc
OSV.dev reports `lodash-es` at version `4.17.21` (resolved in `docs/bun.lock`) is affected by GHSA-r5fr-rjxr-66jc (aka CVE-2021-23337, CVE-2026-4800). Note: `lodash-es` is a transitive dependency — pulled in by another package, not declared directly in a manifest. lodash vulnerable to Code Injecti…
docs/bun.lock ScaOsvGhsa r5fr rjxr 66jc
high System graph dependencies dependencies conf 0.90 Vulnerable dependency lodash-es 4.17.22: GHSA-r5fr-rjxr-66jc
OSV.dev reports `lodash-es` at version `4.17.22` (resolved in `docs/bun.lock`) is affected by GHSA-r5fr-rjxr-66jc (aka CVE-2021-23337, CVE-2026-4800). Note: `lodash-es` is a transitive dependency — pulled in by another package, not declared directly in a manifest. lodash vulnerable to Code Injecti…
docs/bun.lock ScaOsvGhsa r5fr rjxr 66jc
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 10.1.1: GHSA-23c5-xmqv-rm74
OSV.dev reports `minimatch` at version `10.1.1` (resolved in `docs/bun.lock`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch ReDoS: nested *() extglobs generate cat…
docs/bun.lock ScaOsvGhsa 23c5 xmqv rm74
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 10.1.1: GHSA-3ppc-4f35-3m26
OSV.dev reports `minimatch` at version `10.1.1` (resolved in `docs/bun.lock`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has a ReDoS via repeated wildcards with…
docs/bun.lock ScaOsvGhsa 3ppc 4f35 3m26
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 10.1.1: GHSA-7r86-cg39-jmmj
OSV.dev reports `minimatch` at version `10.1.1` (resolved in `docs/bun.lock`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has ReDoS: matchOne() combinatorial bac…
docs/bun.lock ScaOsvGhsa 7r86 cg39 jmmj
high System graph dependencies dependencies conf 1.00 Vulnerable dependency pillow 12.2.0: GHSA-45hq-cxwh-f6vc
OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-45hq-cxwh-f6vc (aka CVE-2026-55379). Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading Aliases: BIT-pillow-2026-55379, CVE-2026-55379, …
pyproject.toml ScaOsvGhsa 45hq cxwh f6vc
high System graph dependencies dependencies conf 0.90 Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q
OSV.dev reports `postcss` at version `8.5.6` (resolved in `docs/bun.lock`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623). Note: `postcss` is a transitive dependency — pulled in by another package, not declared directly in a manifest. PostCSS: Arbitrary file read and information disclosur…
docs/bun.lock ScaOsvGhsa 6g55 p6wh 862q
high System graph dependencies dependencies conf 0.90 Vulnerable dependency preact 10.28.1: GHSA-36hm-qxxp-pg3m
OSV.dev reports `preact` at version `10.28.1` (resolved in `docs/bun.lock`) is affected by GHSA-36hm-qxxp-pg3m (aka CVE-2026-22028). Note: `preact` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Preact has JSON VNode Injection issue Aliases: CVE-20…
docs/bun.lock ScaOsvGhsa 36hm qxxp pg3m
high System graph dependencies dependencies conf 1.00 Vulnerable dependency uuid 11.1.0: GHSA-w5hq-g745-h8pq
OSV.dev reports `uuid` at version `11.1.0` (resolved in `docs/bun.lock`) is affected by GHSA-w5hq-g745-h8pq (aka CVE-2026-41907, CVE-2026-41988). uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided Aliases: CVE-2026-41907, CVE-2026-41988 Advisory: https://osv.dev/vulnerability/GHSA…
docs/bun.lock ScaOsvGhsa w5hq g745 h8pq
high System graph dependencies dependencies conf 1.00 Vulnerable dependency uuid 13.0.0: GHSA-w5hq-g745-h8pq
OSV.dev reports `uuid` at version `13.0.0` (resolved in `web/package-lock.json`) is affected by GHSA-w5hq-g745-h8pq (aka CVE-2026-41907, CVE-2026-41988). uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided Aliases: CVE-2026-41907, CVE-2026-41988 Advisory: https://osv.dev/vulnerabil…
web/package.json ScaOsvGhsa w5hq g745 h8pq
high System graph dependencies dependencies conf 1.00 Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff
OSV.dev reports `vite` at version `5.4.21` (resolved in `docs/bun.lock`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571). vite: `server.fs.deny` bypass on Windows alternate paths Aliases: CVE-2026-53571 Advisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff Fix: upgrade `vite` past t…
docs/bun.lock ScaOsvGhsa fx2h pf6j xcff
high System graph dependencies dependencies conf 0.70 Vulnerable dependency vite 7.2.4: GHSA-fx2h-pf6j-xcff
OSV.dev reports `vite` at version `7.2.4` (declared in `vis/package.json`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571). Note: `7.2.4` is the declared floor of a range — the installed version may be newer. vite: `server.fs.deny` bypass on Windows alternate paths Aliases: CVE-2026-53571…
vis/package.json ScaOsvGhsa fx2h pf6j xcff
high System graph dependencies dependencies conf 0.70 Vulnerable dependency vite 7.2.4: GHSA-p9ff-h696-f583
OSV.dev reports `vite` at version `7.2.4` (declared in `vis/package.json`) is affected by GHSA-p9ff-h696-f583 (aka CVE-2026-39363). Note: `7.2.4` is the declared floor of a range — the installed version may be newer. Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket Aliases: CV…
vis/package.json ScaOsvGhsa p9ff h696 f583
medium System graph frontend Frontend quality conf 0.80 `dangerouslySetInnerHTML` used in a React component — web/src/components/ai-elements/code-block.tsx:419
Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library. Why: OWASP basics. Already partially flagged by the security analyzer. Rule id: fq.dangerous-html
web/src/components/ai-elements/code-block.tsx:419 Fq dangerous html
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: docs/zh/customization/agents.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
docs/zh/customization/agents.md VerificationAgents md
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: src/kimi_cli/acp/AGENTS.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
src/kimi_cli/acp/AGENTS.md VerificationAgents md
medium System graph quality Agent instructions conf 1.00 Agent authority lacks a verifier contract: src/kimi_cli/skills/kimi-cli-help/SKILL.md
This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes.
src/kimi_cli/skills/kimi-cli-help/SKILL.md VerificationSkill file
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph security Trivy conf 1.00 CVE-2025-13465: lodash-es 4.17.21 — web/package-lock.json
lodash: prototype pollution in _.unset and _.omit functions Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion o…
VulnCve 2025 13465
medium System graph security Trivy conf 1.00 CVE-2025-13465: lodash-es 4.17.22 — docs/bun.lock
lodash: prototype pollution in _.unset and _.omit functions Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion o…
VulnCve 2025 13465
medium System graph security Trivy conf 1.00 CVE-2025-68158: authlib 1.6.5 — uv.lock
Authlib: Authlib: Cross-Site Request Forgery due to improper session management in state storage Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF …
VulnCve 2025 68158
medium System graph security Trivy conf 1.00 CVE-2025-69873: ajv 8.17.1 — web/package-lock.json
ajv: ReDoS via $data reference ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaS…
VulnCve 2025 69873
medium System graph security Trivy conf 1.00 CVE-2026-0540: dompurify 3.3.1 — docs/bun.lock
DOMPurify: DOMPurify: Cross-site scripting vulnerability DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, n…
VulnCve 2026 0540
medium System graph security Trivy conf 1.00 CVE-2026-0540: dompurify 3.3.1 — web/package-lock.json
DOMPurify: DOMPurify: Cross-site scripting vulnerability DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, n…
VulnCve 2026 0540
medium System graph security Trivy conf 1.00 CVE-2026-22815: aiohttp 3.13.3 — uv.lock
aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched …
VulnCve 2026 22815
medium System graph security Trivy conf 1.00 CVE-2026-2327: markdown-it 14.1.0 — docs/bun.lock
markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An a…
VulnCve 2026 2327
medium System graph security Trivy conf 1.00 CVE-2026-24398: hono 4.11.6 — web/package-lock.json
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pa…
VulnCve 2026 24398
medium System graph security Trivy conf 1.00 CVE-2026-24472: hono 4.11.6 — web/package-lock.json
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP…
VulnCve 2026 24472
medium System graph security Trivy conf 1.00 CVE-2026-24473: hono 4.11.6 — web/package-lock.json
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter) Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulner…
VulnCve 2026 24473
medium System graph security Trivy conf 1.00 CVE-2026-24771: hono 4.11.6 — web/package-lock.json
Hono vulnerable to XSS through ErrorBoundary component Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-Site Scripting (XSS) vulnerability exists in the `ErrorBoundary` component of the hono/jsx library. Under certain usage pat…
VulnCve 2026 24771
medium System graph security Trivy conf 1.00 CVE-2026-25645: requests 2.32.5 — uv.lock
requests: Requests: Security bypass due to predictable temporary file creation Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. …
VulnCve 2026 25645
medium System graph security Trivy conf 1.00 CVE-2026-28348: lxml-html-clean 0.4.3 — uv.lock
lxml_html_clean is a project for HTML cleaning functionalities copied ... lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This c…
VulnCve 2026 28348
medium System graph security Trivy conf 1.00 CVE-2026-28350: lxml-html-clean 0.4.3 — uv.lock
lxml_html_clean is a project for HTML cleaning functionalities copied ... lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, …
VulnCve 2026 28350
medium System graph security Trivy conf 1.00 CVE-2026-28684: python-dotenv 1.2.1 — uv.lock
python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` file…
VulnCve 2026 28684
medium System graph security Trivy conf 1.00 CVE-2026-29085: hono 4.11.6 — web/package-lock.json
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE() Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (…
VulnCve 2026 29085
medium System graph security Trivy conf 1.00 CVE-2026-29085: hono 4.12.3 — vis/package-lock.json
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE() Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (…
VulnCve 2026 29085
medium System graph security Trivy conf 1.00 CVE-2026-29086: hono 4.11.6 — web/package-lock.json
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie() Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\r), or newline cha…
VulnCve 2026 29086
medium System graph security Trivy conf 1.00 CVE-2026-29086: hono 4.12.3 — vis/package-lock.json
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie() Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\r), or newline cha…
VulnCve 2026 29086
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash-es 4.17.21 — web/package-lock.json
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash-es 4.17.22 — docs/bun.lock
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash-es 4.17.23 — web/package-lock.json
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-33672: picomatch 2.3.1 — vis/package-lock.json
picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Becau…
VulnCve 2026 33672
medium System graph security Trivy conf 1.00 CVE-2026-33672: picomatch 2.3.1 — web/package-lock.json
picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Becau…
VulnCve 2026 33672
medium System graph security Trivy conf 1.00 CVE-2026-33672: picomatch 4.0.3 — vis/package-lock.json
picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Becau…
VulnCve 2026 33672
medium System graph security Trivy conf 1.00 CVE-2026-33672: picomatch 4.0.3 — web/package-lock.json
picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Becau…
VulnCve 2026 33672
medium System graph security Trivy conf 1.00 CVE-2026-33750: brace-expansion 5.0.4 — vis/package-lock.json
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) caus…
VulnCve 2026 33750
medium System graph security Trivy conf 1.00 CVE-2026-34515: aiohttp 3.13.3 — uv.lock
aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been pat…
VulnCve 2026 34515
medium System graph security Trivy conf 1.00 CVE-2026-34516: aiohttp 3.13.3 — uv.lock
aiohttp: AIOHTTP: Denial of Service via excessive multipart headers AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowin…
VulnCve 2026 34516
medium System graph security Trivy conf 1.00 CVE-2026-34525: aiohttp 3.13.3 — uv.lock
aiohttp: aiohttp: Security bypass via multiple Host headers AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4. Package: aiohttp Installed: 3.13.3 Fix…
VulnCve 2026 34525
medium System graph security Trivy conf 1.00 CVE-2026-34993: aiohttp 3.13.3 — uv.lock
aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using th…
VulnCve 2026 34993
medium System graph security Trivy conf 1.00 CVE-2026-39365: vite 7.3.1 — vis/package-lock.json
vite: Vite: Information disclosure via path traversal in dev server's .map request handling Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFil…
VulnCve 2026 39365
medium System graph security Trivy conf 1.00 CVE-2026-39365: vite 7.3.1 — web/package-lock.json
vite: Vite: Information disclosure via path traversal in dev server's .map request handling Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFil…
VulnCve 2026 39365
medium System graph security Trivy conf 1.00 CVE-2026-39406: @hono/node-server 1.19.9 — vis/package-lock.json
@hono/node-server: Middleware bypass via repeated slashes in serveStatic @hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path.…
VulnCve 2026 39406
medium System graph security Trivy conf 1.00 CVE-2026-39406: @hono/node-server 1.19.9 — web/package-lock.json
@hono/node-server: Middleware bypass via repeated slashes in serveStatic @hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path.…
VulnCve 2026 39406
medium System graph security Trivy conf 1.00 CVE-2026-39407: hono 4.11.6 — web/package-lock.json
Hono: Middleware bypass via repeated slashes in serveStatic Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the reques…
VulnCve 2026 39407
medium System graph security Trivy conf 1.00 CVE-2026-39407: hono 4.12.3 — vis/package-lock.json
Hono: Middleware bypass via repeated slashes in serveStatic Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the reques…
VulnCve 2026 39407
medium System graph security Trivy conf 1.00 CVE-2026-39408: hono 4.11.6 — web/package-lock.json
Hono: Path traversal in toSSG() allows writing files outside the output directory Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during stat…
VulnCve 2026 39408
medium System graph security Trivy conf 1.00 CVE-2026-39408: hono 4.12.3 — vis/package-lock.json
Hono: Path traversal in toSSG() allows writing files outside the output directory Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during stat…
VulnCve 2026 39408
medium System graph security Trivy conf 1.00 CVE-2026-39409: hono 4.11.6 — web/package-lock.json
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying I…
VulnCve 2026 39409
medium System graph security Trivy conf 1.00 CVE-2026-39409: hono 4.12.3 — vis/package-lock.json
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying I…
VulnCve 2026 39409
medium System graph security Trivy conf 1.00 CVE-2026-39410: hono 4.11.6 — web/package-lock.json
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie() Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. C…
VulnCve 2026 39410
medium System graph security Trivy conf 1.00 CVE-2026-39410: hono 4.12.3 — vis/package-lock.json
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie() Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. C…
VulnCve 2026 39410
medium System graph security Trivy conf 1.00 CVE-2026-39892: cryptography 46.0.2 — uv.lock
cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.…
VulnCve 2026 39892
medium System graph security Trivy conf 1.00 CVE-2026-40347: python-multipart 0.0.20 — uv.lock
python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epi…
VulnCve 2026 40347
medium System graph security Trivy conf 1.00 CVE-2026-41148: mermaid 11.12.2 — docs/bun.lock
mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS inj…
VulnCve 2026 41148
medium System graph security Trivy conf 1.00 CVE-2026-41148: mermaid 11.12.2 — web/package-lock.json
mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS inj…
VulnCve 2026 41148
medium System graph security Trivy conf 1.00 CVE-2026-41149: mermaid 11.12.2 — docs/bun.lock
mermaid: Mermaid: HTML injection via classDef directive in state diagrams Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the defau…
VulnCve 2026 41149
medium System graph security Trivy conf 1.00 CVE-2026-41149: mermaid 11.12.2 — web/package-lock.json
mermaid: Mermaid: HTML injection via classDef directive in state diagrams Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the defau…
VulnCve 2026 41149
medium System graph security Trivy conf 1.00 CVE-2026-41150: mermaid 11.12.2 — docs/bun.lock
mermaid: Mermaid: Denial of Service via specially crafted gantt charts Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attr…
VulnCve 2026 41150
medium System graph security Trivy conf 1.00 CVE-2026-41150: mermaid 11.12.2 — web/package-lock.json
mermaid: Mermaid: Denial of Service via specially crafted gantt charts Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attr…
VulnCve 2026 41150
medium System graph security Trivy conf 1.00 CVE-2026-41159: mermaid 11.12.2 — docs/bun.lock
mermaid: Mermaid: Information disclosure and page defacement via CSS injection Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies outside of the Merm…
VulnCve 2026 41159
medium System graph security Trivy conf 1.00 CVE-2026-41159: mermaid 11.12.2 — web/package-lock.json
mermaid: Mermaid: Information disclosure and page defacement via CSS injection Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies outside of the Merm…
VulnCve 2026 41159
medium System graph security Trivy conf 1.00 CVE-2026-41238: dompurify 3.3.1 — docs/bun.lock
DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with th…
VulnCve 2026 41238
medium System graph security Trivy conf 1.00 CVE-2026-41238: dompurify 3.3.1 — web/package-lock.json
DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with th…
VulnCve 2026 41238
medium System graph security Trivy conf 1.00 CVE-2026-41239: dompurify 3.3.1 — docs/bun.lock
DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from u…
VulnCve 2026 41239
medium System graph security Trivy conf 1.00 CVE-2026-41239: dompurify 3.3.1 — web/package-lock.json
DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from u…
VulnCve 2026 41239
medium System graph security Trivy conf 1.00 CVE-2026-41240: dompurify 3.3.1 — docs/bun.lock
DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Comm…
VulnCve 2026 41240
medium System graph security Trivy conf 1.00 CVE-2026-41240: dompurify 3.3.1 — web/package-lock.json
DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Comm…
VulnCve 2026 41240
medium System graph security Trivy conf 1.00 CVE-2026-41305: postcss 8.5.6 — vis/package-lock.json
postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifyin…
VulnCve 2026 41305
medium System graph security Trivy conf 1.00 CVE-2026-41305: postcss 8.5.6 — web/package-lock.json
postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifyin…
VulnCve 2026 41305
medium System graph security Trivy conf 1.00 CVE-2026-41425: authlib 1.6.5 — uv.lock
authlib: Authlib: Cross-Site Request Forgery (CSRF) vulnerability in OAuth cache feature Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability …
VulnCve 2026 41425
medium System graph security Trivy conf 1.00 CVE-2026-41479: authlib 1.6.5 — uv.lock
Authlib is a Python library which builds OAuth and OpenID Connect serv ... Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an uns…
VulnCve 2026 41479
medium System graph security Trivy conf 1.00 CVE-2026-41907: uuid 11.1.0 — docs/bun.lock
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silen…
VulnCve 2026 41907
medium System graph security Trivy conf 1.00 CVE-2026-41907: uuid 11.1.0 — web/package-lock.json
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silen…
VulnCve 2026 41907
medium System graph security Trivy conf 1.00 CVE-2026-41907: uuid 13.0.0 — web/package-lock.json
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silen…
VulnCve 2026 41907
medium System graph security Trivy conf 1.00 CVE-2026-42338: ip-address 10.0.1 — vis/package-lock.json
ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embeddi…
VulnCve 2026 42338
medium System graph security Trivy conf 1.00 CVE-2026-44455: hono 4.11.6 — web/package-lock.json
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generat…
VulnCve 2026 44455
medium System graph security Trivy conf 1.00 CVE-2026-44455: hono 4.12.3 — vis/package-lock.json
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generat…
VulnCve 2026 44455
medium System graph security Trivy conf 1.00 CVE-2026-44456: hono 4.11.6 — web/package-lock.json
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunke…
VulnCve 2026 44456
medium System graph security Trivy conf 1.00 CVE-2026-44456: hono 4.12.3 — vis/package-lock.json
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunke…
VulnCve 2026 44456
medium System graph security Trivy conf 1.00 CVE-2026-44457: hono 4.11.6 — web/package-lock.json
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Var…
VulnCve 2026 44457
medium System graph security Trivy conf 1.00 CVE-2026-44457: hono 4.12.3 — vis/package-lock.json
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Var…
VulnCve 2026 44457
medium System graph security Trivy conf 1.00 CVE-2026-44458: hono 4.11.6 — web/package-lock.json
Hono has CSS Declaration Injection via Style Object Values in JSX SSR Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or …
VulnCve 2026 44458
medium System graph security Trivy conf 1.00 CVE-2026-44458: hono 4.12.3 — vis/package-lock.json
Hono has CSS Declaration Injection via Style Object Values in JSX SSR Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or …
VulnCve 2026 44458
medium System graph security Trivy conf 1.00 CVE-2026-44681: authlib 1.6.5 — uv.lock
Authlib is a Python library which builds OAuth and OpenID Connect serv ... Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a rem…
VulnCve 2026 44681
medium System graph security Trivy conf 1.00 CVE-2026-45149: brace-expansion 5.0.4 — vis/package-lock.json
brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expa…
VulnCve 2026 45149
medium System graph security Trivy conf 1.00 CVE-2026-45409: idna 3.10 — uv.lock
python-idna: idna: Denial of Service via specially crafted long inputs Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as …
VulnCve 2026 45409
medium System graph security Trivy conf 1.00 CVE-2026-47265: aiohttp 3.13.3 — uv.lock
python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cr…
VulnCve 2026 47265
medium System graph security Trivy conf 1.00 CVE-2026-47673: hono 4.11.6 — web/package-lock.json
Hono: JWT middleware accepts any Authorization scheme, not only Bearer Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header va…
VulnCve 2026 47673
medium System graph security Trivy conf 1.00 CVE-2026-47673: hono 4.12.3 — vis/package-lock.json
Hono: JWT middleware accepts any Authorization scheme, not only Bearer Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header va…
VulnCve 2026 47673
medium System graph security Trivy conf 1.00 CVE-2026-47674: hono 4.11.6 — web/package-lock.json
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules…
VulnCve 2026 47674
medium System graph security Trivy conf 1.00 CVE-2026-47674: hono 4.12.3 — vis/package-lock.json
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules…
VulnCve 2026 47674
medium System graph security Trivy conf 1.00 CVE-2026-47675: hono 4.11.6 — web/package-lock.json
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corru…
VulnCve 2026 47675
medium System graph security Trivy conf 1.00 CVE-2026-47675: hono 4.12.3 — vis/package-lock.json
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corru…
VulnCve 2026 47675
medium System graph security Trivy conf 1.00 CVE-2026-47676: hono 4.11.6 — web/package-lock.json
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw U…
VulnCve 2026 47676
medium System graph security Trivy conf 1.00 CVE-2026-47676: hono 4.12.3 — vis/package-lock.json
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw U…
VulnCve 2026 47676
medium System graph security Trivy conf 1.00 CVE-2026-48522: pyjwt 2.12.1 — uv.lock
python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector regis…
VulnCve 2026 48522
medium System graph security Trivy conf 1.00 CVE-2026-48523: pyjwt 2.12.1 — uv.lock
python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The to…
VulnCve 2026 48523
medium System graph security Trivy conf 1.00 CVE-2026-48525: pyjwt 2.12.1 — uv.lock
python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the co…
VulnCve 2026 48525
medium System graph security Trivy conf 1.00 CVE-2026-48710: starlette 0.48.0 — uv.lock
starlette: Starlette: Security restriction bypass via malformed HTTP Host header Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the r…
VulnCve 2026 48710
medium System graph security Trivy conf 1.00 CVE-2026-48817: starlette 0.48.0 — uv.lock
starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up a…
VulnCve 2026 48817
medium System graph security Trivy conf 1.00 CVE-2026-48988: markdown-it 14.1.0 — docs/bun.lock
markdown-it is a Markdown parser. Versions 14.1.1 and below contain a ... markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from rep…
VulnCve 2026 48988
medium System graph security Trivy conf 1.00 CVE-2026-4923: path-to-regexp 8.3.0 — vis/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second…
VulnCve 2026 4923
medium System graph security Trivy conf 1.00 CVE-2026-4923: path-to-regexp 8.3.0 — web/package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second…
VulnCve 2026 4923
medium System graph security Trivy conf 1.00 CVE-2026-49458: dompurify 3.3.1 — docs/bun.lock
dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks us…
VulnCve 2026 49458
medium System graph security Trivy conf 1.00 CVE-2026-49458: dompurify 3.3.1 — web/package-lock.json
dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks us…
VulnCve 2026 49458
medium System graph security Trivy conf 1.00 CVE-2026-49459: dompurify 3.3.1 — docs/bun.lock
dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form…
VulnCve 2026 49459
medium System graph security Trivy conf 1.00 CVE-2026-49459: dompurify 3.3.1 — web/package-lock.json
dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form…
VulnCve 2026 49459
medium System graph security Trivy conf 1.00 CVE-2026-49978: dompurify 3.3.1 — docs/bun.lock
dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing att…
VulnCve 2026 49978
medium System graph security Trivy conf 1.00 CVE-2026-49978: dompurify 3.3.1 — web/package-lock.json
dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing att…
VulnCve 2026 49978
medium System graph security Trivy conf 1.00 CVE-2026-53550: js-yaml 3.14.2 — docs/bun.lock
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence.…
VulnCve 2026 53550
medium System graph security Trivy conf 1.00 CVE-2026-53550: js-yaml 4.1.1 — vis/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence.…
VulnCve 2026 53550
medium System graph security Trivy conf 1.00 CVE-2026-53550: js-yaml 4.1.1 — web/package-lock.json
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence.…
VulnCve 2026 53550
medium System graph security Trivy conf 1.00 CVE-2026-53632: vite 7.3.1 — vis/package-lock.json
launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a U…
VulnCve 2026 53632
medium System graph security Trivy conf 1.00 CVE-2026-53632: vite 7.3.1 — web/package-lock.json
launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a U…
VulnCve 2026 53632
medium System graph security Trivy conf 1.00 CVE-2026-54273: aiohttp 3.13.3 — uv.lock
aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to …
VulnCve 2026 54273
medium System graph security Trivy conf 1.00 CVE-2026-54274: aiohttp 3.13.3 — uv.lock
aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory …
VulnCve 2026 54274
medium System graph security Trivy conf 1.00 CVE-2026-54276: aiohttp 3.13.3 — uv.lock
aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This like…
VulnCve 2026 54276
medium System graph security Trivy conf 1.00 CVE-2026-54277: aiohttp 3.13.3 — uv.lock
aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using…
VulnCve 2026 54277
medium System graph security Trivy conf 1.00 CVE-2026-54278: aiohttp 3.13.3 — uv.lock
aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one ch…
VulnCve 2026 54278
medium System graph security Trivy conf 1.00 CVE-2026-54286: hono 4.11.6 — web/package-lock.json
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Windows path resolver tre…
VulnCve 2026 54286
medium System graph security Trivy conf 1.00 CVE-2026-54286: hono 4.12.3 — vis/package-lock.json
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Windows path resolver tre…
VulnCve 2026 54286
medium System graph security Trivy conf 1.00 CVE-2026-54287: hono 4.11.6 — web/package-lock.json
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice …
VulnCve 2026 54287
medium System graph security Trivy conf 1.00 CVE-2026-54287: hono 4.12.3 — vis/package-lock.json
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice …
VulnCve 2026 54287
medium System graph security Trivy conf 1.00 CVE-2026-54288: hono 4.11.6 — web/package-lock.json
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within…
VulnCve 2026 54288
medium System graph security Trivy conf 1.00 CVE-2026-54288: hono 4.12.3 — vis/package-lock.json
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within…
VulnCve 2026 54288
medium System graph security Trivy conf 1.00 CVE-2026-54289: hono 4.11.6 — web/package-lock.json
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as severa…
VulnCve 2026 54289
medium System graph security Trivy conf 1.00 CVE-2026-54289: hono 4.12.3 — vis/package-lock.json
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as severa…
VulnCve 2026 54289
medium System graph security Trivy conf 1.00 CVE-2026-55798: pillow 12.2.0 — uv.lock
python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result t…
VulnCve 2026 55798
medium System graph security Trivy conf 1.00 CVE-2026-56761: hono 4.11.6 — web/package-lock.json
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attr…
VulnCve 2026 56761
medium System graph security Trivy conf 1.00 CVE-2026-56761: hono 4.12.3 — vis/package-lock.json
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attr…
VulnCve 2026 56761
medium System graph security Trivy conf 1.00 CVE-2026-59198: pillow 12.2.0 — uv.lock
Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copie…
VulnCve 2026 59198
medium System graph security Trivy conf 1.00 CVE-2026-59203: pillow 12.2.0 — uv.lock
Pillow: Pillow: Denial of Service via crafted EPS file Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to t…
VulnCve 2026 59203
medium System graph security Trivy conf 1.00 CVE-2026-59895: hono 4.11.6 — web/package-lock.json
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the …
VulnCve 2026 59895
medium System graph security Trivy conf 1.00 CVE-2026-59895: hono 4.12.3 — vis/package-lock.json
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the …
VulnCve 2026 59895
medium System graph security Trivy conf 1.00 CVE-2026-59896: hono 4.12.3 — vis/package-lock.json
hono/jsx does not isolate context per request, leading to cross-request data disclosure Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing creat…
VulnCve 2026 59896
medium System graph security Trivy conf 1.00 CVE-2026-59897: hono 4.11.6 — web/package-lock.json
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value bec…
VulnCve 2026 59897
medium System graph security Trivy conf 1.00 CVE-2026-59897: hono 4.12.3 — vis/package-lock.json
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value bec…
VulnCve 2026 59897
medium System graph security Trivy conf 1.00 CVE-2026-8723: qs 6.14.1 — web/package-lock.json
### Summary `qs.stringify` throws `TypeError` when called with `arr ... ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's nul…
VulnCve 2026 8723
medium System graph security Trivy conf 1.00 CVE-2026-8723: qs 6.15.0 — vis/package-lock.json
### Summary `qs.stringify` throws `TypeError` when called with `arr ... ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's nul…
VulnCve 2026 8723
medium System graph dependencies dependencies conf 0.90 Dependency ai is two or more major versions behind
`ai` is pinned at `5.0.99` in `web/package.json` while the latest release on the npm registry is `7.0.36` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `ai` to `7.0.36`.
web/package.json FreshnessOutdated
medium System graph security Trivy conf 1.00 GHSA-26pp-8wgv-hjvm: hono 4.11.6 — web/package-lock.json
Hono missing validation of cookie name on write path in setCookie() ## Summary Cookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers. While certain cookie attributes such as domain and path are validated, t…
VulnGhsa 26pp 8wgv hjvm
medium System graph security Trivy conf 1.00 GHSA-26pp-8wgv-hjvm: hono 4.12.3 — vis/package-lock.json
Hono missing validation of cookie name on write path in setCookie() ## Summary Cookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers. While certain cookie attributes such as domain and path are validated, t…
VulnGhsa 26pp 8wgv hjvm
medium System graph security Trivy conf 1.00 GHSA-39q2-94rc-95cp: dompurify 3.3.1 — docs/bun.lock
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation ## Summary In `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation. The condition: ``` !(tagCheck(tagName)) && (!AL…
VulnGhsa 39q2 94rc 95cp
medium System graph security Trivy conf 1.00 GHSA-39q2-94rc-95cp: dompurify 3.3.1 — web/package-lock.json
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation ## Summary In `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation. The condition: ``` !(tagCheck(tagName)) && (!AL…
VulnGhsa 39q2 94rc 95cp
medium System graph security Trivy conf 1.00 GHSA-76mc-f452-cxcm: dompurify 3.3.1 — docs/bun.lock
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` # Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` **CWE**: CWE-501 (Tr…
VulnGhsa 76mc f452 cxcm
medium System graph security Trivy conf 1.00 GHSA-76mc-f452-cxcm: dompurify 3.3.1 — web/package-lock.json
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` # Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` **CWE**: CWE-501 (Tr…
VulnGhsa 76mc f452 cxcm
medium System graph security Trivy conf 1.00 GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 — docs/bun.lock
DOMPurify USE_PROFILES prototype pollution allows event handlers ## Summary When `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.…
VulnGhsa cj63 jhhr wcxv
medium System graph security Trivy conf 1.00 GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 — web/package-lock.json
DOMPurify USE_PROFILES prototype pollution allows event handlers ## Summary When `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.…
VulnGhsa cj63 jhhr wcxv
medium System graph security Trivy conf 1.00 GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 — docs/bun.lock
DOMPurify ADD_ATTR predicate skips URI validation ## Summary DOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An…
VulnGhsa cjmm f4jc qw8r
medium System graph security Trivy conf 1.00 GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 — web/package-lock.json
DOMPurify ADD_ATTR predicate skips URI validation ## Summary DOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An…
VulnGhsa cjmm f4jc qw8r
medium System graph security Trivy conf 1.00 GHSA-cmwh-pvxp-8882: dompurify 3.3.1 — docs/bun.lock
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch) ## Summary DOMPurify 3.4.7 shipped a security fix ("permanent hook pollution") that makes a registered `uponSanitizeAttribute` hook's mutation of `data…
VulnGhsa cmwh pvxp 8882
medium System graph security Trivy conf 1.00 GHSA-cmwh-pvxp-8882: dompurify 3.3.1 — web/package-lock.json
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch) ## Summary DOMPurify 3.4.7 shipped a security fix ("permanent hook pollution") that makes a registered `uponSanitizeAttribute` hook's mutation of `data…
VulnGhsa cmwh pvxp 8882
medium System graph security Trivy conf 1.00 GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 — vis/package-lock.json
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) The same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44). ### Summary On Wind…
VulnGhsa frvp 7c67 39w9
medium System graph security Trivy conf 1.00 GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 — web/package-lock.json
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) The same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44). ### Summary On Wind…
VulnGhsa frvp 7c67 39w9
medium System graph security Trivy conf 1.00 GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 — docs/bun.lock
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization ## Description A mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `…
VulnGhsa h8r8 wccr v5f2
medium System graph security Trivy conf 1.00 GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 — web/package-lock.json
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization ## Description A mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `…
VulnGhsa h8r8 wccr v5f2
medium System graph security Trivy conf 1.00 GHSA-v8w9-8mx6-g223: hono 4.11.6 — web/package-lock.json
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true }) ## Summary When using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property. If the parse…
VulnGhsa v8w9 8mx6 g223
medium System graph security Trivy conf 1.00 GHSA-v8w9-8mx6-g223: hono 4.12.3 — vis/package-lock.json
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true }) ## Summary When using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property. If the parse…
VulnGhsa v8w9 8mx6 g223
medium System graph cicd CI/CD security conf 1.00 9 occurrences GitHub Action is tag-pinned rather than SHA-pinned
actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA.
9 files, 9 locations
.github/workflows/ci-kimi-cli.yml:38
.github/workflows/ci-kimi-sdk.yml:27
.github/workflows/ci-kosong.yml:27
.github/workflows/ci-pykaos.yml:42
.github/workflows/release-kimi-cli.yml:17
.github/workflows/release-kimi-sdk.yml:17
.github/workflows/release-kosong.yml:17
.github/workflows/release-pykaos.yml:17
CI/CD securitySupply chainGithub actions
medium System graph cicd CI/CD security conf 1.00 GitHub Actions workflow grants broad write permissions
CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions.
.github/workflows/docs-pages.yml CI/CD securitySupply chainGithub actions
medium System graph cicd CI/CD security conf 1.00 GitHub Actions workflow grants broad write permissions
CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions.
.github/workflows/release-kimi-cli.yml CI/CD securitySupply chainGithub actions
medium System graph security security conf 1.00 Insecure pattern 'cors_wildcard' in src/kimi_cli/vis/app.py:53
Found a known-risky pattern (cors_wildcard). Review and replace if possible.
src/kimi_cli/vis/app.py:53 Cors wildcard
medium System graph security security conf 0.65 Insecure pattern 'dangerous_innerhtml' in web/src/components/ai-elements/code-block.tsx:419
Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible.
web/src/components/ai-elements/code-block.tsx:419 Dangerous innerhtml
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — examples/custom-kimi-soul/main.py:79
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
examples/custom-kimi-soul/main.py:79 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — src/kimi_cli/background/worker.py:23
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
src/kimi_cli/background/worker.py:23 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — src/kimi_cli/cli/plugin.py:145
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
src/kimi_cli/cli/plugin.py:145 runtime safetyRobustness
medium System graph quality Integrity conf 0.85 Network/subprocess call without timeout or try/except — src/kimi_cli/cli/toad.py:71
`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries.
src/kimi_cli/cli/toad.py:71 runtime safetyRobustness
medium System graph quality Placeholder conf 1.00 Placeholder or mock-heavy implementation detected
Found 55 placeholder/mock markers across 30 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data.
Mock dataIncompleteGenerated repo pattern
medium System graph security Skillspector conf 0.60 SkillSpector RA2 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md
create a new skill (or update an existing skill) that extends Kimi's capabilities with specialized knowledge, workflows, or tool integrations. --- # Skill Creator This skill provides guidance for cr Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or sta…
src/kimi_cli/skills/skill-creator/SKILL.md:3 Mcp skillRogue agentRa2
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency @isaacs/brace-expansion 5.0.0: GHSA-7h2j-956f-4vf2
OSV.dev reports `@isaacs/brace-expansion` at version `5.0.0` (resolved in `docs/bun.lock`) is affected by GHSA-7h2j-956f-4vf2. Note: `@isaacs/brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https:…
docs/bun.lock ScaOsvGhsa 7h2j 956f 4vf2
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-2fqr-mr3j-6wp8
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-2fqr-mr3j-6wp8 (aka CVE-2026-54279). aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence Aliases: CVE-2026-54279, PYSEC-2026-2112 Advisory: https://osv.dev/vulnerability/GHSA-2fqr-mr…
pyproject.toml ScaOsvGhsa 2fqr mr3j 6wp8
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-2vrm-gr82-f7m5
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-2vrm-gr82-f7m5 (aka CVE-2026-34514). AIOHTTP has CRLF injection through multipart part content type header construction Aliases: CVE-2026-34514, PYSEC-2026-2096 Advisory: https://osv.dev/vulnerability/GHSA-2…
pyproject.toml ScaOsvGhsa 2vrm gr82 f7m5
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-3wq7-rqq7-wx6j
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-3wq7-rqq7-wx6j (aka CVE-2026-34517). AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS Aliases: CVE-2026-34517, PYSEC-2026-2099 Advisory: https://osv.dev/vulnerability/GHSA-3w…
pyproject.toml ScaOsvGhsa 3wq7 rqq7 wx6j
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-4fvr-rgm6-gqmc
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-4fvr-rgm6-gqmc (aka CVE-2026-54273). aiohttp: HTTP/1 Pipelined Requests Queue Without Limit Aliases: CVE-2026-54273, PYSEC-2026-2107 Advisory: https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc Fix: upgrade `…
pyproject.toml ScaOsvGhsa 4fvr rgm6 gqmc
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-4m7w-qmgq-4wj5
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-4m7w-qmgq-4wj5 (aka CVE-2026-54275). aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections Aliases: CVE-2026-54275, PYSEC-2026-237 Advisory: https://osv.dev/vulnerability/GHSA-4m7w-…
pyproject.toml ScaOsvGhsa 4m7w qmgq 4wj5
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-63hf-3vf5-4wqf
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-63hf-3vf5-4wqf. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-63hf-3vf5-4wqf Fix: upgrade `aiohttp` past the affected range per the advisory.
pyproject.toml ScaOsvGhsa 63hf 3vf5 4wqf
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-63hw-fmq6-xxg2
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-63hw-fmq6-xxg2. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2 Fix: upgrade `aiohttp` past the affected range per the advisory.
pyproject.toml ScaOsvGhsa 63hw fmq6 xxg2
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-966j-vmvw-g2g9
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-966j-vmvw-g2g9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-966j-vmvw-g2g9 Fix: upgrade `aiohttp` past the affected range per the advisory.
pyproject.toml ScaOsvGhsa 966j vmvw g2g9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-9x8q-7h8h-wcw9
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-9x8q-7h8h-wcw9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9 Fix: upgrade `aiohttp` past the affected range per the advisory.
pyproject.toml ScaOsvGhsa 9x8q 7h8h wcw9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency aiohttp 3.13.3: GHSA-c427-h43c-vf67
OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-c427-h43c-vf67. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-c427-h43c-vf67 Fix: upgrade `aiohttp` past the affected range per the advisory.
pyproject.toml ScaOsvGhsa c427 h43c vf67

Showing first 300 of 497. Refine filters or use the findings page for deep search.

For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/6956907c-d7b0-476c-b5d1-09c54f834883/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/6956907c-d7b0-476c-b5d1-09c54f834883/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.