{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-f9bb4ba2b6754313", "name": "Possibly dead Python function: do_GET", "shortDescription": {"text": "Possibly dead Python function: do_GET"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ee5e3cf492e5ff9", "name": "Possibly dead Python function: do_POST", "shortDescription": {"text": "Possibly dead Python function: do_POST"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a381c8cb0d9f5a73", "name": "Possibly dead Python function: log_message", "shortDescription": {"text": "Possibly dead Python function: log_message"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dac84826ae4bd3e2", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-470bd65887e4d82f", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea09e0510b24709e", "name": "Possibly dead Python function: readexactly", "shortDescription": {"text": "Possibly dead Python function: readexactly"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-805d5cfa35135509", "name": "Possibly dead Python function: readuntil", "shortDescription": {"text": "Possibly dead Python function: readuntil"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f8b9ca376aa9ca5", "name": "Possibly dead Python function: can_write_eof", "shortDescription": {"text": "Possibly dead Python function: can_write_eof"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e2ff5d604bfd0df", "name": "Possibly dead Python function: is_closing", "shortDescription": {"text": "Possibly dead Python function: is_closing"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e540463d75b403a7", "name": "Possibly dead Python function: writelines", "shortDescription": {"text": "Possibly dead Python function: writelines"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72bceaebeabd014f", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-213aeda570085709", "name": "Possibly dead Python function: future_done_callback", "shortDescription": {"text": "Possibly dead Python function: future_done_callback"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b53d38f03b92ae5a", "name": "Possibly dead Python function: validate_content_part", "shortDescription": {"text": "Possibly dead Python function: validate_content_part"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24a63e61fef5db37", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0766414acb6fd83", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7cef7239894d4c78", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f1be0c851356c42", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e4f9aa57e4afb8a", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b9599e1f8f1f378", "name": "Possibly dead Python function: validate_display_block", "shortDescription": {"text": "Possibly dead Python function: validate_display_block"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86b2a29ebcf72c5c", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-329b97f3d4a58136", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a993dac622784932", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04c89ee5a9752e12", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7c69f34f5536df3", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b92f3a9eb2098f1", "name": "Possibly dead Python function: type_check", "shortDescription": {"text": "Possibly dead Python function: type_check"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af015520ee4ca814", "name": "Possibly dead Python function: open_browser_after_delay", "shortDescription": {"text": "Possibly dead Python function: open_browser_after_delay"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3dc091281667eed8", "name": "Possibly dead Python function: write_event", "shortDescription": {"text": "Possibly dead Python function: write_event"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7338e8241f10e1c", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/assistant-message.tsx:44", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/assistant-message.tsx:44"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-eab748579e3a540e", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/context-space-map.tsx:190", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/context-space-map.tsx:190"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-091dbd45af46f51e", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/context-viewer.tsx:103", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/context-viewer.tsx:103"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c32c91b767edd6ba", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/tool-call-block.tsx:69", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/tool-call-block.tsx:69"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f37364e65c242e91", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/timeline-view.tsx:574", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/timeline-view.tsx:574"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-4f977561370e054d", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/wire-event-card.tsx:393", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/wire-event-card.tsx:393"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-eadd69043eb57703", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/turn-tree.tsx:236", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/turn-tree.tsx:236"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-99d4996edbc198d2", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/usage-chart.tsx:113", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/usage-chart.tsx:113"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-79e004d78ea28a19", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/tool-stats-dashboard.tsx:204", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/tool-stats-dashboard.tsx:204"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ec5d0f0a6025c8ac", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/integrity-check.tsx:188", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/integrity-check.tsx:188"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-0e1d6d5c3d00ab88", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/statistics/statistics-view.tsx:215", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/statistics/statistics-view.tsx:215"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-369b222bbd9d06a0", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/session-picker/session-picker.tsx:125", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/session-picker/session-picker.tsx:125"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f68f692c188bf181", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/sessions-explorer/session-card.tsx:141", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/sessions-explorer/session-card.tsx:141"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-e057e0c7e9159bb6", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/sessions-explorer/project-group.tsx:43", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/sessions-explorer/project-group.tsx:43"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ddc63baec7215f21", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/agents-panel/agent-scope-bar.tsx:133", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/agents-panel/agent-scope-bar.tsx:133"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-2a5524ffe279bd8d", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/agents-panel/agents-panel.tsx:230", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/agents-panel/agents-panel.tsx:230"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-84fba07fe7bd322e", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/state-viewer/state-viewer.tsx:232", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/state-viewer/state-viewer.tsx:232"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d5f1a5178c994670", "name": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/dual-view/dual-view.tsx:319", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/dual-view/dual-view.tsx:319"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-41cdb8c1e698b895", "name": "Debug `console.log` remains in browser-facing code \u2014 web/src/App.tsx:221", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/App.tsx:221"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-d2a5fc02bcebf7d0", "name": "TODO/FIXME marker in shipping code \u2014 web/src/components/error-boundary.tsx:65", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 web/src/components/error-boundary.tsx:65"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-73f9f33c66942010", "name": "TODO/FIXME marker in shipping code \u2014 web/src/components/ui/diff/utils/parse.ts:197", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 web/src/components/ui/diff/utils/parse.ts:197"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-3a7c714fee4ef884", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/tool.tsx:412", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/tool.tsx:412"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f4fc4137d07181e0", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/subagent-steps.tsx:197", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/subagent-steps.tsx:197"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-3a12ad82d554b251", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 web/src/components/ai-elements/code-block.tsx:419", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/src/components/ai-elements/code-block.tsx:419"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-77e4c73a542d15ce", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/prompt-input.tsx:391", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/prompt-input.tsx:391"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-295df08f3b799f8a", "name": "Debug `console.log` remains in browser-facing code \u2014 web/src/hooks/useSessions.ts:529", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/hooks/useSessions.ts:529"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-cb292aecaf1b7bce", "name": "Debug `console.log` remains in browser-facing code \u2014 web/src/hooks/useSessionStream.ts:2165", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/hooks/useSessionStream.ts:2165"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-54a5c713d9529289", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/sessions/sessions.tsx:854", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/sessions/sessions.tsx:854"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-600920b58932ba9b", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/sessions/create-session-dialog.tsx:283", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/sessions/create-session-dialog.tsx:283"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-983179e85c090e3d", "name": "Debug `console.log` remains in browser-facing code \u2014 web/src/features/chat/chat-workspace-container.tsx:225", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/features/chat/chat-workspace-container.tsx:225"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-74faf4941970760c", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/slash-command-menu.tsx:69", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/slash-command-menu.tsx:69"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-0dd5c1fff9ed7d90", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/file-mention-menu.tsx:108", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/file-mention-menu.tsx:108"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-41cfc87d2671899f", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/message-search-dialog.tsx:220", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/message-search-dialog.tsx:220"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-085133d0106611cd", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/global-config-controls.tsx:229", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/global-config-controls.tsx:229"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f5fb8636f6fa37f9", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/session-info-popover.tsx:39", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/session-info-popover.tsx:39"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-573f40bfbefa62fb", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/chat-workspace-header.tsx:12", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/chat-workspace-header.tsx:120"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-0b61204e5da5a338", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/open-in-menu.tsx:158", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/open-in-menu.tsx:158"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-bc56d3ddc0a4f224", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/prompt-toolbar/toolbar-queue", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/prompt-toolbar/toolbar-queue.tsx:34"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f39254953228c334", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/prompt-toolbar/toolbar-chang", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/prompt-toolbar/toolbar-changes.tsx:62"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-09c9eaf2e2e17727", "name": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/tool/components/display-content.tsx:499", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/tool/components/display-content.tsx:499"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d1e89462f2170f01", "name": "subprocess shell true \u2014 examples/custom-kimi-soul/main.py:79", "shortDescription": {"text": "subprocess shell true \u2014 examples/custom-kimi-soul/main.py:79"}, "fullDescription": {"text": "Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.\n\nRule: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true\nSeverity: ERROR\nOWASP: A01:2017 - Injection, A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\nCategory: security\nContext: non-production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.55}}, {"id": "scanner-1306a99a97b9b04e", "name": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion\n\n@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the No\n\nPackage: @isaacs/brace-expansion\nInstalled: 5.0.0\nFixed in: 5.0.1\nSeverity: HIGH\nFix: Upgrade @isaacs/brace-expansion to 5.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a51948f377ddc0af", "name": "CVE-2026-0540: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-site scripting vulnerability\n\nDOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2, 2.5.9\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2, 2.5.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5aee5801ae78687e", "name": "CVE-2026-41238: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9cadd6545c720b00", "name": "CVE-2026-41239: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7453d68904b00d65", "name": "CVE-2026-41240: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive \n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c919f95ff610a9a6", "name": "CVE-2026-49458: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b713bf022023539", "name": "CVE-2026-49459: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0733dfdf5d9c272", "name": "CVE-2026-49978: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f83abb2dbb664e3", "name": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation\n\n## Summary\nIn `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation.\n\nThe condition:\n```\n!(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])\n```\nWhen `tagCheck(tagName)` returns `true`, the entire condition is `false` and the element is kept \u2014 `FORBID_TAGS[tagName]` is never evaluated.\n\n## Inconsistency\nThis contradicts the attribute-side pattern at line 1214 where `FORBID_ATTR` expl\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-53bfe348882a1dd0", "name": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b67770921f69d868", "name": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify USE_PROFILES prototype pollution allows event handlers\n\n## Summary\nWhen `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.prototype` property that is polluted also counts as an allowlisted attribute. An attacker who can set `Array.prototype.onclick = true` (or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such as `onclick` even when th\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14b6c882adb5c61b", "name": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify ADD_ATTR predicate skips URI validation\n\n## Summary\nDOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An attacker who supplies a predicate that accepts specific attribute/tag combinations can then sanitize input such as `<a href=\"javascript:alert(document.domain)\">` and have the `javascript:` URL survive, because URI validation is skipped for that attrib\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58f2f220d57073b5", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28e51389cfe16b00", "name": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify is vulnerable to mutation-XSS via Re-Contextualization \n\n## Description\n\nA mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a065033a41ef2fcd", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24030aa85f12ee06", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-452ba5e99e14d171", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-721d8714c39e99c7", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 docs/bun.lock", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15425563dd004da2", "name": "CVE-2026-59869: js-yaml 3.14.2 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-59869: js-yaml 3.14.2 \u2014 docs/bun.lock"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 3.14.2\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4e7fe77a4fb6028", "name": "CVE-2026-53550: js-yaml 3.14.2 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-53550: js-yaml 3.14.2 \u2014 docs/bun.lock"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 3.14.2\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dffbb586f340d133", "name": "CVE-2026-48801: linkify-it 5.0.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-48801: linkify-it 5.0.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability\n\nlinkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N\u00b2) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service tr\n\nPackage: linkify-it\nInstalled: 5.0.0\nFixed in: 5.0.1\nSeverity: HIGH\nFix: Upgrade linkify-it to 5.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fe983cb8fd7d2dbc", "name": "CVE-2026-59887: linkify-it 5.0.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-59887: linkify-it 5.0.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text\n\nlinkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.\n\nPackage: linkify-it\nInstalled: 5.0.0\nFixed in: 5.0.2\nSeverity: HIGH\nFix: Upgrade linkify-it to 5.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-825ebf8c7ecd03b3", "name": "CVE-2026-4800: lodash-es 4.17.22 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.22 \u2014 docs/bun.lock"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.22\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f56c31c8ee4c133b", "name": "CVE-2025-13465: lodash-es 4.17.22 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.22 \u2014 docs/bun.lock"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.22\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74740e3c40dbb188", "name": "CVE-2026-2950: lodash-es 4.17.22 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.22 \u2014 docs/bun.lock"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.22\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5a4422eef426d5a", "name": "CVE-2026-2327: markdown-it 14.1.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-2327: markdown-it 14.1.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify function\n\nVersions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.\n\nPackage: markdown-it\nInstalled: 14.1.0\nFixed in: 14.1.1\nSeverity: MEDIUM\nFix: Upgrade markdown-it to 14.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-274bd60c24a66513", "name": "CVE-2026-48988: markdown-it 14.1.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-48988: markdown-it 14.1.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "markdown-it is a Markdown parser. Versions 14.1.1 and below contain a  ...\n\nmarkdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typo\n\nPackage: markdown-it\nInstalled: 14.1.0\nFixed in: 14.2.0\nSeverity: MEDIUM\nFix: Upgrade markdown-it to 14.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f193e7523e729b17", "name": "CVE-2026-41148: mermaid 11.12.2 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 docs/bun.lock"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ad981d6752f53a5", "name": "CVE-2026-41149: mermaid 11.12.2 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 docs/bun.lock"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c1fe14fc078af75", "name": "CVE-2026-41150: mermaid 11.12.2 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 docs/bun.lock"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac75420f68bc932c", "name": "CVE-2026-41159: mermaid 11.12.2 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 docs/bun.lock"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-80ff5d6936d0b89c", "name": "CVE-2026-26996: minimatch 10.1.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-26996: minimatch 10.1.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b22220a231959c6", "name": "CVE-2026-27903: minimatch 10.1.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-27903: minimatch 10.1.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c48e3ac5488f5624", "name": "CVE-2026-27904: minimatch 10.1.1 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-27904: minimatch 10.1.1 \u2014 docs/bun.lock"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-80d711bc8ff86db7", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 docs/bun.lock", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 docs/bun.lock"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9f13f1b85af6381e", "name": "CVE-2026-22815: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-22815: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-77955225a12aa136", "name": "CVE-2026-34515: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34515: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via static resource handler on Windows\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-322e954f571d718f", "name": "CVE-2026-34516: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34516: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multipart headers may be allowed to use more memory than intended, potentially allowing a DoS vulnerability. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7ef5abf039de7a1c", "name": "CVE-2026-34525: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34525: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Security bypass via multiple Host headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58bee39f8a77b367", "name": "CVE-2026-34993: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34993: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load()\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-befd34523ea2756e", "name": "CVE-2026-47265: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-47265: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "python-aiohttp: AIOHTTP: Information disclosure via improper handling of cookies during cross-origin redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.0\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e70d9ab001ae667", "name": "CVE-2026-54273: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54273: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via excessive pipelined requests\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a753555ff0ec7fd", "name": "CVE-2026-54274: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54274: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via incomplete websocket frame payloads\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c86cde080336dd7d", "name": "CVE-2026-54276: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54276: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Information disclosure via DigestAuthMiddleware after cross-origin redirect\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute. Further, the attacker is only receiving the digest, so should only be able to extract the user's credentials if the cryptography is weak or there is some kind of password reuse. This\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58cf8c56e1e09a7c", "name": "CVE-2026-54277: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54277: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service via oversized HTTP request lines bypassing max_line_size check\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through the HTTP parser and use an excessive amount of memory, potentially leading to DoS. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8b12accbe4408398", "name": "CVE-2026-54278: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54278: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Denial of Service due to excessive memory consumption from compressed request body\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory, potentially leading to DoS (a zip bomb edge case). This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: MEDIUM\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba57b8dcfa683e0e", "name": "CVE-2026-34513: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34513: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service due to unbounded DNS cache\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1430a1fa6086b7a5", "name": "CVE-2026-34514: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34514: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header Injection via content_type parameter manipulation\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c105e19d51abfca3", "name": "CVE-2026-34517: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34517: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Denial of Service via large multipart form fields\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read the entire field into memory before checking client_max_size. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-511a1033762f22b2", "name": "CVE-2026-34518: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34518: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Information disclosure via retained Cookie and Proxy-Authorization headers during redirects\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9239e6c0e690f7f", "name": "CVE-2026-34519: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34519: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: aiohttp: Header injection vulnerability via reason parameter\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the reason parameter when creating a Response may be able to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba7a27f8cbe9af52", "name": "CVE-2026-34520: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34520: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Header injection vulnerability due to improper character handling\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.13.4\nSeverity: LOW\nFix: Upgrade aiohttp to 3.13.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f66d4480de5e005", "name": "CVE-2026-50269: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-50269: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: CRLF injection in multipart headers\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerabi\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.0\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fa9026578dffef7", "name": "CVE-2026-54275: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54275: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: TLS SNI check bypass via connection reuse\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e980a4024edcfef3", "name": "CVE-2026-54279: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54279: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eac59cdc990c4ea5", "name": "CVE-2026-54280: aiohttp 3.13.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54280: aiohttp 3.13.3 \u2014 uv.lock"}, "fullDescription": {"text": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...\n\nAIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.\n\nPackage: aiohttp\nInstalled: 3.13.3\nFixed in: 3.14.1\nSeverity: LOW\nFix: Upgrade aiohttp to 3.14.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2a13a13b8ae7dcb", "name": "CVE-2026-27962: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-27962: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed\n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.6.9\nSeverity: CRITICAL\nFix: Upgrade authlib to 1.6.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-0620285b783fef91", "name": "CVE-2026-28490: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-28490: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "authlib: Authlib: Information disclosure due to cryptographic padding oracle in JWE RSA1_5\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning the implementation of the JSON Web Encryption (JWE) RSA1_5 key management algorithm. Authlib registers RSA1_5 in its default algorithm registry without requiring explicit opt-in, and actively destroys the constant-time Bleichenbacher mitigation that the underlying cryptography library implements cor\n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.6.9\nSeverity: HIGH\nFix: Upgrade authlib to 1.6.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1a033cf8f942048d", "name": "CVE-2026-28498: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-28498: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "authlib: Authlib: Authentication bypass via forged OpenID Connect ID Tokens\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorit\n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.6.9\nSeverity: HIGH\nFix: Upgrade authlib to 1.6.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-db2f064a3e3716c5", "name": "CVE-2026-28802: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-28802: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "authlib: Authlib: Signature verification bypass via malicious JWT allows unauthorized access\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.\n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.6.7\nSeverity: HIGH\nFix: Upgrade authlib to 1.6.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e28b78dfff1db76f", "name": "CVE-2025-68158: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-68158: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "Authlib: Authlib: Cross-Site Request Forgery due to improper session management in state storage\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that has a valid state (easily obtainable via an attacker-initiated authentication flow). When a cache is supplied to the OAuth client registry, FrameworkIntegration.set_state_data writes the entire state blob under _state_{app}_{state}, and get_state_data ignores the c\n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.6.6\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.6.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9666b65fae647c2", "name": "CVE-2026-41425: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-41425: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "authlib: Authlib: Cross-Site Request Forgery (CSRF) vulnerability in OAuth cache feature\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth.  This vulnerability is fixed in 1.6.11.\n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.6.11\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.6.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-102cb04253319eba", "name": "CVE-2026-41479: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-41479: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "Authlib is a Python library which builds OAuth and OpenID Connect serv ...\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. \n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.6.10, 1.7.1\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.6.10, 1.7.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f2c049fb972fa3bc", "name": "CVE-2026-44681: authlib 1.6.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44681: authlib 1.6.5 \u2014 uv.lock"}, "fullDescription": {"text": "Authlib is a Python library which builds OAuth and OpenID Connect serv ...\n\nAuthlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.\n\nPackage: authlib\nInstalled: 1.6.5\nFixed in: 1.7.1, 1.6.12\nSeverity: MEDIUM\nFix: Upgrade authlib to 1.7.1, 1.6.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e1d70859a649eeb", "name": "CVE-2026-26007: cryptography 46.0.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-26007: cryptography 46.0.2 \u2014 uv.lock"}, "fullDescription": {"text": "cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead \n\nPackage: cryptography\nInstalled: 46.0.2\nFixed in: 46.0.5\nSeverity: HIGH\nFix: Upgrade cryptography to 46.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d2a69e8acd688649", "name": "GHSA-537c-gmf6-5ccf: cryptography 46.0.2 \u2014 uv.lock", "shortDescription": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.2 \u2014 uv.lock"}, "fullDescription": {"text": "Vulnerable OpenSSL included in cryptography wheels\n\npyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on \n\nPackage: cryptography\nInstalled: 46.0.2\nFixed in: 48.0.1\nSeverity: HIGH\nFix: Upgrade cryptography to 48.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2d8a93ade5b30c3f", "name": "CVE-2026-39892: cryptography 46.0.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-39892: cryptography 46.0.2 \u2014 uv.lock"}, "fullDescription": {"text": "cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.\n\nPackage: cryptography\nInstalled: 46.0.2\nFixed in: 46.0.7\nSeverity: MEDIUM\nFix: Upgrade cryptography to 46.0.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ecc0cb594b7e601d", "name": "CVE-2026-34073: cryptography 46.0.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-34073: cryptography 46.0.2 \u2014 uv.lock"}, "fullDescription": {"text": "python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation\n\ncryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the \"peer name\" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for b\n\nPackage: cryptography\nInstalled: 46.0.2\nFixed in: 46.0.6\nSeverity: LOW\nFix: Upgrade cryptography to 46.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54431d598451332d", "name": "CVE-2026-42215: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42215: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at it\n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c32c52607d4675e9", "name": "CVE-2026-42284: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42284: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(\" \".join(multi_options)). A string like \"--branch main --config core.hooksPath=/x\" passes validation (starts with --branch), but after split becomes [\"--branch\", \"main\", \"--config\", \"core.hooksPath=/x\"]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.\n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.47\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.47"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5110ca4600327972", "name": "CVE-2026-44243: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44243: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython: GitPython: Arbitrary file write via crafted reference paths\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository\u2019s .git directory via insufficient validation of reference paths in reference creation, rename, and delete operations. This issue has been patched in version 3.1.48.\n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.48\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.48"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6387eae900792e19", "name": "CVE-2026-44244: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44244: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython is a python library used to interact with Git repositories.  ...\n\nGitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \\n becomes \\n\\t), but Git still accepts an indented [core] stanza as a section header \u2014 so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout)\n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.49\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.49"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb47971fe5df0456", "name": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist\n\n## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)\n\n**Component:** gitpython-developers/GitPython (PyPI: GitPython)\n**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)\n**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) \u2192 CWE-78 (OS Command Injection)\n**Severity:** inherits the parent CVE-2026-42215 surface; estimated Hi\n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-10584ccd6a28c305", "name": "GHSA-956x-8gvw-wg5v: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "GHSA-956x-8gvw-wg5v: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`\n\n## Summary\n\nGitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of \"unsafe\" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, \u2026) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.\n\nThat enforcement is only wired into the **network** commands \u2014 `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other p\n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.51\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.51"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-650f5f0e55ac3ca2", "name": "GHSA-mv93-w799-cj2w: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath\n\nSummary\n\nThe patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \\n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.\n\nDetails\n\nFile: git/config.py \u2014 \n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.50\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.50"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b7c4a24e724685d3", "name": "GHSA-rwj8-pgh3-r573: gitpython 3.1.45 \u2014 uv.lock", "shortDescription": {"text": "GHSA-rwj8-pgh3-r573: gitpython 3.1.45 \u2014 uv.lock"}, "fullDescription": {"text": "GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL\n\n### Summary\n`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument \u2014 the documented use case for `clone_from()` in \"import repository from URL\" features of CI servers, git-hosting mirrors, and dependency scanners \u2014 can embed `$NAME` / `${NAME}` tokens that are expanded server-side to the values of the hosting process\n\nPackage: gitpython\nInstalled: 3.1.45\nFixed in: 3.1.52\nSeverity: HIGH\nFix: Upgrade gitpython to 3.1.52"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-403e5905f1ebc50e", "name": "CVE-2026-45409: idna 3.10 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-45409: idna 3.10 \u2014 uv.lock"}, "fullDescription": {"text": "python-idna: idna: Denial of Service via specially crafted long inputs\n\nInternationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi\n\nPackage: idna\nInstalled: 3.10\nFixed in: 3.15\nSeverity: MEDIUM\nFix: Upgrade idna to 3.15"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6cc76acfbf412673", "name": "CVE-2026-41066: lxml 6.0.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-41066: lxml 6.0.2 \u2014 uv.lock"}, "fullDescription": {"text": "lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read\n\nlxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.\n\nPackage: lxml\nInstalled: 6.0.2\nFixed in: 6.1.0\nSeverity: HIGH\nFix: Upgrade lxml to 6.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2b96861f5b27d344", "name": "CVE-2026-49825: lxml-html-clean 0.4.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-49825: lxml-html-clean 0.4.3 \u2014 uv.lock"}, "fullDescription": {"text": "`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes\n\n# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)\n\n**Reporter:** Guillem Lefait <guillem@datamq.com> \u00b7 **Date:** 2026-05-10\n**Affected:** `lxml` \u2264 6.1.0 and `lxml_html_clean` \u2264 0.4.4 (latest stable)\n**Confirmed against:** lxml 6.1.0 + lxml_html_clean 0.4.4 on Python 3.13.5, 3.14.4, and 3.15.0a8 (libxml2 2.14.6 / 2.9.14 \u2014 bug is in pure-Python sanitizer logic, independent of the libxml2 backend)\n**Root-cause class:** same as CVE-2021-28957\n\nPackage: lxml-html-clean\nInstalled: 0.4.3\nFixed in: 0.4.5\nSeverity: HIGH\nFix: Upgrade lxml-html-clean to 0.4.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cd83ec549d525a8d", "name": "CVE-2026-28348: lxml-html-clean 0.4.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-28348: lxml-html-clean 0.4.3 \u2014 uv.lock"}, "fullDescription": {"text": "lxml_html_clean is a project for HTML cleaning functionalities copied  ...\n\nlxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing external CSS loading or XSS in older browsers. This issue has been patched in version 0.4.4.\n\nPackage: lxml-html-clean\nInstalled: 0.4.3\nFixed in: 0.4.4\nSeverity: MEDIUM\nFix: Upgrade lxml-html-clean to 0.4.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d7f06bb3210ba20", "name": "CVE-2026-28350: lxml-html-clean 0.4.3 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-28350: lxml-html-clean 0.4.3 \u2014 uv.lock"}, "fullDescription": {"text": "lxml_html_clean is a project for HTML cleaning functionalities copied  ...\n\nlxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject it and hijack relative links on the page. This issue has been patched in version 0.4.4.\n\nPackage: lxml-html-clean\nInstalled: 0.4.3\nFixed in: 0.4.4\nSeverity: MEDIUM\nFix: Upgrade lxml-html-clean to 0.4.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-393a17c0d4dd691c", "name": "CVE-2026-52869: mcp 1.27.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-52869: mcp 1.27.1 \u2014 uv.lock"}, "fullDescription": {"text": "MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client\n\nPackage: mcp\nInstalled: 1.27.1\nFixed in: 1.27.2\nSeverity: HIGH\nFix: Upgrade mcp to 1.27.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-df6a7df895b9a551", "name": "CVE-2026-52870: mcp 1.27.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-52870: mcp 1.27.1 \u2014 uv.lock"}, "fullDescription": {"text": "MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.\n\nPackage: mcp\nInstalled: 1.27.1\nFixed in: 1.27.2\nSeverity: HIGH\nFix: Upgrade mcp to 1.27.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62dbff4a083928b1", "name": "CVE-2026-59950: mcp 1.27.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59950: mcp 1.27.1 \u2014 uv.lock"}, "fullDescription": {"text": "MCP Python SDK: WebSocket server transport does not support Host/Origin validation\n\nThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.\n\nPackage: mcp\nInstalled: 1.27.1\nFixed in: 1.28.1\nSeverity: HIGH\nFix: Upgrade mcp to 1.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9737b39b2a7551a7", "name": "CVE-2026-54058: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54058: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image\n\nPillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92f5952034493030", "name": "CVE-2026-54059: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54059: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted PCF font data\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ff9f66ba430e736", "name": "CVE-2026-54060: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54060: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c85e0cc00b91ed7", "name": "CVE-2026-55379: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55379: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted BDF font file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b2568d3cbcb767f", "name": "CVE-2026-55380: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55380: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Denial of Service via crafted GD 2.x image file\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8f83941fee577645", "name": "CVE-2026-59197: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59197: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Native heap out-of-bounds write\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e268c1133819fbf", "name": "CVE-2026-59199: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59199: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via out-of-bounds write in image processing\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8297d3abcb7190eb", "name": "CVE-2026-59200: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59200: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of service via crafted PDF stream\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3f4c42d809f3d4d4", "name": "CVE-2026-59204: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59204: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted JPEG2000 image\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4254579d8b441828", "name": "CVE-2026-59205: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59205: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API\n\nPillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: HIGH\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eee5d94fc3e70870", "name": "CVE-2026-55798: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-55798: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths\n\nPillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-027941125df659f6", "name": "CVE-2026-59198: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59198: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read\n\nPillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bff8feb430b5016c", "name": "CVE-2026-59203: pillow 12.2.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59203: pillow 12.2.0 \u2014 uv.lock"}, "fullDescription": {"text": "Pillow: Pillow: Denial of Service via crafted EPS file\n\nPillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.\n\nPackage: pillow\nInstalled: 12.2.0\nFixed in: 12.3.0\nSeverity: MEDIUM\nFix: Upgrade pillow to 12.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a66a46b30aafdf4e", "name": "CVE-2026-23490: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.2\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eaf386c6a405e5a9", "name": "CVE-2026-30922: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consu\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.3\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b16f1d147b41ab9", "name": "CVE-2026-59885: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values.\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f56dfa97d69c0517", "name": "CVE-2026-59886: pyasn1 0.6.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 uv.lock"}, "fullDescription": {"text": "pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values\n\npyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print\n\nPackage: pyasn1\nInstalled: 0.6.1\nFixed in: 0.6.4\nSeverity: HIGH\nFix: Upgrade pyasn1 to 0.6.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0da8a15114591082", "name": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock"}, "fullDescription": {"text": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer\n\nA security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.\n\nPackage: pygments\nInstalled: 2.19.2\nFixed in: 2.20.0\nSeverity: LOW\nFix: Upgrade pygments to 2.20.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6514fbdcfaa9204b", "name": "CVE-2026-48526: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48526: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: HIGH\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-10d45d6df7a6f197", "name": "CVE-2026-48522: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48522: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5728cdec0dc11919", "name": "CVE-2026-48523: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48523: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access\n\nPyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ba6012c73817cff", "name": "CVE-2026-48525: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48525: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens\n\nPyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option (\"b64\": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled \u201cwork amplifier\u201d: a\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: MEDIUM\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-898e5e1bfb2fa7db", "name": "CVE-2026-48524: pyjwt 2.12.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48524: pyjwt 2.12.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs\n\nPyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be\n\nPackage: pyjwt\nInstalled: 2.12.1\nFixed in: 2.13.0\nSeverity: LOW\nFix: Upgrade pyjwt to 2.13.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b549bf95b003cf48", "name": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 uv.lock"}, "fullDescription": {"text": "python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following\n\npython-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered. Users should upgrade to v.1.2.2 or, as a workaround, apply the patch manually.\n\nPackage: python-dotenv\nInstalled: 1.2.1\nFixed in: 1.2.2\nSeverity: MEDIUM\nFix: Upgrade python-dotenv to 1.2.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a46c3e2c18f75245", "name": "CVE-2026-24486: python-multipart 0.0.20 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability\n\nPython-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users should upgrade to version 0.0.22 to receive a patch or, as a workaround, avoid using `UPLOAD_KEEP_FILENAME=True` in project configurations.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.22\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.22"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1caad244fd2a309", "name": "CVE-2026-42561: python-multipart 0.0.20 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: python-multipart: Denial of Service via excessive multipart part headers\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.27\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b217658f9afadfa5", "name": "CVE-2026-53539: python-multipart 0.0.20 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: HIGH\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0651fe3acb9d9b53", "name": "CVE-2026-40347: python-multipart 0.0.20 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests\n\nPython-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.26\nSeverity: MEDIUM\nFix: Upgrade python-multipart to 0.0.26"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6989ea5c3149368a", "name": "CVE-2026-53537: python-multipart 0.0.20 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 uv.lock"}, "fullDescription": {"text": "multipart: Python-Multipart: Information disclosure via header parsing discrepancy\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 \u00a74.2 explicitly forbid\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-89f71c3ba44f9ad6", "name": "CVE-2026-53538: python-multipart 0.0.20 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form \n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.30\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.30"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce31dd15888fefca", "name": "CVE-2026-53540: python-multipart 0.0.20 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 uv.lock"}, "fullDescription": {"text": "python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory\n\nPython-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.\n\nPackage: python-multipart\nInstalled: 0.0.20\nFixed in: 0.0.31\nSeverity: LOW\nFix: Upgrade python-multipart to 0.0.31"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0bc6a832539e0bf", "name": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock"}, "fullDescription": {"text": "requests: Requests: Security bypass due to predictable temporary file creation\n\nRequests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulner\n\nPackage: requests\nInstalled: 2.32.5\nFixed in: 2.33.0\nSeverity: MEDIUM\nFix: Upgrade requests to 2.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a0a3fca4e88f57a5", "name": "CVE-2025-62727: starlette 0.48.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-62727: starlette 0.48.0 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette DoS via Range header merging\n\nStarlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial\u2011of\u2011service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.\n\nPackage: starlette\nInstalled: 0.48.0\nFixed in: 0.49.1\nSeverity: HIGH\nFix: Upgrade starlette to 0.49.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-469ff7519151f326", "name": "CVE-2026-48818: starlette 0.48.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48818: starlette 0.48.0 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas\n\nPackage: starlette\nInstalled: 0.48.0\nFixed in: 1.1.0\nSeverity: HIGH\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a275dfce4ece1a3e", "name": "CVE-2026-54283: starlette 0.48.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54283: starlette 0.48.0 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS\n\nStarlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.\n\nPackage: starlette\nInstalled: 0.48.0\nFixed in: 1.3.1\nSeverity: HIGH\nFix: Upgrade starlette to 1.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-81f16d9c11134448", "name": "CVE-2026-48710: starlette 0.48.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48710: starlette 0.48.0 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) \n\nPackage: starlette\nInstalled: 0.48.0\nFixed in: 1.0.1\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9290c3728bbbc080", "name": "CVE-2026-48817: starlette 0.48.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-48817: starlette 0.48.0 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods\n\nStarlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo\n\nPackage: starlette\nInstalled: 0.48.0\nFixed in: 1.1.0\nSeverity: MEDIUM\nFix: Upgrade starlette to 1.1.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9815506a5fd59a31", "name": "CVE-2026-54282: starlette 0.48.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-54282: starlette 0.48.0 \u2014 uv.lock"}, "fullDescription": {"text": "starlette: Starlette: Information disclosure due to improper HTTP request path validation\n\nStarlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header \n\nPackage: starlette\nInstalled: 0.48.0\nFixed in: 1.3.0\nSeverity: LOW\nFix: Upgrade starlette to 1.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ce2e929f54e2a70", "name": "CVE-2025-66418: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-66418: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b32d2265f744fa8b", "name": "CVE-2025-66471: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2025-66471: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 Streaming API improperly handles highly compressed data\n\nurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, b\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.6.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e01e826fca9ae59b", "name": "CVE-2026-21441: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-21441: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)\n\nurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in ve\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.6.3\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.6.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-79d12b66c3169372", "name": "CVE-2026-44431: urllib3 2.5.0 \u2014 uv.lock", "shortDescription": {"text": "CVE-2026-44431: urllib3 2.5.0 \u2014 uv.lock"}, "fullDescription": {"text": "urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers\n\nurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.\n\nPackage: urllib3\nInstalled: 2.5.0\nFixed in: 2.7.0\nSeverity: HIGH\nFix: Upgrade urllib3 to 2.7.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c38d176017a7d97d", "name": "CVE-2026-49356: @babel/core 7.29.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.29.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.29.0\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-107a662d2fb41a27", "name": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware\n\n@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middl\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.10\nSeverity: HIGH\nFix: Upgrade @hono/node-server to 1.19.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7fcc3811554042e3", "name": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic\n\n@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in 1.19.13.\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.13\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 1.19.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8c9631d6ae9b64db", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 vis/package-lock.json", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f89c2515ddb3c0e", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4cc352c5ed57ff9", "name": "CVE-2026-13149: brace-expansion 5.0.4 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 5.0.4 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 5.0.4\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-79926b04bb9dc553", "name": "CVE-2026-33750: brace-expansion 5.0.4 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-33750: brace-expansion 5.0.4 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.\n\nPackage: brace-expansion\nInstalled: 5.0.4\nFixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.5, 3.0.2, 2.0.3, 1.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57a0947952533fa5", "name": "CVE-2026-45149: brace-expansion 5.0.4 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-45149: brace-expansion 5.0.4 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vul\n\nPackage: brace-expansion\nInstalled: 5.0.4\nFixed in: 5.0.6\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6948ec052945adbd", "name": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "esbuild allows arbitrary file read when running the development server on Windows\n\n### Summary\n\nThe development server contains a path traversal vulnerability on Windows when serving files from `servedir`.\n\nDue to the use of `path.Clean()` (which only normalizes forward-slash `/` separators) instead of a Windows-aware path normalization function, it is possible to craft requests using backslashes (`\\`) that bypass the intended directory containment logic. An attacker can escape the configured `servedir` root and access arbitrary files on the filesystem.\nThis issue affects Wind\n\nPackage: esbuild\nInstalled: 0.27.3\nFixed in: 0.28.1\nSeverity: LOW\nFix: Upgrade esbuild to 0.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3dd5566d8502f6b8", "name": "CVE-2026-30827: express-rate-limit 8.2.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-30827: express-rate-limit 8.2.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking\n\nexpress-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.3.0, the default keyGenerator in express-rate-limit applies IPv6 subnet masking (/56 by default) to all addresses that net.isIPv6() returns true for. This includes IPv4-mapped IPv6 addresses (::ffff:x.x.x.x), which Node.js returns as request.ip on dual-stack servers. Because the first 80 bits of all IPv4-mapped addresses are zero, a /56 (or any /32 \n\nPackage: express-rate-limit\nInstalled: 8.2.1\nFixed in: 8.2.2, 8.1.1, 8.0.2\nSeverity: HIGH\nFix: Upgrade express-rate-limit to 8.2.2, 8.1.1, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4268959e22171d57", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-30c88963157ac2d2", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-06d4fa2851ae629e", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0108b600cdc0fd59", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-88b5ec286643f49a", "name": "CVE-2026-29045: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-29045: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to arbitrary file access via serveStatic vulnerability \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed without authorization. The router used decodeURI, while serveStatic used decodeURIComponent. This mismatch allowed paths containing encoded slashes (%2F) to bypass middleware protections while still resolving\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.4\nSeverity: HIGH\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4487a6e72f1d1bf3", "name": "CVE-2026-54290: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-54290: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1d3a2339543d00c", "name": "CVE-2026-29085: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-29085: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\\r) or newline (\\n) characters. Because the SSE protocol uses line breaks as field delimiters, this could allow injection of additional SSE fields within the same event frame if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fdf242442712363d", "name": "CVE-2026-29086: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-29086: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\\r), or newline characters (\\n) in the domain and path options when constructing the Set-Cookie header. Because cookie attributes are delimited by semicolons, this could allow injection of additional cookie attributes if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d13e7c997311b14a", "name": "CVE-2026-39407: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39407: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: Middleware bypass via repeated slashes in serveStatic\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in \n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c63d710368013501", "name": "CVE-2026-39408: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39408: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: Path traversal in toSSG() allows writing files outside the output directory\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially crafted values can cause generated file paths to escape the intended output directory. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8adb77bfe044dffc", "name": "CVE-2026-39409: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39409: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9e3a43ab1c8dd1c", "name": "CVE-2026-39410: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39410: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17b86a53ea9b7ea1", "name": "CVE-2026-44455: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-44455: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0067293f3f6ea463", "name": "CVE-2026-44456: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-44456: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b1e249ab5ae2a08", "name": "CVE-2026-44457: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-44457: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2acf26e5069e9142", "name": "CVE-2026-44458: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-44458: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b53e3fc75c770005", "name": "CVE-2026-47673: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-47673: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75e408356666940a", "name": "CVE-2026-47674: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-47674: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3100ac49c2c74748", "name": "CVE-2026-47675: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-47675: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b36074f92b29ef1f", "name": "CVE-2026-47676: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-47676: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a504bfd6b249a689", "name": "CVE-2026-54286: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-54286: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-164d47f20399a832", "name": "CVE-2026-54287: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-54287: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e2af7995f9414b8a", "name": "CVE-2026-54288: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-54288: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-93c094f8e0739c71", "name": "CVE-2026-54289: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-54289: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f24bcc38a1284694", "name": "CVE-2026-56761: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-56761: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nhono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.14\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c346faa63ee483a", "name": "CVE-2026-59895: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-59895: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-753728d22037fe15", "name": "CVE-2026-59896: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-59896: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "hono/jsx does not isolate context per request, leading to cross-request data disclosure\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4580e474aa4c4e08", "name": "CVE-2026-59897: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-59897: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2bff54afcabe5429", "name": "GHSA-26pp-8wgv-hjvm: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono missing validation of cookie name on write path in setCookie()\n\n## Summary\n\nCookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.\n\nWhile certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.\n\nThis results in inconsistent handling of cookie names between parsing (read path) and serialization (write path).\n\n## Details\n\nWhen applications use `setCookie()`, `serialize()`, or `serializeSigned()` with a user-c\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-075abf73c8344301", "name": "GHSA-v8w9-8mx6-g223: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "GHSA-v8w9-8mx6-g223: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })\n\n## Summary\n\nWhen using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property.\n\nIf the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object.\n\n## Details\n\nThe `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names.\n\nIn previous versions, the `__proto__`\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7126e4092fbad58d", "name": "CVE-2026-44459: hono 4.12.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-44459: hono 4.12.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.12.3\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23a525950146b86d", "name": "CVE-2026-42338: ip-address 10.0.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-42338: ip-address 10.0.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods,\n\nPackage: ip-address\nInstalled: 10.0.1\nFixed in: 10.1.1\nSeverity: MEDIUM\nFix: Upgrade ip-address to 10.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df8a2c547785f1b9", "name": "CVE-2026-59869: js-yaml 4.1.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-44562751a63d30bc", "name": "CVE-2026-53550: js-yaml 4.1.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca42b4dbcd015428", "name": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions\n\nImpact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c577108a7764d391", "name": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards\n\nImpact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: MEDIUM\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efebd015f93ca5d6", "name": "CVE-2026-33671: picomatch 2.3.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b281200026504e4f", "name": "CVE-2026-33672: picomatch 2.3.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5bbb91f82589dcc3", "name": "CVE-2026-33671: picomatch 4.0.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e2a37be63feebaaf", "name": "CVE-2026-33672: picomatch 4.0.3 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fa6e52f30ee550c2", "name": "CVE-2026-41305: postcss 8.5.6 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c5b2d1395b25db8", "name": "CVE-2026-8723: qs 6.15.0 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.15.0 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.15.0\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-925f0a6961ff4942", "name": "CVE-2026-39363: vite 7.3.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39363: vite 7.3.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "Vite: Vite: Information disclosure via WebSocket connection bypasses access control\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server\u2019s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default \"...\"). The access control enforced in the HTTP request path (such as server.fs.allo\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dae9ee1dc677bbad", "name": "CVE-2026-39364: vite 7.3.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39364: vite 7.3.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "vite: Vite: Information disclosure via query parameter manipulation on the development server\n\nVite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5f7f83a25ebd581", "name": "CVE-2026-53571: vite 7.3.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-53571: vite 7.3.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "vite: `server.fs.deny` bypass on Windows alternate paths\n\nVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite\u2019s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw a\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: HIGH\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27780c5a9a52d03c", "name": "CVE-2026-39365: vite 7.3.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-39365: vite 7.3.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "vite: Vite: Information disclosure via path traversal in dev server's .map request handling\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server\u2019s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72745f95799ce14e", "name": "CVE-2026-53632: vite 7.3.1 \u2014 vis/package-lock.json", "shortDescription": {"text": "CVE-2026-53632: vite 7.3.1 \u2014 vis/package-lock.json"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7210ec2587942dd7", "name": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 web/package-lock.json"}, "fullDescription": {"text": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue\n\nA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.\n\nPackage: @ai-sdk/provider-utils\nInstalled: 3.0.20\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b196e4a3e2a3c1d6", "name": "CVE-2026-49356: @babel/core 7.28.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.28.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.28.6\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0bab4e876461f561", "name": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 web/package-lock.json"}, "fullDescription": {"text": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware\n\n@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middl\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.10\nSeverity: HIGH\nFix: Upgrade @hono/node-server to 1.19.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4b547ec73919cb7a", "name": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 web/package-lock.json"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic\n\n@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in 1.19.13.\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 1.19.13\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 1.19.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7d075d79a112d77f", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.9\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10c4ef93b1c765e6", "name": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion\n\n@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the No\n\nPackage: @isaacs/brace-expansion\nInstalled: 5.0.0\nFixed in: 5.0.1\nSeverity: HIGH\nFix: Upgrade @isaacs/brace-expansion to 5.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cf0e2dd25b161941", "name": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak\n\nMCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multiple client connections, most commonly in stateless StreamableHTTPServerTransport deployments. This issue has been patched in version 1.26.0.\n\nPackage: @modelcontextprotocol/sdk\nInstalled: 1.25.3\nFixed in: 1.26.0\nSeverity: HIGH\nFix: Upgrade @modelcontextprotocol/sdk to 1.26.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fc895e164bc4ceb2", "name": "CVE-2025-69873: ajv 8.17.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "ajv: ReDoS via $data reference\n\najv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds\n\nPackage: ajv\nInstalled: 8.17.1\nFixed in: 8.18.0, 6.14.0\nSeverity: MEDIUM\nFix: Upgrade ajv to 8.18.0, 6.14.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1acbe20ab940f1e2", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 web/package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d3312872ada341d", "name": "CVE-2026-0540: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-site scripting vulnerability\n\nDOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2, 2.5.9\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2, 2.5.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ecdb4f2c486b6725", "name": "CVE-2026-41238: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b688eed9bef55eb0", "name": "CVE-2026-41239: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6a812220cd6b4070", "name": "CVE-2026-41240: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely. This allows forbidden elements to survive \n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a914709f2b88b050", "name": "CVE-2026-49458: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6fa151b70a7b5506", "name": "CVE-2026-49459: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4bffe58345140531", "name": "CVE-2026-49978: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-879b9dc0e3dc252b", "name": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation\n\n## Summary\nIn `src/purify.ts:1117-1123`, `ADD_TAGS` as a function (via `EXTRA_ELEMENT_HANDLING.tagCheck`) bypasses `FORBID_TAGS` due to short-circuit evaluation.\n\nThe condition:\n```\n!(tagCheck(tagName)) && (!ALLOWED_TAGS[tagName] || FORBID_TAGS[tagName])\n```\nWhen `tagCheck(tagName)` returns `true`, the entire condition is `false` and the element is kept \u2014 `FORBID_TAGS[tagName]` is never evaluated.\n\n## Inconsistency\nThis contradicts the attribute-side pattern at line 1214 where `FORBID_ATTR` expl\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.0\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6c8c9b5836c07f15", "name": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e58eb9f0dd11166f", "name": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify USE_PROFILES prototype pollution allows event handlers\n\n## Summary\nWhen `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.prototype` property that is polluted also counts as an allowlisted attribute. An attacker who can set `Array.prototype.onclick = true` (or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such as `onclick` even when th\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b080e3d9d369b2cb", "name": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify ADD_ATTR predicate skips URI validation\n\n## Summary\nDOMPurify allows `ADD_ATTR` to be provided as a predicate function via `EXTRA_ELEMENT_HANDLING.attributeCheck`. When the predicate returns `true`, `_isValidAttribute` short-circuits the attribute check before URI-safe validation runs. An attacker who supplies a predicate that accepts specific attribute/tag combinations can then sanitize input such as `<a href=\"javascript:alert(document.domain)\">` and have the `javascript:` URL survive, because URI validation is skipped for that attrib\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d01c531a02213674", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c87e8fd756d5baee", "name": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify is vulnerable to mutation-XSS via Re-Contextualization \n\n## Description\n\nA mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.3.2\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98863c560715b0fe", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ed598a8b4edc673", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d93daf6ab91f1ec2", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88cdd13c9bbe5294", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.3.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fee4a428e0674a05", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5bf90cb7f7922abe", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9155feee87bb6d21", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e4ca98c74754b4a", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-373ac01d284957d9", "name": "CVE-2026-29045: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-29045: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to arbitrary file access via serveStatic vulnerability \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed without authorization. The router used decodeURI, while serveStatic used decodeURIComponent. This mismatch allowed paths containing encoded slashes (%2F) to bypass middleware protections while still resolving\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.4\nSeverity: HIGH\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e61824af2a9be18", "name": "CVE-2026-54290: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-54290: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.25\nSeverity: HIGH\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e93d56161fcc472", "name": "CVE-2026-24398: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-24398: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls. Version 4.11.7 contains a patch for the issue.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7c9dc11e39abecf", "name": "CVE-2026-24472: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-24472: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono cache middleware ignores \"Cache-Control: private\" leading to Web Cache Deception\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard cache control headers such as `Cache-Control: private` or `Cache-Control: no-store`, which may result in private or authenticated responses being cached and subsequently exposed to unauthorized users. Version 4.11.7 has \n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ec3d1ef43e221d6", "name": "CVE-2026-24473: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-24473: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the Workers environment. Improper validation of user-controlled paths can result in unintended access to internal asset keys. Version 4.11.7 contains a patch for the issue.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e13829dbd09a6af1", "name": "CVE-2026-24771: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-24771: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to XSS through ErrorBoundary component \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-Site Scripting (XSS) vulnerability exists in the `ErrorBoundary` component of the hono/jsx library. Under certain usage patterns, untrusted user-controlled strings may be rendered as raw HTML, allowing arbitrary script execution in the victim's browser. Version 4.11.7 patches the issue.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.11.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.11.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4cf66fb5bd58ee40", "name": "CVE-2026-29085: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-29085: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\\r) or newline (\\n) characters. Because the SSE protocol uses line breaks as field delimiters, this could allow injection of additional SSE fields within the same event frame if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dfea9aa23f1d514c", "name": "CVE-2026-29086: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-29086: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\\r), or newline characters (\\n) in the domain and path options when constructing the Set-Cookie header. Because cookie attributes are delimited by semicolons, this could allow injection of additional cookie attributes if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.4\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f39ec9259517d7e5", "name": "CVE-2026-39407: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39407: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: Middleware bypass via repeated slashes in serveStatic\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not match paths containing repeated slashes, while serveStatic resolves them as normalized paths. This can lead to a middleware bypass. This vulnerability is fixed in \n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-edcecc7732b13eac", "name": "CVE-2026-39408: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39408: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: Path traversal in toSSG() allows writing files outside the output directory\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially crafted values can cause generated file paths to escape the intended output directory. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17e47b91f999bd4c", "name": "CVE-2026-39409: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39409: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a3b0014746510b7c", "name": "CVE-2026-39410: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39410: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-761ccc35f3630f24", "name": "CVE-2026-44455: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44455: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f97514d90418e674", "name": "CVE-2026-44456: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44456: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.16\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.16"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0a24e9a022159d7", "name": "CVE-2026-44457: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44457: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ad005499172c672", "name": "CVE-2026-44458: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44458: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS declarations into the rendered style attribute. The impact is limited to CSS and does not allow JavaScript execution or HTML attribute breakout. This vulnerability is fixed in 4.12.18.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.18\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d278c944f822375", "name": "CVE-2026-47673: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-47673: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value \u2014 regardless of the scheme name in the first position \u2014 proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c1c584330425995", "name": "CVE-2026-47674: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-47674: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 \n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule \u2014 such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses \u2014 do not match the normalized rule entry, causing the \n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4fcf8db694852abd", "name": "CVE-2026-47675: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-47675: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \\r, \\n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed \n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2bdb2520dbe9b176", "name": "CVE-2026-47676: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-47676: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.21\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.21"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f59c19c46247e129", "name": "CVE-2026-54286: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-54286: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \\, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b145303565ab831", "name": "CVE-2026-54287: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-54287: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-78eb82845dd2276e", "name": "CVE-2026-54288: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-54288: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and Lambda@Edge) the body is delivered fully buffered and the adapter builds the request with the client-declared Content-Length, which need not match the actual payload. A client can declare a tiny Content-Length while sending a\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e24cfc01a1b9c2a", "name": "CVE-2026-54289: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-54289: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of Headers.append, so every value overwrites the previous one and only the last reaches the application. Repeated request headers such as X-Forwarded-For, Forwarded, and Via are silently truncated to a single value. Request mid\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.25\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.25"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-840fa19ba09b1d42", "name": "CVE-2026-56761: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-56761: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR\n\nhono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.14\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.14"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46096b62670097dc", "name": "CVE-2026-59895: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-59895: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c99a2a7dec7d2b48", "name": "CVE-2026-59897: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-59897: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication\n\nHono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.27\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.27"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4eb3111d5258074a", "name": "GHSA-26pp-8wgv-hjvm: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono missing validation of cookie name on write path in setCookie()\n\n## Summary\n\nCookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.\n\nWhile certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.\n\nThis results in inconsistent handling of cookie names between parsing (read path) and serialization (write path).\n\n## Details\n\nWhen applications use `setCookie()`, `serialize()`, or `serializeSigned()` with a user-c\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.12\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3b592d18aa740727", "name": "GHSA-v8w9-8mx6-g223: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })\n\n## Summary\n\nWhen using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property.\n\nIf the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object.\n\n## Details\n\nThe `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names.\n\nIn previous versions, the `__proto__`\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.7\nSeverity: MEDIUM\nFix: Upgrade hono to 4.12.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ace9aa5b776e6fb8", "name": "CVE-2026-44459: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44459: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()\n\nHono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() \u2014 typically when the application itself issues such tokens, or when the signing key is otherwise unde\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.12.18\nSeverity: LOW\nFix: Upgrade hono to 4.12.18"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bba1f14ea170d9c3", "name": "GHSA-gq3j-xvxp-8hrf: hono 4.11.6 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Hono added timing comparison hardening in basicAuth and bearerAuth\n\n## Summary\n\nThe `basicAuth` and `bearerAuth` middlewares previously used a comparison that was not fully timing-safe.\n\nThe `timingSafeEqual` function used normal string equality (`===`) when comparing hash values. This comparison may stop early if values differ, which can theoretically cause small timing differences.\n\nThe implementation has been updated to use a safer comparison method.\n\n\n## Details\n\nThe issue was caused by the use of normal string equality (`===`) when comparing hash values ins\n\nPackage: hono\nInstalled: 4.11.6\nFixed in: 4.11.10\nSeverity: LOW\nFix: Upgrade hono to 4.11.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-132a88cf5c46dee7", "name": "CVE-2026-59869: js-yaml 4.1.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-764d9e66a5dbf4cc", "name": "CVE-2026-53550: js-yaml 4.1.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-558492ef3c161650", "name": "CVE-2026-4800: lodash-es 4.17.21 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 web/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7081b8a400505bf9", "name": "CVE-2025-13465: lodash-es 4.17.21 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 web/package-lock.json"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-816fff617a91a18f", "name": "CVE-2026-2950: lodash-es 4.17.21 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 web/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3dce40b47cd10e9", "name": "CVE-2026-4800: lodash-es 4.17.23 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 web/package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-856845249921821e", "name": "CVE-2026-2950: lodash-es 4.17.23 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 web/package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-33d99886d828b994", "name": "CVE-2026-41148: mermaid 11.12.2 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d792de696b217f57", "name": "CVE-2026-41149: mermaid 11.12.2 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1227c8a1e556bd5f", "name": "CVE-2026-41150: mermaid 11.12.2 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-18174bd7db43e408", "name": "CVE-2026-41159: mermaid 11.12.2 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.12.2\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-50abbf3f7a5b9d11", "name": "CVE-2026-26996: minimatch 10.1.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-26996: minimatch 10.1.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service via specially crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't appear in the test string. Each * compiles to a separate [^/]*? regex group, and when the match fails, V8's regex engine backtracks exponentially across all possible splits. The time complexity is O(4^N) \n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0bb79d54e9a8f36a", "name": "CVE-2026-27903: minimatch 10.1.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-27903: minimatch 10.1.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBSTAR) segments and the input path does not match. The time complexity is O(C(n, k)) -- binomial -- where `n` is the number of path segments and `k` is the number of globstars. With k=11 and n=30, a call\n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-622725ff45a8b907", "name": "CVE-2026-27904: minimatch 10.1.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-27904: minimatch 10.1.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions\n\nminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastrophic backtracking in V8. With a 12-byte pattern `*(*(*(a|b)))` and an 18-byte non-matching input, `minimatch()` stalls for over 7 seconds. Adding a single nesting level or a few input characters pushe\n\nPackage: minimatch\nInstalled: 10.1.1\nFixed in: 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4\nSeverity: HIGH\nFix: Upgrade minimatch to 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-052241e669c85f95", "name": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions\n\nImpact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: HIGH\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ba185bbf38c0476", "name": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards\n\nImpact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too\n\nPackage: path-to-regexp\nInstalled: 8.3.0\nFixed in: 8.4.0\nSeverity: MEDIUM\nFix: Upgrade path-to-regexp to 8.4.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94c7ca87f18d61ca", "name": "CVE-2026-33671: picomatch 2.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e87f0baf6eac872", "name": "CVE-2026-33672: picomatch 2.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 2.3.1\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5ddea67eea573ca", "name": "CVE-2026-33671: picomatch 4.0.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users \n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: HIGH\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b6b7ba331901df48", "name": "CVE-2026-33672: picomatch 4.0.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions\n\nPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (int\n\nPackage: picomatch\nInstalled: 4.0.3\nFixed in: 4.0.4, 3.0.2, 2.3.2\nSeverity: MEDIUM\nFix: Upgrade picomatch to 4.0.4, 3.0.2, 2.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-936b05795ab3555e", "name": "CVE-2026-41305: postcss 8.5.6 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 web/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.5.6\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70d4e0e473d83c12", "name": "CVE-2026-8723: qs 6.14.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c1181a521e88fe4", "name": "CVE-2026-2391: qs 6.14.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "qs: qs's arrayLimit bypass in comma parsing allows denial of service\n\n### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?\n\nPackage: qs\nInstalled: 6.14.1\nFixed in: 6.14.2\nSeverity: LOW\nFix: Upgrade qs to 6.14.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c74db0c2bfb0994", "name": "CVE-2026-27606: rollup 4.56.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-27606: rollup 4.56.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability\n\nRollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output filenames (e.g., via CLI named inputs, manual chunk aliases, or malicious plugins) and use traversal sequences (`../`) to overwrite files anywhere on the host filesystem that the build\n\nPackage: rollup\nInstalled: 4.56.0\nFixed in: 2.80.0, 3.30.0, 4.59.0\nSeverity: HIGH\nFix: Upgrade rollup to 2.80.0, 3.30.0, 4.59.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-876259069f5195e3", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-00133e8d69c95772", "name": "CVE-2026-41907: uuid 13.0.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 13.0.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b26cb6d5c5913830", "name": "CVE-2026-39363: vite 7.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39363: vite 7.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Vite: Vite: Information disclosure via WebSocket connection bypasses access control\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server\u2019s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to retrieve the contents of arbitrary files on the server as a JavaScript string (e.g., export default \"...\"). The access control enforced in the HTTP request path (such as server.fs.allo\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b79b533a5c5a1c1f", "name": "CVE-2026-39364: vite 7.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39364: vite 7.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "vite: Vite: Information disclosure via query parameter manipulation on the development server\n\nVite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2\nSeverity: HIGH\nFix: Upgrade vite to 8.0.5, 7.3.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-19da828fdd50d440", "name": "CVE-2026-53571: vite 7.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-53571: vite 7.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "vite: `server.fs.deny` bypass on Windows alternate paths\n\nVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite\u2019s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw a\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: HIGH\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-03ac5d3544c4801f", "name": "CVE-2026-39365: vite 7.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-39365: vite 7.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "vite: Vite: Information disclosure via path traversal in dev server's .map request handling\n\nVite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server\u2019s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow list and retrieve .map files located outside the project root, provided they can be parsed as valid source map JSON. This vulnerability is fixed in 6.4.2, 7.3.2, and 8.0.5.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.5, 7.3.2, 6.4.2\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.5, 7.3.2, 6.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4156c4d4d707d2d", "name": "CVE-2026-53632: vite 7.3.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-53632: vite 7.3.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access\n\nlaunch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user\u2019s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.\n\nPackage: vite\nInstalled: 7.3.1\nFixed in: 8.0.16, 7.3.5, 6.4.3\nSeverity: MEDIUM\nFix: Upgrade vite to 8.0.16, 7.3.5, 6.4.3"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-79b21bd939f88b58", "name": "Agent authority lacks a verifier contract: docs/zh/customization/agents.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: docs/zh/customization/agents.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7709eb2299adaebd", "name": "Agent authority lacks a verifier contract: tests_e2e/AGENTS.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: tests_e2e/AGENTS.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f74542df7406817", "name": "Agent authority lacks a verifier contract: src/kimi_cli/acp/AGENTS.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: src/kimi_cli/acp/AGENTS.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73b54cc38905de2f", "name": "Agent authority lacks a verifier contract: src/kimi_cli/skills/kimi-cli-help/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: src/kimi_cli/skills/kimi-cli-help/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14e9677aff48a310", "name": "SkillSpector RA1 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md", "shortDescription": {"text": "SkillSpector RA1 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md"}, "fullDescription": {"text": "write SKILL\n\nSkill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.\n\nSkill: skill-creator\nRule: RA1  Category: rogue-agent\nSeverity: HIGH  Confidence: 0.85\n\nRemediation: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.85}}, {"id": "scanner-4ee2a071395dd2e8", "name": "SkillSpector RA2 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md", "shortDescription": {"text": "SkillSpector RA2 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md"}, "fullDescription": {"text": "create a new skill (or update an existing skill) that extends Kimi's capabilities with specialized knowledge, workflows, or tool integrations.\n---\n\n# Skill Creator\n\nThis skill provides guidance for cr\n\nSkill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.\n\nSkill: skill-creator\nRule: RA2  Category: rogue-agent\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan examples/sample-plugin --format sarif -"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a43404708c48f220", "name": "Insecure pattern 'dangerous_innerhtml' in web/src/components/ai-elements/code-block.tsx:419", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in web/src/components/ai-elements/code-block.tsx:419"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-4292cffb9a39534b", "name": "Insecure pattern 'cors_wildcard' in src/kimi_cli/vis/app.py:53", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in src/kimi_cli/vis/app.py:53"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-963d9472199fa641", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a05273fbb31c1df", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-036625a4cc85c58d", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-54e209731d934268", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-92fd18f7960ea0fc", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2fc7b9381819720", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3fd8280f24592fa", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef24c99fc93818e8", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-20c80f3ff485f877", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13e6f6c2dc7231e1", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-057ebf0f76b942cc", "name": "GitHub Action tracks a moving branch", "shortDescription": {"text": "GitHub Action tracks a moving branch"}, "fullDescription": {"text": "DeterminateSystems/nix-installer-action@main can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6785afae3935ea7a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f8b9ecdd9768fcb2", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb0f46e2443b4e3b", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a3ad83d51fda4321", "name": "Very large file: tests/tools/test_agent_tool.py (1611 lines)", "shortDescription": {"text": "Very large file: tests/tools/test_agent_tool.py (1611 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3941a6629417d748", "name": "Very large file: tests/core/test_kimisoul_background_wait.py (1463 lines)", "shortDescription": {"text": "Very large file: tests/core/test_kimisoul_background_wait.py (1463 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-136ff6a927d8e60b", "name": "Very large file: tests/core/test_skill.py (1841 lines)", "shortDescription": {"text": "Very large file: tests/core/test_skill.py (1841 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ffd74846139d70a5", "name": "Very large file: tests/telemetry/test_instrumentation.py (1381 lines)", "shortDescription": {"text": "Very large file: tests/telemetry/test_instrumentation.py (1381 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bf300717fe5895f", "name": "Very large file: web/src/hooks/useSessionStream.ts (3102 lines)", "shortDescription": {"text": "Very large file: web/src/hooks/useSessionStream.ts (3102 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4acc33a13184b55", "name": "Very large file: web/src/features/sessions/sessions.tsx (1274 lines)", "shortDescription": {"text": "Very large file: web/src/features/sessions/sessions.tsx (1274 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e71025c013849db2", "name": "Very large file: src/kimi_cli/ui/shell/__init__.py (1551 lines)", "shortDescription": {"text": "Very large file: src/kimi_cli/ui/shell/__init__.py (1551 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82da86aab5549546", "name": "Very large file: src/kimi_cli/ui/shell/prompt.py (2259 lines)", "shortDescription": {"text": "Very large file: src/kimi_cli/ui/shell/prompt.py (2259 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd29667973cece46", "name": "Very large file: src/kimi_cli/soul/kimisoul.py (1963 lines)", "shortDescription": {"text": "Very large file: src/kimi_cli/soul/kimisoul.py (1963 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-98eecf7aa017d4cb", "name": "96 TODO/FIXME markers", "shortDescription": {"text": "96 TODO/FIXME markers"}, "fullDescription": {"text": "High count of TODO/FIXME/HACK markers \u2014 track them as issues so they're not forgotten."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 125 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 55 placeholder/mock markers across 30 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75454790e0c325b0", "name": "Network/subprocess call without timeout or try/except \u2014 tests_ai/scripts/run.py:49", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 tests_ai/scripts/run.py:49"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-4f764ba2b88fde08", "name": "Stub function `log_message` (body is just `pass`/`return`) \u2014 scripts/telemetry_debug_server.py:104", "shortDescription": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 scripts/telemetry_debug_server.py:104"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e65416f9e6d0900", "name": "Legacy-named symbol `model_copy` in packages/kosong/src/kosong/_generate.py:64", "shortDescription": {"text": "Legacy-named symbol `model_copy` in packages/kosong/src/kosong/_generate.py:64"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4863aff295561d55", "name": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/mock.py:40", "shortDescription": {"text": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/mock.py:40"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fefab07eb160b85", "name": "Legacy-named symbol `OpenAILegacy` in packages/kosong/src/kosong/chat_provider/chaos.py:152", "shortDescription": {"text": "Legacy-named symbol `OpenAILegacy` in packages/kosong/src/kosong/chat_provider/chaos.py:152"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b33baf6704058e4", "name": "Legacy-named symbol `model_copy` in packages/kosong/src/kosong/chat_provider/kimi.py:327", "shortDescription": {"text": "Legacy-named symbol `model_copy` in packages/kosong/src/kosong/chat_provider/kimi.py:327"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73dce4bdea8868d3", "name": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/echo/scripted_", "shortDescription": {"text": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/echo/scripted_echo.py:44"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d58ec04aae9a385f", "name": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/echo/echo.py:6", "shortDescription": {"text": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/echo/echo.py:67"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f2e2dd4b58a0f1f", "name": "Legacy-named symbol `openai_legacy` in packages/kosong/src/kosong/contrib/chat_provider/openai_legacy.py:38", "shortDescription": {"text": "Legacy-named symbol `openai_legacy` in packages/kosong/src/kosong/contrib/chat_provider/openai_legacy.py:38"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96de48ccf491ad75", "name": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/openai_legacy", "shortDescription": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/openai_legacy.py:246"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63e9b9539b8fc07a", "name": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/anthropic.py:", "shortDescription": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/anthropic.py:529"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-532fd1dca8ad2a97", "name": "Legacy-named symbol `OpenAILegacy` in packages/kosong/src/kosong/contrib/chat_provider/openai_responses.py:95", "shortDescription": {"text": "Legacy-named symbol `OpenAILegacy` in packages/kosong/src/kosong/contrib/chat_provider/openai_responses.py:95"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a76d946fc06a406", "name": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/openai_respon", "shortDescription": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/openai_responses.py:478"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e8b787ebd50f8f6", "name": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/google_genai.", "shortDescription": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/google_genai.py:253"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee011fc3cd67720c", "name": "Legacy-named symbol `lineNumberOld` in web/src/components/ui/diff/index.tsx:147", "shortDescription": {"text": "Legacy-named symbol `lineNumberOld` in web/src/components/ui/diff/index.tsx:147"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-680943cc25494261", "name": "Legacy-named symbol `OpenaiLegacy` in web/src/lib/api/models/ProviderType.ts:22", "shortDescription": {"text": "Legacy-named symbol `OpenaiLegacy` in web/src/lib/api/models/ProviderType.ts:22"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99a5883e262b3e61", "name": "Network/subprocess call without timeout or try/except \u2014 examples/custom-kimi-soul/main.py:79", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 examples/custom-kimi-soul/main.py:79"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-4358bfed3c2714dc", "name": "Legacy-named symbol `files_to_copy` in src/kimi_cli/session_fork.py:315", "shortDescription": {"text": "Legacy-named symbol `files_to_copy` in src/kimi_cli/session_fork.py:315"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21cdda6c41e8befc", "name": "Legacy-named symbol `openai_legacy` in src/kimi_cli/config.py:50", "shortDescription": {"text": "Legacy-named symbol `openai_legacy` in src/kimi_cli/config.py:50"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72214a1add7122fe", "name": "Legacy-named symbol `openai_legacy` in src/kimi_cli/llm.py:34", "shortDescription": {"text": "Legacy-named symbol `openai_legacy` in src/kimi_cli/llm.py:34"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e654319617156b87", "name": "Legacy-named symbol `model_copy` in src/kimi_cli/notifications/manager.py:55", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/notifications/manager.py:55"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3c1f1734f6ff415", "name": "Stub function `flush` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/print/visualize.py:38", "shortDescription": {"text": "Stub function `flush` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/print/visualize.py:38"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-656f260ec7a72182", "name": "Legacy-named symbol `model_copy` in src/kimi_cli/ui/shell/__init__.py:1163", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/ui/shell/__init__.py:1163"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ec9b7c313c6d377", "name": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_btw_panel.p", "shortDescription": {"text": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_btw_panel.py:199"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c67cc1104319a06", "name": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_approval_pa", "shortDescription": {"text": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_approval_panel.py:389"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4835dca9ddf8ee02", "name": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_question_pa", "shortDescription": {"text": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_question_panel.py:377"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bfe6d546f2d14b3", "name": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/cli/plugin.py:145", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/cli/plugin.py:145"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-b6aaf2a9a1c9f2b3", "name": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/cli/toad.py:71", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/cli/toad.py:71"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-41836e44672e85f8", "name": "Stub function `close` (body is just `pass`/`return`) \u2014 src/kimi_cli/acp/kaos.py:22", "shortDescription": {"text": "Stub function `close` (body is just `pass`/`return`) \u2014 src/kimi_cli/acp/kaos.py:22"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63df3d8f50464b7f", "name": "Legacy-named symbol `model_copy` in src/kimi_cli/soul/toolset.py:226", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/soul/toolset.py:226"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc7fb9ec28e33da5", "name": "Legacy-named symbol `model_copy` in src/kimi_cli/tools/background/__init__.py:247", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/tools/background/__init__.py:247"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5b46bf493bf6b6c", "name": "Legacy-named symbol `model_copy` in src/kimi_cli/background/worker.py:188", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/background/worker.py:188"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e8329d5f1ccd13c", "name": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/background/worker.py:23", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/background/worker.py:23"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-aec9ada46b4974cd", "name": "Legacy-named symbol `model_copy` in src/kimi_cli/background/manager.py:393", "shortDescription": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/background/manager.py:393"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\nscripts/build_web.py:50:resolve_npm, scripts/build_vis.py:26:resolve_npm\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\npackages/kosong/src/kosong/contrib/chat_provider/openai_legacy.py:170:with_generation_kwargs, packages/kosong/src/kosong/contrib/chat_provider/anthropic.py:419:with_generation_kwargs, packages/kosong/src/kosong/contrib/chat_provider/openai_responses.py:206:with_generation_kwargs, packages/kosong/src/kosong/contrib/chat_provider/google_genai.py:207:with_generation_kwargs\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-700227e33027cc35", "name": "FastAPI POST `import_session` without auth dependency \u2014 src/kimi_cli/vis/api/sessions.py:606", "shortDescription": {"text": "FastAPI POST `import_session` without auth dependency \u2014 src/kimi_cli/vis/api/sessions.py:606"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bd59ba5827b980d0", "name": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/kimi_cli/vis/api/sessions.py:673", "shortDescription": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/kimi_cli/vis/api/sessions.py:673"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-a2cee554867be179", "name": "FastAPI PATCH `update_global_config` without auth dependency \u2014 src/kimi_cli/web/api/config.py:128", "shortDescription": {"text": "FastAPI PATCH `update_global_config` without auth dependency \u2014 src/kimi_cli/web/api/config.py:128"}, "fullDescription": {"text": "`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-fb615a26750dbb23", "name": "FastAPI PUT `update_config_toml` without auth dependency \u2014 src/kimi_cli/web/api/config.py:187", "shortDescription": {"text": "FastAPI PUT `update_config_toml` without auth dependency \u2014 src/kimi_cli/web/api/config.py:187"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c6676c2f8b2ab02a", "name": "FastAPI POST `open_in` without auth dependency \u2014 src/kimi_cli/web/api/open_in.py:176", "shortDescription": {"text": "FastAPI POST `open_in` without auth dependency \u2014 src/kimi_cli/web/api/open_in.py:176"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-34615ef32843ca78", "name": "FastAPI POST `create_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:299", "shortDescription": {"text": "FastAPI POST `create_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:299"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-57b4b1641e20bcef", "name": "FastAPI POST `upload_session_file` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:379", "shortDescription": {"text": "FastAPI POST `upload_session_file` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:379"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-1cc7c652314a7f6c", "name": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:565", "shortDescription": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:565"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2790e447b726ec75", "name": "FastAPI PATCH `update_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:586", "shortDescription": {"text": "FastAPI PATCH `update_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:586"}, "fullDescription": {"text": "`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2e9cf0d3da523edf", "name": "FastAPI POST `fork_session_endpoint` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:684", "shortDescription": {"text": "FastAPI POST `fork_session_endpoint` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:684"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-e24f02913f1907b6", "name": "FastAPI POST `generate_session_title` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:749", "shortDescription": {"text": "FastAPI POST `generate_session_title` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:749"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-212575d3b04067ab", "name": "Vulnerable dependency js-yaml 3.14.2: GHSA-52cp-r559-cp3m", "shortDescription": {"text": "Vulnerable dependency js-yaml 3.14.2: GHSA-52cp-r559-cp3m"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `3.14.2` (resolved in `docs/bun.lock`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869).\n\njs-yaml: YAML merge-key chains can force quadratic CPU consumption\n\nAliases: CVE-2026-59869\nAdvisory: https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b41e333292639b42", "name": "Vulnerable dependency js-yaml 3.14.2: GHSA-h67p-54hq-rp68", "shortDescription": {"text": "Vulnerable dependency js-yaml 3.14.2: GHSA-h67p-54hq-rp68"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `3.14.2` (resolved in `docs/bun.lock`) is affected by GHSA-h67p-54hq-rp68 (aka CVE-2026-53550).\n\nJS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases\n\nAliases: CVE-2026-53550\nAdvisory: https://osv.dev/vulnerability/GHSA-h67p-54hq-rp68\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e2b56e6094d27e56", "name": "Vulnerable dependency mermaid 11.12.2: GHSA-6m6c-36f7-fhxh", "shortDescription": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-6m6c-36f7-fhxh"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.12.2` (resolved in `docs/bun.lock`) is affected by GHSA-6m6c-36f7-fhxh (aka CVE-2026-41150).\n\nMermaid Gantt Charts are vulnerable to an Infinite Loop DoS\n\nAliases: CVE-2026-41150\nAdvisory: https://osv.dev/vulnerability/GHSA-6m6c-36f7-fhxh\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6946d88015c8d257", "name": "Vulnerable dependency mermaid 11.12.2: GHSA-87f9-hvmw-gh4p", "shortDescription": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-87f9-hvmw-gh4p"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.12.2` (resolved in `docs/bun.lock`) is affected by GHSA-87f9-hvmw-gh4p (aka CVE-2026-41159).\n\nMermaid: Improper sanitization of configuration leads to CSS injection\n\nAliases: CVE-2026-41159\nAdvisory: https://osv.dev/vulnerability/GHSA-87f9-hvmw-gh4p\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f1688d50c54451b", "name": "Vulnerable dependency mermaid 11.12.2: GHSA-ghcm-xqfw-q4vr", "shortDescription": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-ghcm-xqfw-q4vr"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.12.2` (resolved in `docs/bun.lock`) is affected by GHSA-ghcm-xqfw-q4vr (aka CVE-2026-41149).\n\nMermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection\n\nAliases: CVE-2026-41149\nAdvisory: https://osv.dev/vulnerability/GHSA-ghcm-xqfw-q4vr\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-09f823568694d4c6", "name": "Vulnerable dependency mermaid 11.12.2: GHSA-xcj9-5m2h-648r", "shortDescription": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-xcj9-5m2h-648r"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.12.2` (resolved in `docs/bun.lock`) is affected by GHSA-xcj9-5m2h-648r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xcj9-5m2h-648r\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d254dd8a8f495c7", "name": "Vulnerable dependency uuid 11.1.0: GHSA-w5hq-g745-h8pq", "shortDescription": {"text": "Vulnerable dependency uuid 11.1.0: GHSA-w5hq-g745-h8pq"}, "fullDescription": {"text": "OSV.dev reports `uuid` at version `11.1.0` (resolved in `docs/bun.lock`) is affected by GHSA-w5hq-g745-h8pq (aka CVE-2026-41907, CVE-2026-41988).\n\nuuid: Missing buffer bounds check in v3/v5/v6 when buf is provided\n\nAliases: CVE-2026-41907, CVE-2026-41988\nAdvisory: https://osv.dev/vulnerability/GHSA-w5hq-g745-h8pq\nFix: upgrade `uuid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-97f2892f18113d2d", "name": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `docs/bun.lock`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ddfe3289ae22d5a3", "name": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `docs/bun.lock`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb9159bcc344c6f1", "name": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `5.4.21` (resolved in `docs/bun.lock`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-caa469ae1d48826a", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-2fqr-mr3j-6wp8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2fqr-mr3j-6wp8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-2fqr-mr3j-6wp8 (aka CVE-2026-54279).\n\naiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence\n\nAliases: CVE-2026-54279, PYSEC-2026-2112\nAdvisory: https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a11b8a9a73becc5", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-2vrm-gr82-f7m5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2vrm-gr82-f7m5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-2vrm-gr82-f7m5 (aka CVE-2026-34514).\n\nAIOHTTP has CRLF injection through multipart part content type header construction\n\nAliases: CVE-2026-34514, PYSEC-2026-2096\nAdvisory: https://osv.dev/vulnerability/GHSA-2vrm-gr82-f7m5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f554ec6b83a12ddb", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-3wq7-rqq7-wx6j", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-3wq7-rqq7-wx6j"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-3wq7-rqq7-wx6j (aka CVE-2026-34517).\n\nAIOHTTP has late size enforcement for non-file multipart fields causes memory DoS\n\nAliases: CVE-2026-34517, PYSEC-2026-2099\nAdvisory: https://osv.dev/vulnerability/GHSA-3wq7-rqq7-wx6j\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6bb9cc560c27851b", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-4fvr-rgm6-gqmc", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4fvr-rgm6-gqmc"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-4fvr-rgm6-gqmc (aka CVE-2026-54273).\n\naiohttp: HTTP/1 Pipelined Requests Queue Without Limit\n\nAliases: CVE-2026-54273, PYSEC-2026-2107\nAdvisory: https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9697c24aa4e094dc", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-4m7w-qmgq-4wj5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4m7w-qmgq-4wj5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-4m7w-qmgq-4wj5 (aka CVE-2026-54275).\n\naiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections\n\nAliases: CVE-2026-54275, PYSEC-2026-237\nAdvisory: https://osv.dev/vulnerability/GHSA-4m7w-qmgq-4wj5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6605999a5655046d", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hf-3vf5-4wqf", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hf-3vf5-4wqf"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-63hf-3vf5-4wqf.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hf-3vf5-4wqf\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b04019ff778e11e", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hw-fmq6-xxg2", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hw-fmq6-xxg2"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-63hw-fmq6-xxg2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7f24e42ab71a0c5", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-966j-vmvw-g2g9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-966j-vmvw-g2g9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-966j-vmvw-g2g9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-966j-vmvw-g2g9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-31e8a3e4292fccca", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-9x8q-7h8h-wcw9", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-9x8q-7h8h-wcw9"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-9x8q-7h8h-wcw9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2eea30546fee0e81", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-c427-h43c-vf67", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-c427-h43c-vf67"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-c427-h43c-vf67.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c427-h43c-vf67\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ffc2cec7e38f5655", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-g3cq-j2xw-wf74", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-g3cq-j2xw-wf74"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-g3cq-j2xw-wf74.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g3cq-j2xw-wf74\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-647bb06712718701", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-hcc4-c3v8-rx92", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hcc4-c3v8-rx92"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-hcc4-c3v8-rx92.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hcc4-c3v8-rx92\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b53fe845d091f72e", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-hg6j-4rv6-33pg", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hg6j-4rv6-33pg"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-hg6j-4rv6-33pg.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hg6j-4rv6-33pg\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e025c42aa4a9bea", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-hpj7-wq8m-9hgp", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hpj7-wq8m-9hgp"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-hpj7-wq8m-9hgp.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hpj7-wq8m-9hgp\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d40361292f797c15", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-jg22-mg44-37j8", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-jg22-mg44-37j8"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-jg22-mg44-37j8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d1383d39fd08f35", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-m5qp-6w8w-w647", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m5qp-6w8w-w647"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-m5qp-6w8w-w647.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m5qp-6w8w-w647\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7fc364b8230458f", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-m6qw-4cw2-hm4m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m6qw-4cw2-hm4m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-m6qw-4cw2-hm4m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-m6qw-4cw2-hm4m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4b3e3b387bad0d80", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-mwh4-6h8g-pg8w", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-mwh4-6h8g-pg8w"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-mwh4-6h8g-pg8w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwh4-6h8g-pg8w\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29bf4996aa48ac34", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-p998-jp59-783m", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-p998-jp59-783m"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-p998-jp59-783m.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p998-jp59-783m\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42f7dbd34eeac13c", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-w2fm-2cpv-w7v5", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-w2fm-2cpv-w7v5"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-w2fm-2cpv-w7v5.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-w2fm-2cpv-w7v5\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c0708c829148ab52", "name": "Vulnerable dependency aiohttp 3.13.3: GHSA-xcgm-r5h9-7989", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-xcgm-r5h9-7989"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by GHSA-xcgm-r5h9-7989.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xcgm-r5h9-7989\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efe96a59942df855", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2094", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2094"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2094.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2094\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bdd5476454137428", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2095", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2095"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2095.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2095\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-36a9ed9825abec46", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2097", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2097"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2097.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2097\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4e6d996955fe2aee", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2098", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2098"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2098.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2098\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ed2b8963814a1237", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2100", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2100"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2100.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2100\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8459238f0f24dfa9", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2101", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2101"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2101.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2101\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7cfd946f083c3fdd", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2102", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2102"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2102.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2102\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-178e037badb1d97c", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2103", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2103"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2103.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2103\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc4eeaf5812e4da5", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2104", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2104"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2104.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2104\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d86f28942ec95de6", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2105", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2105"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2105.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2105\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d844c2ae1a8955ff", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2106", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2106"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2106.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2106\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b3bed74be25763b6", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2108", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2108"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2108.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2108\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9dbd79f569e97d08", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2109", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2109"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2109.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2109\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-385291c68642e7c3", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2110", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2110"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2110.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2110\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b071ccd679537de1", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2111", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2111"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2111.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2111\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-184e843d542d2f54", "name": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2113", "shortDescription": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2113"}, "fullDescription": {"text": "OSV.dev reports `aiohttp` at version `3.13.3` (resolved in `uv.lock`) is affected by PYSEC-2026-2113.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2113\nFix: upgrade `aiohttp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e020a884ce691a0", "name": "Vulnerable dependency lxml 6.0.2: GHSA-vfmq-68hx-4jfw", "shortDescription": {"text": "Vulnerable dependency lxml 6.0.2: GHSA-vfmq-68hx-4jfw"}, "fullDescription": {"text": "OSV.dev reports `lxml` at version `6.0.2` (resolved in `uv.lock`) is affected by GHSA-vfmq-68hx-4jfw.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vfmq-68hx-4jfw\nFix: upgrade `lxml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-21895d371778d4fc", "name": "Vulnerable dependency lxml 6.0.2: PYSEC-2026-87", "shortDescription": {"text": "Vulnerable dependency lxml 6.0.2: PYSEC-2026-87"}, "fullDescription": {"text": "OSV.dev reports `lxml` at version `6.0.2` (resolved in `uv.lock`) is affected by PYSEC-2026-87.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-87\nFix: upgrade `lxml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28778d523a11cc4f", "name": "Vulnerable dependency mcp 1.27.1: GHSA-hvrp-rf83-w775", "shortDescription": {"text": "Vulnerable dependency mcp 1.27.1: GHSA-hvrp-rf83-w775"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.27.1` (resolved in `uv.lock`) is affected by GHSA-hvrp-rf83-w775.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hvrp-rf83-w775\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11e70092a10b83a9", "name": "Vulnerable dependency mcp 1.27.1: GHSA-jpw9-pfvf-9f58", "shortDescription": {"text": "Vulnerable dependency mcp 1.27.1: GHSA-jpw9-pfvf-9f58"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.27.1` (resolved in `uv.lock`) is affected by GHSA-jpw9-pfvf-9f58.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jpw9-pfvf-9f58\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-531df51c5b1c0a8b", "name": "Vulnerable dependency mcp 1.27.1: GHSA-vj7q-gjh5-988w", "shortDescription": {"text": "Vulnerable dependency mcp 1.27.1: GHSA-vj7q-gjh5-988w"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.27.1` (resolved in `uv.lock`) is affected by GHSA-vj7q-gjh5-988w.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vj7q-gjh5-988w\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b17bbc17fb18785d", "name": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3481", "shortDescription": {"text": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3481"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.27.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3481.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3481\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-097486ce09a16abb", "name": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3482", "shortDescription": {"text": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3482"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.27.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3482.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3482\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-945ffc2907864939", "name": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3483", "shortDescription": {"text": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3483"}, "fullDescription": {"text": "OSV.dev reports `mcp` at version `1.27.1` (resolved in `uv.lock`) is affected by PYSEC-2026-3483.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3483\nFix: upgrade `mcp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-26b6f8b3807a7d11", "name": "Vulnerable dependency pillow 12.2.0: GHSA-45hq-cxwh-f6vc", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-45hq-cxwh-f6vc"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-45hq-cxwh-f6vc (aka CVE-2026-55379).\n\nPillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` \u2014 bomb protection bypass via font loading\n\nAliases: BIT-pillow-2026-55379, CVE-2026-55379, PYSEC-2026-2255\nAdvisory: https://osv.dev/vulnerability/GHSA-45hq-cxwh-f6vc\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e179a0cd7e264c13", "name": "Vulnerable dependency pillow 12.2.0: GHSA-4x4j-2g7c-83w6", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-4x4j-2g7c-83w6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-4x4j-2g7c-83w6 (aka CVE-2026-55798).\n\nPillow: WindowsViewer.get_command() OS command injection via unescaped shell path\n\nAliases: BIT-pillow-2026-55798, CVE-2026-55798, PYSEC-2026-2257\nAdvisory: https://osv.dev/vulnerability/GHSA-4x4j-2g7c-83w6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3a36f07ef177754", "name": "Vulnerable dependency pillow 12.2.0: GHSA-5x94-69rx-g8h2", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-5x94-69rx-g8h2"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-5x94-69rx-g8h2.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5384747de2e37c98", "name": "Vulnerable dependency pillow 12.2.0: GHSA-62p4-gmf7-7g93", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-62p4-gmf7-7g93"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-62p4-gmf7-7g93.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-62p4-gmf7-7g93\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f8beff4a9af5c5be", "name": "Vulnerable dependency pillow 12.2.0: GHSA-6r8x-57c9-28j4", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-6r8x-57c9-28j4"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-6r8x-57c9-28j4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6r8x-57c9-28j4\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f8488f3a91f8df65", "name": "Vulnerable dependency pillow 12.2.0: GHSA-8v84-f9pq-wr9x", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-8v84-f9pq-wr9x"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-8v84-f9pq-wr9x.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8v84-f9pq-wr9x\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7602a07828225ac7", "name": "Vulnerable dependency pillow 12.2.0: GHSA-9hw9-ch79-4vh6", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-9hw9-ch79-4vh6"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-9hw9-ch79-4vh6.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-9hw9-ch79-4vh6\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6c920ed71172c7ef", "name": "Vulnerable dependency pillow 12.2.0: GHSA-fj7v-r99m-22gq", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-fj7v-r99m-22gq"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-fj7v-r99m-22gq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-fj7v-r99m-22gq\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae690675f1331b95", "name": "Vulnerable dependency pillow 12.2.0: GHSA-jjj6-mw9f-p565", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-jjj6-mw9f-p565"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-jjj6-mw9f-p565.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-92d8e588e496021f", "name": "Vulnerable dependency pillow 12.2.0: GHSA-pg7v-jwj7-p798", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-pg7v-jwj7-p798"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-pg7v-jwj7-p798.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pg7v-jwj7-p798\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06c84b207e834da7", "name": "Vulnerable dependency pillow 12.2.0: GHSA-phj9-mv4w-65pm", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-phj9-mv4w-65pm"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-phj9-mv4w-65pm.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-phj9-mv4w-65pm\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70b58a986e4ca70b", "name": "Vulnerable dependency pillow 12.2.0: GHSA-vjc4-5qp5-m44j", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-vjc4-5qp5-m44j"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-vjc4-5qp5-m44j.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vjc4-5qp5-m44j\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f29ea915376b373", "name": "Vulnerable dependency pillow 12.2.0: GHSA-xj96-63gp-2gmr", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-xj96-63gp-2gmr"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by GHSA-xj96-63gp-2gmr.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dfd30679f5478158", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2253", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2253"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2253.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2253\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-967f2045d8f37ea1", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2254", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2254"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2254.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2254\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e0e9722f366f4c4", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2256", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2256"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-2256.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2256\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4302a20b8a3a5346", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3451", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3451"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3451.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3451\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7917dff4db13603", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3452", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3452"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3452.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3452\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ad66eec714af149", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3453", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3453"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3453.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3453\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7601908cb7bf2225", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3454", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3454"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3454.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3454\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad0db56c4ac414b9", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3493", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3493"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3493.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3493\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e5171d7207f6b07", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3494", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3494"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3494.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3494\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f2f22e193493c3c", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3495", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3495"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3495.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3495\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-979def41aaef6c02", "name": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3496", "shortDescription": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3496"}, "fullDescription": {"text": "OSV.dev reports `pillow` at version `12.2.0` (resolved in `uv.lock`) is affected by PYSEC-2026-3496.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-3496\nFix: upgrade `pillow` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4fe508fe435c3eb", "name": "Vulnerable dependency python-dotenv 1.2.1: GHSA-mf9w-mj56-hr94", "shortDescription": {"text": "Vulnerable dependency python-dotenv 1.2.1: GHSA-mf9w-mj56-hr94"}, "fullDescription": {"text": "OSV.dev reports `python-dotenv` at version `1.2.1` (resolved in `uv.lock`) is affected by GHSA-mf9w-mj56-hr94.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mf9w-mj56-hr94\nFix: upgrade `python-dotenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-739fa31a9483e558", "name": "Vulnerable dependency python-dotenv 1.2.1: PYSEC-2026-2270", "shortDescription": {"text": "Vulnerable dependency python-dotenv 1.2.1: PYSEC-2026-2270"}, "fullDescription": {"text": "OSV.dev reports `python-dotenv` at version `1.2.1` (resolved in `uv.lock`) is affected by PYSEC-2026-2270.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/PYSEC-2026-2270\nFix: upgrade `python-dotenv` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-983c20c586ea3ae3", "name": "Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `web/package-lock.json`) is affected by GHSA-52cp-r559-cp3m (aka CVE-2026-59869).\n\njs-yaml: YAML merge-key chains can force quadratic CPU consumption\n\nAliases: CVE-2026-59869\nAdvisory: https://osv.dev/vulnerability/GHSA-52cp-r559-cp3m\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f431c20b53cfc9c", "name": "Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68", "shortDescription": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68"}, "fullDescription": {"text": "OSV.dev reports `js-yaml` at version `4.1.1` (resolved in `web/package-lock.json`) is affected by GHSA-h67p-54hq-rp68 (aka CVE-2026-53550).\n\nJS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases\n\nAliases: CVE-2026-53550\nAdvisory: https://osv.dev/vulnerability/GHSA-h67p-54hq-rp68\nFix: upgrade `js-yaml` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df6c3416105c8180", "name": "Vulnerable dependency uuid 13.0.0: GHSA-w5hq-g745-h8pq", "shortDescription": {"text": "Vulnerable dependency uuid 13.0.0: GHSA-w5hq-g745-h8pq"}, "fullDescription": {"text": "OSV.dev reports `uuid` at version `13.0.0` (resolved in `web/package-lock.json`) is affected by GHSA-w5hq-g745-h8pq (aka CVE-2026-41907, CVE-2026-41988).\n\nuuid: Missing buffer bounds check in v3/v5/v6 when buf is provided\n\nAliases: CVE-2026-41907, CVE-2026-41988\nAdvisory: https://osv.dev/vulnerability/GHSA-w5hq-g745-h8pq\nFix: upgrade `uuid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f37aa0dcec16e6fe", "name": "Vulnerable dependency vite 7.2.4: GHSA-4w7w-66w2-5vf9", "shortDescription": {"text": "Vulnerable dependency vite 7.2.4: GHSA-4w7w-66w2-5vf9"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.2.4` (declared in `vis/package.json`) is affected by GHSA-4w7w-66w2-5vf9 (aka CVE-2026-39365).\nNote: `7.2.4` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite Vulnerable to Path Traversal in Optimized Deps `.map` Handling\n\nAliases: CVE-2026-39365\nAdvisory: https://osv.dev/vulnerability/GHSA-4w7w-66w2-5vf9\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-669deaa7cb137589", "name": "Vulnerable dependency vite 7.2.4: GHSA-fx2h-pf6j-xcff", "shortDescription": {"text": "Vulnerable dependency vite 7.2.4: GHSA-fx2h-pf6j-xcff"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.2.4` (declared in `vis/package.json`) is affected by GHSA-fx2h-pf6j-xcff (aka CVE-2026-53571).\nNote: `7.2.4` is the declared floor of a range \u2014 the installed version may be newer.\n\nvite: `server.fs.deny` bypass on Windows alternate paths\n\nAliases: CVE-2026-53571\nAdvisory: https://osv.dev/vulnerability/GHSA-fx2h-pf6j-xcff\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-f93f6e98eae25194", "name": "Vulnerable dependency vite 7.2.4: GHSA-p9ff-h696-f583", "shortDescription": {"text": "Vulnerable dependency vite 7.2.4: GHSA-p9ff-h696-f583"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.2.4` (declared in `vis/package.json`) is affected by GHSA-p9ff-h696-f583 (aka CVE-2026-39363).\nNote: `7.2.4` is the declared floor of a range \u2014 the installed version may be newer.\n\nVite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket\n\nAliases: CVE-2026-39363\nAdvisory: https://osv.dev/vulnerability/GHSA-p9ff-h696-f583\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.7}}, {"id": "scanner-1fafdba5bbf26059", "name": "Vulnerable dependency vite 7.2.4: GHSA-v2wj-q39q-566r", "shortDescription": {"text": "Vulnerable dependency vite 7.2.4: GHSA-v2wj-q39q-566r"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.2.4` (declared in `vis/package.json`) is affected by GHSA-v2wj-q39q-566r.\nNote: `7.2.4` is the declared floor of a range \u2014 the installed version may be newer.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v2wj-q39q-566r\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-5cc790d06c2d9b3b", "name": "Vulnerable dependency vite 7.2.4: GHSA-v6wh-96g9-6wx3", "shortDescription": {"text": "Vulnerable dependency vite 7.2.4: GHSA-v6wh-96g9-6wx3"}, "fullDescription": {"text": "OSV.dev reports `vite` at version `7.2.4` (declared in `vis/package.json`) is affected by GHSA-v6wh-96g9-6wx3 (aka CVE-2026-53632).\nNote: `7.2.4` is the declared floor of a range \u2014 the installed version may be newer.\n\nlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows\n\nAliases: CVE-2026-53632\nAdvisory: https://osv.dev/vulnerability/GHSA-v6wh-96g9-6wx3\nFix: upgrade `vite` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-6c267888a2469717", "name": "Vulnerable dependency @isaacs/brace-expansion 5.0.0: GHSA-7h2j-956f-4vf2", "shortDescription": {"text": "Vulnerable dependency @isaacs/brace-expansion 5.0.0: GHSA-7h2j-956f-4vf2"}, "fullDescription": {"text": "OSV.dev reports `@isaacs/brace-expansion` at version `5.0.0` (resolved in `docs/bun.lock`) is affected by GHSA-7h2j-956f-4vf2.\nNote: `@isaacs/brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7h2j-956f-4vf2\nFix: upgrade `@isaacs/brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b42bec48d22ccce8", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-39q2-94rc-95cp", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-39q2-94rc-95cp"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-39q2-94rc-95cp (aka CVE-2026-65903).\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation\n\nAliases: CVE-2026-65903\nAdvisory: https://osv.dev/vulnerability/GHSA-39q2-94rc-95cp\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8f92adac25e76894", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-76mc-f452-cxcm", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-76mc-f452-cxcm"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-76mc-f452-cxcm.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-76mc-f452-cxcm\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b0ec2dd47549a346", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-c2j3-45gr-mqc4", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-c2j3-45gr-mqc4"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-c2j3-45gr-mqc4.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c2j3-45gr-mqc4\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b3b28afcd2e4da07", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-cj63-jhhr-wcxv", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-cj63-jhhr-wcxv"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-cj63-jhhr-wcxv.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-cj63-jhhr-wcxv\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5e1203c81bfd4f38", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-cjmm-f4jc-qw8r", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-cjmm-f4jc-qw8r"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-cjmm-f4jc-qw8r.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-cjmm-f4jc-qw8r\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7974be37e2a06d82", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-cmwh-pvxp-8882", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-cmwh-pvxp-8882"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-cmwh-pvxp-8882.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-cmwh-pvxp-8882\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-86e7673338c6205b", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-crv5-9vww-q3g8", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-crv5-9vww-q3g8"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-crv5-9vww-q3g8.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-crv5-9vww-q3g8\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b776610a93e32745", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-gvmj-g25r-r7wr", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-gvmj-g25r-r7wr"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-gvmj-g25r-r7wr.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gvmj-g25r-r7wr\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-6e406a031b72ae55", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-h7mw-gpvr-xq4m", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-h7mw-gpvr-xq4m"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-h7mw-gpvr-xq4m.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h7mw-gpvr-xq4m\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-807cfbec9f23850a", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-h8r8-wccr-v5f2", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-h8r8-wccr-v5f2"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-h8r8-wccr-v5f2.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-h8r8-wccr-v5f2\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c1babea11b5cb953", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-hpcv-96wg-7vj8", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-hpcv-96wg-7vj8"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-hpcv-96wg-7vj8.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hpcv-96wg-7vj8\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-42fe30043e8586e6", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-r47g-fvhr-h676", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-r47g-fvhr-h676"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-r47g-fvhr-h676.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r47g-fvhr-h676\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-cd6874b117e2b95b", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-rp9w-3fw7-7cwq", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-rp9w-3fw7-7cwq"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-rp9w-3fw7-7cwq.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rp9w-3fw7-7cwq\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4be24907e8e459c9", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-v2wj-7wpq-c8vv", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-v2wj-7wpq-c8vv"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-v2wj-7wpq-c8vv.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v2wj-7wpq-c8vv\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7bb85b8174ffddfb", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-v9jr-rg53-9pgp", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-v9jr-rg53-9pgp"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-v9jr-rg53-9pgp.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v9jr-rg53-9pgp\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-efb3aaf7fc3e8fb6", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-vxr8-fq34-vvx9", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-vxr8-fq34-vvx9"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-vxr8-fq34-vvx9.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vxr8-fq34-vvx9\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b0bef337d3dbdff1", "name": "Vulnerable dependency dompurify 3.3.1: GHSA-x4vx-rjvf-j5p4", "shortDescription": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-x4vx-rjvf-j5p4"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.3.1` (resolved in `docs/bun.lock`) is affected by GHSA-x4vx-rjvf-j5p4.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x4vx-rjvf-j5p4\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b38b41feba2d0049", "name": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99", "shortDescription": {"text": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.21.5` (resolved in `docs/bun.lock`) is affected by GHSA-67mh-4wv8-2f99.\nNote: `esbuild` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nesbuild enables any website to send any requests to the development server and read the response\n\nAdvisory: https://osv.dev/vulnerability/GHSA-67mh-4wv8-2f99\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-a26446024ab210b8", "name": "Vulnerable dependency linkify-it 5.0.0: GHSA-22p9-wv53-3rq4", "shortDescription": {"text": "Vulnerable dependency linkify-it 5.0.0: GHSA-22p9-wv53-3rq4"}, "fullDescription": {"text": "OSV.dev reports `linkify-it` at version `5.0.0` (resolved in `docs/bun.lock`) is affected by GHSA-22p9-wv53-3rq4 (aka CVE-2026-48801).\nNote: `linkify-it` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nLinkifyIt#match scan loop has quadratic algorithmic complexity\n\nAliases: CVE-2026-48801\nAdvisory: https://osv.dev/vulnerability/GHSA-22p9-wv53-3rq4\nFix: upgrade `linkify-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-72ae09e814e9225e", "name": "Vulnerable dependency linkify-it 5.0.0: GHSA-v245-v573-v5vm", "shortDescription": {"text": "Vulnerable dependency linkify-it 5.0.0: GHSA-v245-v573-v5vm"}, "fullDescription": {"text": "OSV.dev reports `linkify-it` at version `5.0.0` (resolved in `docs/bun.lock`) is affected by GHSA-v245-v573-v5vm.\nNote: `linkify-it` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v245-v573-v5vm\nFix: upgrade `linkify-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7ed851b2680410c6", "name": "Vulnerable dependency lodash-es 4.17.22: GHSA-f23m-r3pf-42rh", "shortDescription": {"text": "Vulnerable dependency lodash-es 4.17.22: GHSA-f23m-r3pf-42rh"}, "fullDescription": {"text": "OSV.dev reports `lodash-es` at version `4.17.22` (resolved in `docs/bun.lock`) is affected by GHSA-f23m-r3pf-42rh (aka CVE-2025-13465, CVE-2026-2950).\nNote: `lodash-es` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nlodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`\n\nAliases: CVE-2025-13465, CVE-2026-2950, GHSA-f23m-r3pf-42rh, GHSA-xxjr-mmjv-4gpg\nAdvisory: https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh\nFix: upgrade `lodash-es` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4208ccad857d3060", "name": "Vulnerable dependency lodash-es 4.17.22: GHSA-r5fr-rjxr-66jc", "shortDescription": {"text": "Vulnerable dependency lodash-es 4.17.22: GHSA-r5fr-rjxr-66jc"}, "fullDescription": {"text": "OSV.dev reports `lodash-es` at version `4.17.22` (resolved in `docs/bun.lock`) is affected by GHSA-r5fr-rjxr-66jc (aka CVE-2021-23337, CVE-2026-4800).\nNote: `lodash-es` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nlodash vulnerable to Code Injection via `_.template` imports key names\n\nAliases: CVE-2021-23337, CVE-2026-4800, GHSA-35jh-r3h4-6jhm\nAdvisory: https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc\nFix: upgrade `lodash-es` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3048e345e321e32a", "name": "Vulnerable dependency markdown-it 14.1.0: GHSA-38c4-r59v-3vqw", "shortDescription": {"text": "Vulnerable dependency markdown-it 14.1.0: GHSA-38c4-r59v-3vqw"}, "fullDescription": {"text": "OSV.dev reports `markdown-it` at version `14.1.0` (resolved in `docs/bun.lock`) is affected by GHSA-38c4-r59v-3vqw (aka CVE-2026-2327).\nNote: `markdown-it` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nmarkdown-it is has a Regular Expression Denial of Service (ReDoS)\n\nAliases: CVE-2026-2327\nAdvisory: https://osv.dev/vulnerability/GHSA-38c4-r59v-3vqw\nFix: upgrade `markdown-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b0bcdf712124063e", "name": "Vulnerable dependency markdown-it 14.1.0: GHSA-6v5v-wf23-fmfq", "shortDescription": {"text": "Vulnerable dependency markdown-it 14.1.0: GHSA-6v5v-wf23-fmfq"}, "fullDescription": {"text": "OSV.dev reports `markdown-it` at version `14.1.0` (resolved in `docs/bun.lock`) is affected by GHSA-6v5v-wf23-fmfq.\nNote: `markdown-it` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-6v5v-wf23-fmfq\nFix: upgrade `markdown-it` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-74224f48f5eea0ee", "name": "Vulnerable dependency minimatch 10.1.1: GHSA-23c5-xmqv-rm74", "shortDescription": {"text": "Vulnerable dependency minimatch 10.1.1: GHSA-23c5-xmqv-rm74"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `10.1.1` (resolved in `docs/bun.lock`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions\n\nAliases: CVE-2026-27904\nAdvisory: https://osv.dev/vulnerability/GHSA-23c5-xmqv-rm74\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-da30265ba3ffaafd", "name": "Vulnerable dependency minimatch 10.1.1: GHSA-3ppc-4f35-3m26", "shortDescription": {"text": "Vulnerable dependency minimatch 10.1.1: GHSA-3ppc-4f35-3m26"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `10.1.1` (resolved in `docs/bun.lock`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has a ReDoS via repeated wildcards with non-matching literal in pattern\n\nAliases: CVE-2026-26996\nAdvisory: https://osv.dev/vulnerability/GHSA-3ppc-4f35-3m26\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ff378d2aaf4654c7", "name": "Vulnerable dependency minimatch 10.1.1: GHSA-7r86-cg39-jmmj", "shortDescription": {"text": "Vulnerable dependency minimatch 10.1.1: GHSA-7r86-cg39-jmmj"}, "fullDescription": {"text": "OSV.dev reports `minimatch` at version `10.1.1` (resolved in `docs/bun.lock`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903).\nNote: `minimatch` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nminimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments\n\nAliases: CVE-2026-27903\nAdvisory: https://osv.dev/vulnerability/GHSA-7r86-cg39-jmmj\nFix: upgrade `minimatch` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-65995639c3a75424", "name": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `docs/bun.lock`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\nNote: `postcss` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d2b61b17e63d0c84", "name": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `docs/bun.lock`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\nNote: `postcss` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-067de11778c7b000", "name": "Vulnerable dependency preact 10.28.1: GHSA-36hm-qxxp-pg3m", "shortDescription": {"text": "Vulnerable dependency preact 10.28.1: GHSA-36hm-qxxp-pg3m"}, "fullDescription": {"text": "OSV.dev reports `preact` at version `10.28.1` (resolved in `docs/bun.lock`) is affected by GHSA-36hm-qxxp-pg3m (aka CVE-2026-22028).\nNote: `preact` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPreact has JSON VNode Injection issue\n\nAliases: CVE-2026-22028\nAdvisory: https://osv.dev/vulnerability/GHSA-36hm-qxxp-pg3m\nFix: upgrade `preact` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4d2e0b474519a79d", "name": "Vulnerable dependency rollup 4.54.0: GHSA-mw96-cpmx-2vgc", "shortDescription": {"text": "Vulnerable dependency rollup 4.54.0: GHSA-mw96-cpmx-2vgc"}, "fullDescription": {"text": "OSV.dev reports `rollup` at version `4.54.0` (resolved in `docs/bun.lock`) is affected by GHSA-mw96-cpmx-2vgc.\nNote: `rollup` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mw96-cpmx-2vgc\nFix: upgrade `rollup` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-eb7af4c61120c534", "name": "Vulnerable dependency lodash-es 4.17.21: GHSA-f23m-r3pf-42rh", "shortDescription": {"text": "Vulnerable dependency lodash-es 4.17.21: GHSA-f23m-r3pf-42rh"}, "fullDescription": {"text": "OSV.dev reports `lodash-es` at version `4.17.21` (resolved in `docs/bun.lock`) is affected by GHSA-f23m-r3pf-42rh (aka CVE-2025-13465, CVE-2026-2950).\nNote: `lodash-es` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nlodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`\n\nAliases: CVE-2025-13465, CVE-2026-2950, GHSA-f23m-r3pf-42rh, GHSA-xxjr-mmjv-4gpg\nAdvisory: https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh\nFix: upgrade `lodash-es` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-aa5dd81c81becbf0", "name": "Vulnerable dependency lodash-es 4.17.21: GHSA-r5fr-rjxr-66jc", "shortDescription": {"text": "Vulnerable dependency lodash-es 4.17.21: GHSA-r5fr-rjxr-66jc"}, "fullDescription": {"text": "OSV.dev reports `lodash-es` at version `4.17.21` (resolved in `docs/bun.lock`) is affected by GHSA-r5fr-rjxr-66jc (aka CVE-2021-23337, CVE-2026-4800).\nNote: `lodash-es` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nlodash vulnerable to Code Injection via `_.template` imports key names\n\nAliases: CVE-2021-23337, CVE-2026-4800, GHSA-35jh-r3h4-6jhm\nAdvisory: https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc\nFix: upgrade `lodash-es` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c551a312a19d4b32", "name": "Dependency ai is two or more major versions behind", "shortDescription": {"text": "Dependency ai is two or more major versions behind"}, "fullDescription": {"text": "`ai` is pinned at `5.0.99` in `web/package.json` while the latest release on the npm registry is `7.0.36` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `ai` to `7.0.36`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-461956b7cb09e112", "name": "Dependency diff is a major version behind", "shortDescription": {"text": "Dependency diff is a major version behind"}, "fullDescription": {"text": "`diff` is pinned at `8.0.2` in `web/package.json` while the latest release on the npm registry is `9.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `diff` to `9.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-7edef27cb5011917", "name": "Dependency js-yaml is a major version behind", "shortDescription": {"text": "Dependency js-yaml is a major version behind"}, "fullDescription": {"text": "`js-yaml` is pinned at `4.1.1` in `web/package.json` while the latest release on the npm registry is `5.2.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `js-yaml` to `5.2.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-3b7570e32489e46f", "name": "Dependency lucide-react is a major version behind", "shortDescription": {"text": "Dependency lucide-react is a major version behind"}, "fullDescription": {"text": "`lucide-react` is pinned at `0.561.0` in `vis/package.json` while the latest release on the npm registry is `1.26.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `lucide-react` to `1.26.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-ee979033c0becf23", "name": "Dependency nanoid is a major version behind", "shortDescription": {"text": "Dependency nanoid is a major version behind"}, "fullDescription": {"text": "`nanoid` is pinned at `5.1.6` in `web/package.json` while the latest release on the npm registry is `6.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `nanoid` to `6.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-ec26d8f79d4f1591", "name": "Dangling fetch: POST /api/open-in (vis/src/lib/api.ts:263)", "shortDescription": {"text": "Dangling fetch: POST /api/open-in (vis/src/lib/api.ts:263)"}, "fullDescription": {"text": "`vis/src/lib/api.ts:263` calls `POST /api/open-in` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/open-in`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1abbf23209de6710", "name": "Dangling fetch: POST /api/open-in (web/src/features/chat/open-in-shared.ts:76)", "shortDescription": {"text": "Dangling fetch: POST /api/open-in (web/src/features/chat/open-in-shared.ts:76)"}, "fullDescription": {"text": "`web/src/features/chat/open-in-shared.ts:76` calls `POST /api/open-in` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/open-in`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7e6d161776b758bd", "name": "16 backend endpoints not called by scanned frontend", "shortDescription": {"text": "16 backend endpoints not called by scanned frontend"}, "fullDescription": {"text": "No scanned frontend call matched these backend routes. Sample: GET /statistics, GET /capabilities, GET /scalar, GET /docs, GET /toml, PUT /toml, GET /{session_id}, POST /{session_id}/files + 8 more. This is fine when endpoints serve external clients (mobile apps, SDKs, third-party integrations, server-side webhooks). Otherwise document consumers or remove dead routes."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30755"}, "properties": {"repository": "MoonshotAI/kimi-cli", "repoUrl": "https://github.com/MoonshotAI/kimi-cli", "branch": "main"}, "results": [{"ruleId": "scanner-f9bb4ba2b6754313", "level": "note", "message": {"text": "Possibly dead Python function: do_GET"}, "properties": {"repobilityId": "2d943bb45e4f13bd", "scanner": "scanner-primary", "fingerprint": "f9bb4ba2b6754313", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/telemetry_debug_server.py:60"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ee5e3cf492e5ff9", "level": "note", "message": {"text": "Possibly dead Python function: do_POST"}, "properties": {"repobilityId": "53357410ca9379a9", "scanner": "scanner-primary", "fingerprint": "4ee5e3cf492e5ff9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/telemetry_debug_server.py:66"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a381c8cb0d9f5a73", "level": "note", "message": {"text": "Possibly dead Python function: log_message"}, "properties": {"repobilityId": "965f3150b4af5b2e", "scanner": "scanner-primary", "fingerprint": "a381c8cb0d9f5a73", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/telemetry_debug_server.py:104"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dac84826ae4bd3e2", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "dac84826ae4bd3e2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/local.py:27"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-470bd65887e4d82f", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "470bd65887e4d82f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/__init__.py:16"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea09e0510b24709e", "level": "note", "message": {"text": "Possibly dead Python function: readexactly"}, "properties": {"repobilityId": "c5c6fb2068c86203", "scanner": "scanner-primary", "fingerprint": "ea09e0510b24709e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/__init__.py:59"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-805d5cfa35135509", "level": "note", "message": {"text": "Possibly dead Python function: readuntil"}, "properties": {"repobilityId": "613ae1b784ef98a9", "scanner": "scanner-primary", "fingerprint": "805d5cfa35135509", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/__init__.py:63"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f8b9ca376aa9ca5", "level": "note", "message": {"text": "Possibly dead Python function: can_write_eof"}, "properties": {"repobilityId": "95bd32b05389442e", "scanner": "scanner-primary", "fingerprint": "2f8b9ca376aa9ca5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/__init__.py:72"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8e2ff5d604bfd0df", "level": "note", "message": {"text": "Possibly dead Python function: is_closing"}, "properties": {"repobilityId": "4b7d2654df63487d", "scanner": "scanner-primary", "fingerprint": "8e2ff5d604bfd0df", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/__init__.py:84"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e540463d75b403a7", "level": "note", "message": {"text": "Possibly dead Python function: writelines"}, "properties": {"repobilityId": "68d8d752de5cc6ff", "scanner": "scanner-primary", "fingerprint": "e540463d75b403a7", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/__init__.py:96"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72bceaebeabd014f", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "72bceaebeabd014f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kaos/src/kaos/ssh.py:26"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-213aeda570085709", "level": "note", "message": {"text": "Possibly dead Python function: future_done_callback"}, "properties": {"repobilityId": "6c3572d8af23dcd7", "scanner": "scanner-primary", "fingerprint": "213aeda570085709", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/__init__.py:137"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b53d38f03b92ae5a", "level": "note", "message": {"text": "Possibly dead Python function: validate_content_part"}, "properties": {"repobilityId": "fc36c78a8d2dd851", "scanner": "scanner-primary", "fingerprint": "b53d38f03b92ae5a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/message.py:53"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24a63e61fef5db37", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "24a63e61fef5db37", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/chat_provider/mock.py:17"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d0766414acb6fd83", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "d0766414acb6fd83", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/chat_provider/chaos.py:24"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cef7239894d4c78", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "7cef7239894d4c78", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/chat_provider/kimi.py:50"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f1be0c851356c42", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "5f1be0c851356c42", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/chat_provider/echo/scripted_echo.py:23"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7e4f9aa57e4afb8a", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "7e4f9aa57e4afb8a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/chat_provider/echo/echo.py:21"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2b9599e1f8f1f378", "level": "note", "message": {"text": "Possibly dead Python function: validate_display_block"}, "properties": {"repobilityId": "f1940e8c762d33cd", "scanner": "scanner-primary", "fingerprint": "2b9599e1f8f1f378", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/tooling/__init__.py:72"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86b2a29ebcf72c5c", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "86b2a29ebcf72c5c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/tooling/simple.py:26"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-329b97f3d4a58136", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "329b97f3d4a58136", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/tooling/empty.py:9"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a993dac622784932", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "a993dac622784932", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/contrib/chat_provider/openai_legacy.py:38"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-04c89ee5a9752e12", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "04c89ee5a9752e12", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/contrib/chat_provider/anthropic.py:95"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e7c69f34f5536df3", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "e7c69f34f5536df3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/contrib/chat_provider/openai_responses.py:62"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5b92f3a9eb2098f1", "level": "note", "message": {"text": "Possibly dead Python function: type_check"}, "properties": {"repobilityId": "5cdb07a6a7ce2af2", "scanner": "scanner-primary", "fingerprint": "5b92f3a9eb2098f1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/kosong/src/kosong/contrib/chat_provider/google_genai.py:61"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-af015520ee4ca814", "level": "note", "message": {"text": "Possibly dead Python function: open_browser_after_delay"}, "properties": {"repobilityId": "063119a2253dbe13", "scanner": "scanner-primary", "fingerprint": "af015520ee4ca814", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/vis/app.py:155"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3dc091281667eed8", "level": "note", "message": {"text": "Possibly dead Python function: write_event"}, "properties": {"repobilityId": "4c7fe54a945b2c1e", "scanner": "scanner-primary", "fingerprint": "3dc091281667eed8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/notifications/store.py:79"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f7338e8241f10e1c", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/assistant-message.tsx:44"}, "properties": {"repobilityId": "5993d34bf3b78d82", "scanner": "scanner-primary", "fingerprint": "f7338e8241f10e1c", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/context-viewer/assistant-message.tsx"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-eab748579e3a540e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/context-space-map.tsx:190"}, "properties": {"repobilityId": "41cc1c1c25a4b409", "scanner": "scanner-primary", "fingerprint": "eab748579e3a540e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/context-viewer/context-space-map.tsx"}, "region": {"startLine": 190}}}]}, {"ruleId": "scanner-091dbd45af46f51e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/context-viewer.tsx:103"}, "properties": {"repobilityId": "5813406db7fb3d98", "scanner": "scanner-primary", "fingerprint": "091dbd45af46f51e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/context-viewer/context-viewer.tsx"}, "region": {"startLine": 103}}}]}, {"ruleId": "scanner-c32c91b767edd6ba", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/context-viewer/tool-call-block.tsx:69"}, "properties": {"repobilityId": "9025c5c6ad9e7602", "scanner": "scanner-primary", "fingerprint": "c32c91b767edd6ba", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/context-viewer/tool-call-block.tsx"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-f37364e65c242e91", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/timeline-view.tsx:574"}, "properties": {"repobilityId": "d5fb215ec86494e3", "scanner": "scanner-primary", "fingerprint": "f37364e65c242e91", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/wire-viewer/timeline-view.tsx"}, "region": {"startLine": 574}}}]}, {"ruleId": "scanner-4f977561370e054d", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/wire-event-card.tsx:393"}, "properties": {"repobilityId": "3cb1e2b4f09c64a8", "scanner": "scanner-primary", "fingerprint": "4f977561370e054d", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/wire-viewer/wire-event-card.tsx"}, "region": {"startLine": 393}}}]}, {"ruleId": "scanner-eadd69043eb57703", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/turn-tree.tsx:236"}, "properties": {"repobilityId": "8fc6703c1b20113f", "scanner": "scanner-primary", "fingerprint": "eadd69043eb57703", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/wire-viewer/turn-tree.tsx"}, "region": {"startLine": 236}}}]}, {"ruleId": "scanner-99d4996edbc198d2", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/usage-chart.tsx:113"}, "properties": {"repobilityId": "2f9518c95dc2a47b", "scanner": "scanner-primary", "fingerprint": "99d4996edbc198d2", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/wire-viewer/usage-chart.tsx"}, "region": {"startLine": 113}}}]}, {"ruleId": "scanner-79e004d78ea28a19", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/tool-stats-dashboard.tsx:204"}, "properties": {"repobilityId": "e39902dbc24f2bdc", "scanner": "scanner-primary", "fingerprint": "79e004d78ea28a19", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/wire-viewer/tool-stats-dashboard.tsx"}, "region": {"startLine": 204}}}]}, {"ruleId": "scanner-ec5d0f0a6025c8ac", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/wire-viewer/integrity-check.tsx:188"}, "properties": {"repobilityId": "483f9f0cfb12d3d2", "scanner": "scanner-primary", "fingerprint": "ec5d0f0a6025c8ac", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/wire-viewer/integrity-check.tsx"}, "region": {"startLine": 188}}}]}, {"ruleId": "scanner-0e1d6d5c3d00ab88", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/statistics/statistics-view.tsx:215"}, "properties": {"repobilityId": "f3bb83e0a064db73", "scanner": "scanner-primary", "fingerprint": "0e1d6d5c3d00ab88", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/statistics/statistics-view.tsx"}, "region": {"startLine": 215}}}]}, {"ruleId": "scanner-369b222bbd9d06a0", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/session-picker/session-picker.tsx:125"}, "properties": {"repobilityId": "b06dddf94c6ee946", "scanner": "scanner-primary", "fingerprint": "369b222bbd9d06a0", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/session-picker/session-picker.tsx"}, "region": {"startLine": 125}}}]}, {"ruleId": "scanner-f68f692c188bf181", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/sessions-explorer/session-card.tsx:141"}, "properties": {"repobilityId": "47a942cefed76cf4", "scanner": "scanner-primary", "fingerprint": "f68f692c188bf181", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/sessions-explorer/session-card.tsx"}, "region": {"startLine": 141}}}]}, {"ruleId": "scanner-e057e0c7e9159bb6", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/sessions-explorer/project-group.tsx:43"}, "properties": {"repobilityId": "7b6809866765b3ed", "scanner": "scanner-primary", "fingerprint": "e057e0c7e9159bb6", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/sessions-explorer/project-group.tsx"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-ddc63baec7215f21", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/agents-panel/agent-scope-bar.tsx:133"}, "properties": {"repobilityId": "1537d1f17cdb0874", "scanner": "scanner-primary", "fingerprint": "ddc63baec7215f21", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/agents-panel/agent-scope-bar.tsx"}, "region": {"startLine": 133}}}]}, {"ruleId": "scanner-2a5524ffe279bd8d", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/agents-panel/agents-panel.tsx:230"}, "properties": {"repobilityId": "2b095579ba9b1e79", "scanner": "scanner-primary", "fingerprint": "2a5524ffe279bd8d", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/agents-panel/agents-panel.tsx"}, "region": {"startLine": 230}}}]}, {"ruleId": "scanner-84fba07fe7bd322e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/state-viewer/state-viewer.tsx:232"}, "properties": {"repobilityId": "2e27673b7fa1fd18", "scanner": "scanner-primary", "fingerprint": "84fba07fe7bd322e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/state-viewer/state-viewer.tsx"}, "region": {"startLine": 232}}}]}, {"ruleId": "scanner-d5f1a5178c994670", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 vis/src/features/dual-view/dual-view.tsx:319"}, "properties": {"repobilityId": "0017a17b7dc9ce0b", "scanner": "scanner-primary", "fingerprint": "d5f1a5178c994670", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/features/dual-view/dual-view.tsx"}, "region": {"startLine": 319}}}]}, {"ruleId": "scanner-41cdb8c1e698b895", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/App.tsx:221"}, "properties": {"repobilityId": "0d155048dbf4cc18", "scanner": "scanner-primary", "fingerprint": "41cdb8c1e698b895", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/App.tsx"}, "region": {"startLine": 221}}}]}, {"ruleId": "scanner-d2a5fc02bcebf7d0", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 web/src/components/error-boundary.tsx:65"}, "properties": {"repobilityId": "ddc5ec9ac540b70c", "scanner": "scanner-primary", "fingerprint": "d2a5fc02bcebf7d0", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/components/error-boundary.tsx"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-73f9f33c66942010", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 web/src/components/ui/diff/utils/parse.ts:197"}, "properties": {"repobilityId": "049c0eb6daebc473", "scanner": "scanner-primary", "fingerprint": "73f9f33c66942010", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/components/ui/diff/utils/parse.ts"}, "region": {"startLine": 197}}}]}, {"ruleId": "scanner-3a7c714fee4ef884", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/tool.tsx:412"}, "properties": {"repobilityId": "ac2f4ec8e4474f26", "scanner": "scanner-primary", "fingerprint": "3a7c714fee4ef884", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/components/ai-elements/tool.tsx"}, "region": {"startLine": 412}}}]}, {"ruleId": "scanner-f4fc4137d07181e0", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/subagent-steps.tsx:197"}, "properties": {"repobilityId": "fe5f5234fa449145", "scanner": "scanner-primary", "fingerprint": "f4fc4137d07181e0", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/components/ai-elements/subagent-steps.tsx"}, "region": {"startLine": 197}}}]}, {"ruleId": "scanner-3a12ad82d554b251", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/src/components/ai-elements/code-block.tsx:419"}, "properties": {"repobilityId": "594c9449a0c1ea6a", "scanner": "scanner-primary", "fingerprint": "3a12ad82d554b251", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/components/ai-elements/code-block.tsx"}, "region": {"startLine": 419}}}]}, {"ruleId": "scanner-77e4c73a542d15ce", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/components/ai-elements/prompt-input.tsx:391"}, "properties": {"repobilityId": "c8ab20c1fca94913", "scanner": "scanner-primary", "fingerprint": "77e4c73a542d15ce", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/components/ai-elements/prompt-input.tsx"}, "region": {"startLine": 391}}}]}, {"ruleId": "scanner-295df08f3b799f8a", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/hooks/useSessions.ts:529"}, "properties": {"repobilityId": "f2a5026fd3ca284e", "scanner": "scanner-primary", "fingerprint": "295df08f3b799f8a", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/hooks/useSessions.ts"}, "region": {"startLine": 529}}}]}, {"ruleId": "scanner-cb292aecaf1b7bce", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/hooks/useSessionStream.ts:2165"}, "properties": {"repobilityId": "2df6a751b56fa677", "scanner": "scanner-primary", "fingerprint": "cb292aecaf1b7bce", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/hooks/useSessionStream.ts"}, "region": {"startLine": 2165}}}]}, {"ruleId": "scanner-54a5c713d9529289", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/sessions/sessions.tsx:854"}, "properties": {"repobilityId": "7493a9f214e6f9d9", "scanner": "scanner-primary", "fingerprint": "54a5c713d9529289", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/sessions/sessions.tsx"}, "region": {"startLine": 854}}}]}, {"ruleId": "scanner-600920b58932ba9b", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/sessions/create-session-dialog.tsx:283"}, "properties": {"repobilityId": "b23502a4fc229171", "scanner": "scanner-primary", "fingerprint": "600920b58932ba9b", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/sessions/create-session-dialog.tsx"}, "region": {"startLine": 283}}}]}, {"ruleId": "scanner-983179e85c090e3d", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 web/src/features/chat/chat-workspace-container.tsx:225"}, "properties": {"repobilityId": "ae88b711748b4700", "scanner": "scanner-primary", "fingerprint": "983179e85c090e3d", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/chat-workspace-container.tsx"}, "region": {"startLine": 225}}}]}, {"ruleId": "scanner-74faf4941970760c", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/slash-command-menu.tsx:69"}, "properties": {"repobilityId": "2b04f5df1ded2aac", "scanner": "scanner-primary", "fingerprint": "74faf4941970760c", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/slash-command-menu.tsx"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-0dd5c1fff9ed7d90", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/file-mention-menu.tsx:108"}, "properties": {"repobilityId": "ba3ca96ba8f05f00", "scanner": "scanner-primary", "fingerprint": "0dd5c1fff9ed7d90", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/file-mention-menu.tsx"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-41cfc87d2671899f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/message-search-dialog.tsx:220"}, "properties": {"repobilityId": "891d36a282649b1c", "scanner": "scanner-primary", "fingerprint": "41cfc87d2671899f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/message-search-dialog.tsx"}, "region": {"startLine": 220}}}]}, {"ruleId": "scanner-085133d0106611cd", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/global-config-controls.tsx:229"}, "properties": {"repobilityId": "80f31eb8f8d2844c", "scanner": "scanner-primary", "fingerprint": "085133d0106611cd", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/global-config-controls.tsx"}, "region": {"startLine": 229}}}]}, {"ruleId": "scanner-f5fb8636f6fa37f9", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/session-info-popover.tsx:39"}, "properties": {"repobilityId": "f1b1f6f410a73568", "scanner": "scanner-primary", "fingerprint": "f5fb8636f6fa37f9", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/components/session-info-popover.tsx"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-573f40bfbefa62fb", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/chat-workspace-header.tsx:120"}, "properties": {"repobilityId": "d18d90b07b728722", "scanner": "scanner-primary", "fingerprint": "573f40bfbefa62fb", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/components/chat-workspace-header.tsx"}, "region": {"startLine": 120}}}]}, {"ruleId": "scanner-0b61204e5da5a338", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/open-in-menu.tsx:158"}, "properties": {"repobilityId": "850291498ad755da", "scanner": "scanner-primary", "fingerprint": "0b61204e5da5a338", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/components/open-in-menu.tsx"}, "region": {"startLine": 158}}}]}, {"ruleId": "scanner-bc56d3ddc0a4f224", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/prompt-toolbar/toolbar-queue.tsx:34"}, "properties": {"repobilityId": "5cd4312e6f607d45", "scanner": "scanner-primary", "fingerprint": "bc56d3ddc0a4f224", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/components/prompt-toolbar/toolbar-queue.tsx"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-f39254953228c334", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/chat/components/prompt-toolbar/toolbar-changes.tsx:62"}, "properties": {"repobilityId": "2c54e10781eba584", "scanner": "scanner-primary", "fingerprint": "f39254953228c334", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/components/prompt-toolbar/toolbar-changes.tsx"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-09c9eaf2e2e17727", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/src/features/tool/components/display-content.tsx:499"}, "properties": {"repobilityId": "b902a0b1299352cc", "scanner": "scanner-primary", "fingerprint": "09c9eaf2e2e17727", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/tool/components/display-content.tsx"}, "region": {"startLine": 499}}}]}, {"ruleId": "scanner-d1e89462f2170f01", "level": "error", "message": {"text": "subprocess shell true \u2014 examples/custom-kimi-soul/main.py:79"}, "properties": {"repobilityId": "968f403fc93379bb", "scanner": "scanner-primary", "fingerprint": "d1e89462f2170f01", "layer": "security", "severity": "high", "confidence": 0.55, "tags": ["semgrep", "security", "python", "non-production-context"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/custom-kimi-soul/main.py"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-1306a99a97b9b04e", "level": "error", "message": {"text": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "5b8d95eb55394785", "scanner": "scanner-primary", "fingerprint": "1306a99a97b9b04e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25547"]}}, {"ruleId": "scanner-a51948f377ddc0af", "level": "warning", "message": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "7428168c20b30cf6", "scanner": "scanner-primary", "fingerprint": "a51948f377ddc0af", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0540"]}}, {"ruleId": "scanner-5aee5801ae78687e", "level": "warning", "message": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "3581d609c9744e26", "scanner": "scanner-primary", "fingerprint": "5aee5801ae78687e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41238"]}}, {"ruleId": "scanner-9cadd6545c720b00", "level": "warning", "message": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "7685908ec7f7f550", "scanner": "scanner-primary", "fingerprint": "9cadd6545c720b00", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41239"]}}, {"ruleId": "scanner-7453d68904b00d65", "level": "warning", "message": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "bb77e250d18ac150", "scanner": "scanner-primary", "fingerprint": "7453d68904b00d65", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41240"]}}, {"ruleId": "scanner-c919f95ff610a9a6", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "670bec1ba5530efd", "scanner": "scanner-primary", "fingerprint": "c919f95ff610a9a6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-4b713bf022023539", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "4285f4f5584eb9fa", "scanner": "scanner-primary", "fingerprint": "4b713bf022023539", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-f0733dfdf5d9c272", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "9a064db1ee0373be", "scanner": "scanner-primary", "fingerprint": "f0733dfdf5d9c272", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-6f83abb2dbb664e3", "level": "warning", "message": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "ae9f5ae586d1ac7b", "scanner": "scanner-primary", "fingerprint": "6f83abb2dbb664e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-39q2-94rc-95cp"]}}, {"ruleId": "scanner-53bfe348882a1dd0", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "4ed3c936c8297c83", "scanner": "scanner-primary", "fingerprint": "53bfe348882a1dd0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-b67770921f69d868", "level": "warning", "message": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "d4c5f20848054da1", "scanner": "scanner-primary", "fingerprint": "b67770921f69d868", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cj63-jhhr-wcxv"]}}, {"ruleId": "scanner-14b6c882adb5c61b", "level": "warning", "message": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "d0788b12d7ba3397", "scanner": "scanner-primary", "fingerprint": "14b6c882adb5c61b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cjmm-f4jc-qw8r"]}}, {"ruleId": "scanner-58f2f220d57073b5", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "35267ab16c1a36d1", "scanner": "scanner-primary", "fingerprint": "58f2f220d57073b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-28e51389cfe16b00", "level": "warning", "message": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "4cf8f310c212122c", "scanner": "scanner-primary", "fingerprint": "28e51389cfe16b00", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h8r8-wccr-v5f2"]}}, {"ruleId": "scanner-a065033a41ef2fcd", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "584889b9c8e784c0", "scanner": "scanner-primary", "fingerprint": "a065033a41ef2fcd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-24030aa85f12ee06", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "c13a1629a2ce2392", "scanner": "scanner-primary", "fingerprint": "24030aa85f12ee06", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-452ba5e99e14d171", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "772c6b004b3686b1", "scanner": "scanner-primary", "fingerprint": "452ba5e99e14d171", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-721d8714c39e99c7", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "e846a3ed1f29dc28", "scanner": "scanner-primary", "fingerprint": "721d8714c39e99c7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-15425563dd004da2", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 3.14.2 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "5ff46fbf5d0f99e7", "scanner": "scanner-primary", "fingerprint": "15425563dd004da2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-f4e7fe77a4fb6028", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 3.14.2 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "08c04efc4eecde92", "scanner": "scanner-primary", "fingerprint": "f4e7fe77a4fb6028", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-dffbb586f340d133", "level": "error", "message": {"text": "CVE-2026-48801: linkify-it 5.0.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "b388ce94d1767a7d", "scanner": "scanner-primary", "fingerprint": "dffbb586f340d133", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48801"]}}, {"ruleId": "scanner-fe983cb8fd7d2dbc", "level": "error", "message": {"text": "CVE-2026-59887: linkify-it 5.0.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "56d2cd834d668ac5", "scanner": "scanner-primary", "fingerprint": "fe983cb8fd7d2dbc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59887"]}}, {"ruleId": "scanner-825ebf8c7ecd03b3", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.22 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "3294d02cb2f61825", "scanner": "scanner-primary", "fingerprint": "825ebf8c7ecd03b3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-f56c31c8ee4c133b", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.22 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "0116efe7ff53ec2d", "scanner": "scanner-primary", "fingerprint": "f56c31c8ee4c133b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-74740e3c40dbb188", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.22 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "501074d008b7f16f", "scanner": "scanner-primary", "fingerprint": "74740e3c40dbb188", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-c5a4422eef426d5a", "level": "warning", "message": {"text": "CVE-2026-2327: markdown-it 14.1.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "581f8df45923c996", "scanner": "scanner-primary", "fingerprint": "c5a4422eef426d5a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2327"]}}, {"ruleId": "scanner-274bd60c24a66513", "level": "warning", "message": {"text": "CVE-2026-48988: markdown-it 14.1.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "04957b69e441b680", "scanner": "scanner-primary", "fingerprint": "274bd60c24a66513", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48988"]}}, {"ruleId": "scanner-f193e7523e729b17", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "17eb2ad1f11fe8c4", "scanner": "scanner-primary", "fingerprint": "f193e7523e729b17", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-7ad981d6752f53a5", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "594ef7904959b94b", "scanner": "scanner-primary", "fingerprint": "7ad981d6752f53a5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-9c1fe14fc078af75", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "f2e420b0b0598364", "scanner": "scanner-primary", "fingerprint": "9c1fe14fc078af75", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-ac75420f68bc932c", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "597df56033729cab", "scanner": "scanner-primary", "fingerprint": "ac75420f68bc932c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-80ff5d6936d0b89c", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 10.1.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "1e2f6db91277c6ef", "scanner": "scanner-primary", "fingerprint": "80ff5d6936d0b89c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-0b22220a231959c6", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 10.1.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "dfc4d1925246b86f", "scanner": "scanner-primary", "fingerprint": "0b22220a231959c6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-c48e3ac5488f5624", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 10.1.1 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "d6b6a9044b93647f", "scanner": "scanner-primary", "fingerprint": "c48e3ac5488f5624", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-80d711bc8ff86db7", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 docs/bun.lock"}, "properties": {"repobilityId": "5adc7a1b25e6c3ea", "scanner": "scanner-primary", "fingerprint": "80d711bc8ff86db7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-9f13f1b85af6381e", "level": "warning", "message": {"text": "CVE-2026-22815: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "bf8fbc12565d7e15", "scanner": "scanner-primary", "fingerprint": "9f13f1b85af6381e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-22815"]}}, {"ruleId": "scanner-77955225a12aa136", "level": "warning", "message": {"text": "CVE-2026-34515: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "f7c844cd603d72b2", "scanner": "scanner-primary", "fingerprint": "77955225a12aa136", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34515"]}}, {"ruleId": "scanner-322e954f571d718f", "level": "warning", "message": {"text": "CVE-2026-34516: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "a7094e9184ed89ad", "scanner": "scanner-primary", "fingerprint": "322e954f571d718f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34516"]}}, {"ruleId": "scanner-7ef5abf039de7a1c", "level": "warning", "message": {"text": "CVE-2026-34525: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "891d3fa7b34d2706", "scanner": "scanner-primary", "fingerprint": "7ef5abf039de7a1c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34525"]}}, {"ruleId": "scanner-58bee39f8a77b367", "level": "warning", "message": {"text": "CVE-2026-34993: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "e7977c365bb7bb0f", "scanner": "scanner-primary", "fingerprint": "58bee39f8a77b367", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34993"]}}, {"ruleId": "scanner-befd34523ea2756e", "level": "warning", "message": {"text": "CVE-2026-47265: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "7035166482a6d084", "scanner": "scanner-primary", "fingerprint": "befd34523ea2756e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47265"]}}, {"ruleId": "scanner-4e70d9ab001ae667", "level": "warning", "message": {"text": "CVE-2026-54273: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "af0aae7929b420d3", "scanner": "scanner-primary", "fingerprint": "4e70d9ab001ae667", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54273"]}}, {"ruleId": "scanner-3a753555ff0ec7fd", "level": "warning", "message": {"text": "CVE-2026-54274: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "7e10ded903752976", "scanner": "scanner-primary", "fingerprint": "3a753555ff0ec7fd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54274"]}}, {"ruleId": "scanner-c86cde080336dd7d", "level": "warning", "message": {"text": "CVE-2026-54276: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "4eb50b27324e7d60", "scanner": "scanner-primary", "fingerprint": "c86cde080336dd7d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54276"]}}, {"ruleId": "scanner-58cf8c56e1e09a7c", "level": "warning", "message": {"text": "CVE-2026-54277: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "76d7edda54afad46", "scanner": "scanner-primary", "fingerprint": "58cf8c56e1e09a7c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54277"]}}, {"ruleId": "scanner-8b12accbe4408398", "level": "warning", "message": {"text": "CVE-2026-54278: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "aebcc1b43ac4ed5e", "scanner": "scanner-primary", "fingerprint": "8b12accbe4408398", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54278"]}}, {"ruleId": "scanner-ba57b8dcfa683e0e", "level": "note", "message": {"text": "CVE-2026-34513: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "c025c7013e2d6258", "scanner": "scanner-primary", "fingerprint": "ba57b8dcfa683e0e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34513"]}}, {"ruleId": "scanner-1430a1fa6086b7a5", "level": "note", "message": {"text": "CVE-2026-34514: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "0e26789ce7cfab41", "scanner": "scanner-primary", "fingerprint": "1430a1fa6086b7a5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34514"]}}, {"ruleId": "scanner-c105e19d51abfca3", "level": "note", "message": {"text": "CVE-2026-34517: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "8b625e126d63cdd3", "scanner": "scanner-primary", "fingerprint": "c105e19d51abfca3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34517"]}}, {"ruleId": "scanner-511a1033762f22b2", "level": "note", "message": {"text": "CVE-2026-34518: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "6e4d0d2d8d1bc4f2", "scanner": "scanner-primary", "fingerprint": "511a1033762f22b2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34518"]}}, {"ruleId": "scanner-f9239e6c0e690f7f", "level": "note", "message": {"text": "CVE-2026-34519: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "41c7fa5778d7981d", "scanner": "scanner-primary", "fingerprint": "f9239e6c0e690f7f", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34519"]}}, {"ruleId": "scanner-ba7a27f8cbe9af52", "level": "note", "message": {"text": "CVE-2026-34520: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "9e4aab615a3fb393", "scanner": "scanner-primary", "fingerprint": "ba7a27f8cbe9af52", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34520"]}}, {"ruleId": "scanner-0f66d4480de5e005", "level": "note", "message": {"text": "CVE-2026-50269: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "ecf7a91f3d433ba8", "scanner": "scanner-primary", "fingerprint": "0f66d4480de5e005", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-50269"]}}, {"ruleId": "scanner-4fa9026578dffef7", "level": "note", "message": {"text": "CVE-2026-54275: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "151d3b178324b38a", "scanner": "scanner-primary", "fingerprint": "4fa9026578dffef7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54275"]}}, {"ruleId": "scanner-e980a4024edcfef3", "level": "note", "message": {"text": "CVE-2026-54279: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "151a621396dd496c", "scanner": "scanner-primary", "fingerprint": "e980a4024edcfef3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54279"]}}, {"ruleId": "scanner-eac59cdc990c4ea5", "level": "note", "message": {"text": "CVE-2026-54280: aiohttp 3.13.3 \u2014 uv.lock"}, "properties": {"repobilityId": "79293d0b4dfc10d1", "scanner": "scanner-primary", "fingerprint": "eac59cdc990c4ea5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54280"]}}, {"ruleId": "scanner-e2a13a13b8ae7dcb", "level": "error", "message": {"text": "CVE-2026-27962: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "6776d96b4149a2df", "scanner": "scanner-primary", "fingerprint": "e2a13a13b8ae7dcb", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27962"]}}, {"ruleId": "scanner-0620285b783fef91", "level": "error", "message": {"text": "CVE-2026-28490: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "ca9d6d7ab1577c6e", "scanner": "scanner-primary", "fingerprint": "0620285b783fef91", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28490"]}}, {"ruleId": "scanner-1a033cf8f942048d", "level": "error", "message": {"text": "CVE-2026-28498: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "f38056b38f2b10ef", "scanner": "scanner-primary", "fingerprint": "1a033cf8f942048d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28498"]}}, {"ruleId": "scanner-db2f064a3e3716c5", "level": "error", "message": {"text": "CVE-2026-28802: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "7feebcfd892a9d93", "scanner": "scanner-primary", "fingerprint": "db2f064a3e3716c5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28802"]}}, {"ruleId": "scanner-e28b78dfff1db76f", "level": "warning", "message": {"text": "CVE-2025-68158: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "c88cf56771eea418", "scanner": "scanner-primary", "fingerprint": "e28b78dfff1db76f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-68158"]}}, {"ruleId": "scanner-b9666b65fae647c2", "level": "warning", "message": {"text": "CVE-2026-41425: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "bd82b013226bd68e", "scanner": "scanner-primary", "fingerprint": "b9666b65fae647c2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41425"]}}, {"ruleId": "scanner-102cb04253319eba", "level": "warning", "message": {"text": "CVE-2026-41479: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "16fb3c11745eec82", "scanner": "scanner-primary", "fingerprint": "102cb04253319eba", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41479"]}}, {"ruleId": "scanner-f2c049fb972fa3bc", "level": "warning", "message": {"text": "CVE-2026-44681: authlib 1.6.5 \u2014 uv.lock"}, "properties": {"repobilityId": "cb4850a90722fd1c", "scanner": "scanner-primary", "fingerprint": "f2c049fb972fa3bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44681"]}}, {"ruleId": "scanner-5e1d70859a649eeb", "level": "error", "message": {"text": "CVE-2026-26007: cryptography 46.0.2 \u2014 uv.lock"}, "properties": {"repobilityId": "c1cdfd1bd1a9c129", "scanner": "scanner-primary", "fingerprint": "5e1d70859a649eeb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26007"]}}, {"ruleId": "scanner-d2a69e8acd688649", "level": "error", "message": {"text": "GHSA-537c-gmf6-5ccf: cryptography 46.0.2 \u2014 uv.lock"}, "properties": {"repobilityId": "a6d76544a3204701", "scanner": "scanner-primary", "fingerprint": "d2a69e8acd688649", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-537c-gmf6-5ccf"]}}, {"ruleId": "scanner-2d8a93ade5b30c3f", "level": "warning", "message": {"text": "CVE-2026-39892: cryptography 46.0.2 \u2014 uv.lock"}, "properties": {"repobilityId": "5bdcf27af4f6891e", "scanner": "scanner-primary", "fingerprint": "2d8a93ade5b30c3f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39892"]}}, {"ruleId": "scanner-ecc0cb594b7e601d", "level": "note", "message": {"text": "CVE-2026-34073: cryptography 46.0.2 \u2014 uv.lock"}, "properties": {"repobilityId": "5f0617f1e8bff253", "scanner": "scanner-primary", "fingerprint": "ecc0cb594b7e601d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-34073"]}}, {"ruleId": "scanner-54431d598451332d", "level": "error", "message": {"text": "CVE-2026-42215: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "f96f06ae122153be", "scanner": "scanner-primary", "fingerprint": "54431d598451332d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42215"]}}, {"ruleId": "scanner-c32c52607d4675e9", "level": "error", "message": {"text": "CVE-2026-42284: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "930497347244c59a", "scanner": "scanner-primary", "fingerprint": "c32c52607d4675e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42284"]}}, {"ruleId": "scanner-5110ca4600327972", "level": "error", "message": {"text": "CVE-2026-44243: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "4968ac9f08f5ac5f", "scanner": "scanner-primary", "fingerprint": "5110ca4600327972", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44243"]}}, {"ruleId": "scanner-6387eae900792e19", "level": "error", "message": {"text": "CVE-2026-44244: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "98f9aa3ad2062e30", "scanner": "scanner-primary", "fingerprint": "6387eae900792e19", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44244"]}}, {"ruleId": "scanner-cb47971fe5df0456", "level": "error", "message": {"text": "GHSA-2f96-g7mh-g2hx: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "84b34d26a45c4c6f", "scanner": "scanner-primary", "fingerprint": "cb47971fe5df0456", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-2f96-g7mh-g2hx"]}}, {"ruleId": "scanner-10584ccd6a28c305", "level": "error", "message": {"text": "GHSA-956x-8gvw-wg5v: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "801fa6bcc6262f01", "scanner": "scanner-primary", "fingerprint": "10584ccd6a28c305", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-956x-8gvw-wg5v"]}}, {"ruleId": "scanner-650f5f0e55ac3ca2", "level": "error", "message": {"text": "GHSA-mv93-w799-cj2w: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "3301e567c92515e1", "scanner": "scanner-primary", "fingerprint": "650f5f0e55ac3ca2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mv93-w799-cj2w"]}}, {"ruleId": "scanner-b7c4a24e724685d3", "level": "error", "message": {"text": "GHSA-rwj8-pgh3-r573: gitpython 3.1.45 \u2014 uv.lock"}, "properties": {"repobilityId": "3cd0bfbd81eeb7bd", "scanner": "scanner-primary", "fingerprint": "b7c4a24e724685d3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-rwj8-pgh3-r573"]}}, {"ruleId": "scanner-403e5905f1ebc50e", "level": "warning", "message": {"text": "CVE-2026-45409: idna 3.10 \u2014 uv.lock"}, "properties": {"repobilityId": "c2f0a4d128834c6b", "scanner": "scanner-primary", "fingerprint": "403e5905f1ebc50e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45409"]}}, {"ruleId": "scanner-6cc76acfbf412673", "level": "error", "message": {"text": "CVE-2026-41066: lxml 6.0.2 \u2014 uv.lock"}, "properties": {"repobilityId": "77f44c11028da546", "scanner": "scanner-primary", "fingerprint": "6cc76acfbf412673", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41066"]}}, {"ruleId": "scanner-2b96861f5b27d344", "level": "error", "message": {"text": "CVE-2026-49825: lxml-html-clean 0.4.3 \u2014 uv.lock"}, "properties": {"repobilityId": "cb0179b585683387", "scanner": "scanner-primary", "fingerprint": "2b96861f5b27d344", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49825"]}}, {"ruleId": "scanner-cd83ec549d525a8d", "level": "warning", "message": {"text": "CVE-2026-28348: lxml-html-clean 0.4.3 \u2014 uv.lock"}, "properties": {"repobilityId": "51d81b1d8c4c62fa", "scanner": "scanner-primary", "fingerprint": "cd83ec549d525a8d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28348"]}}, {"ruleId": "scanner-5d7f06bb3210ba20", "level": "warning", "message": {"text": "CVE-2026-28350: lxml-html-clean 0.4.3 \u2014 uv.lock"}, "properties": {"repobilityId": "edf0564e0234577a", "scanner": "scanner-primary", "fingerprint": "5d7f06bb3210ba20", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28350"]}}, {"ruleId": "scanner-393a17c0d4dd691c", "level": "error", "message": {"text": "CVE-2026-52869: mcp 1.27.1 \u2014 uv.lock"}, "properties": {"repobilityId": "1c41447db45d918e", "scanner": "scanner-primary", "fingerprint": "393a17c0d4dd691c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-52869"]}}, {"ruleId": "scanner-df6a7df895b9a551", "level": "error", "message": {"text": "CVE-2026-52870: mcp 1.27.1 \u2014 uv.lock"}, "properties": {"repobilityId": "542b0ca2f52ed8fe", "scanner": "scanner-primary", "fingerprint": "df6a7df895b9a551", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-52870"]}}, {"ruleId": "scanner-62dbff4a083928b1", "level": "error", "message": {"text": "CVE-2026-59950: mcp 1.27.1 \u2014 uv.lock"}, "properties": {"repobilityId": "72bb20114a795fd4", "scanner": "scanner-primary", "fingerprint": "62dbff4a083928b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59950"]}}, {"ruleId": "scanner-9737b39b2a7551a7", "level": "error", "message": {"text": "CVE-2026-54058: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "ad6b9031837af19d", "scanner": "scanner-primary", "fingerprint": "9737b39b2a7551a7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54058"]}}, {"ruleId": "scanner-92f5952034493030", "level": "error", "message": {"text": "CVE-2026-54059: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "4fd6401261d7b673", "scanner": "scanner-primary", "fingerprint": "92f5952034493030", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54059"]}}, {"ruleId": "scanner-1ff9f66ba430e736", "level": "error", "message": {"text": "CVE-2026-54060: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "460c3dd8de6beb2a", "scanner": "scanner-primary", "fingerprint": "1ff9f66ba430e736", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54060"]}}, {"ruleId": "scanner-6c85e0cc00b91ed7", "level": "error", "message": {"text": "CVE-2026-55379: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "41cc2c5cfa0ab3e7", "scanner": "scanner-primary", "fingerprint": "6c85e0cc00b91ed7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55379"]}}, {"ruleId": "scanner-0b2568d3cbcb767f", "level": "error", "message": {"text": "CVE-2026-55380: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "f90615a9989f57bc", "scanner": "scanner-primary", "fingerprint": "0b2568d3cbcb767f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55380"]}}, {"ruleId": "scanner-8f83941fee577645", "level": "error", "message": {"text": "CVE-2026-59197: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "b4fa5d22b574d8f3", "scanner": "scanner-primary", "fingerprint": "8f83941fee577645", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59197"]}}, {"ruleId": "scanner-5e268c1133819fbf", "level": "error", "message": {"text": "CVE-2026-59199: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "1c3986517b685ff4", "scanner": "scanner-primary", "fingerprint": "5e268c1133819fbf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59199"]}}, {"ruleId": "scanner-8297d3abcb7190eb", "level": "error", "message": {"text": "CVE-2026-59200: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "278253220173941f", "scanner": "scanner-primary", "fingerprint": "8297d3abcb7190eb", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59200"]}}, {"ruleId": "scanner-3f4c42d809f3d4d4", "level": "error", "message": {"text": "CVE-2026-59204: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "ad08bb4154b8a7b2", "scanner": "scanner-primary", "fingerprint": "3f4c42d809f3d4d4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59204"]}}, {"ruleId": "scanner-4254579d8b441828", "level": "error", "message": {"text": "CVE-2026-59205: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "cc9b1626466d8587", "scanner": "scanner-primary", "fingerprint": "4254579d8b441828", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59205"]}}, {"ruleId": "scanner-eee5d94fc3e70870", "level": "warning", "message": {"text": "CVE-2026-55798: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "d0d151cc4785c963", "scanner": "scanner-primary", "fingerprint": "eee5d94fc3e70870", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-55798"]}}, {"ruleId": "scanner-027941125df659f6", "level": "warning", "message": {"text": "CVE-2026-59198: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "4b734d961778b7aa", "scanner": "scanner-primary", "fingerprint": "027941125df659f6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59198"]}}, {"ruleId": "scanner-bff8feb430b5016c", "level": "warning", "message": {"text": "CVE-2026-59203: pillow 12.2.0 \u2014 uv.lock"}, "properties": {"repobilityId": "23f54ff1326a45d7", "scanner": "scanner-primary", "fingerprint": "bff8feb430b5016c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59203"]}}, {"ruleId": "scanner-a66a46b30aafdf4e", "level": "error", "message": {"text": "CVE-2026-23490: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "6b070504fcdbd211", "scanner": "scanner-primary", "fingerprint": "a66a46b30aafdf4e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-23490"]}}, {"ruleId": "scanner-eaf386c6a405e5a9", "level": "error", "message": {"text": "CVE-2026-30922: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "6c9ab345c7ba843c", "scanner": "scanner-primary", "fingerprint": "eaf386c6a405e5a9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30922"]}}, {"ruleId": "scanner-3b16f1d147b41ab9", "level": "error", "message": {"text": "CVE-2026-59885: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "01feb8e00c6b8d6d", "scanner": "scanner-primary", "fingerprint": "3b16f1d147b41ab9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59885"]}}, {"ruleId": "scanner-f56dfa97d69c0517", "level": "error", "message": {"text": "CVE-2026-59886: pyasn1 0.6.1 \u2014 uv.lock"}, "properties": {"repobilityId": "f14e1a039e252f5b", "scanner": "scanner-primary", "fingerprint": "f56dfa97d69c0517", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59886"]}}, {"ruleId": "scanner-0da8a15114591082", "level": "note", "message": {"text": "CVE-2026-4539: pygments 2.19.2 \u2014 uv.lock"}, "properties": {"repobilityId": "f9fcbb5336951446", "scanner": "scanner-primary", "fingerprint": "0da8a15114591082", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4539"]}}, {"ruleId": "scanner-6514fbdcfaa9204b", "level": "error", "message": {"text": "CVE-2026-48526: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "5c15467f51394509", "scanner": "scanner-primary", "fingerprint": "6514fbdcfaa9204b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48526"]}}, {"ruleId": "scanner-10d45d6df7a6f197", "level": "warning", "message": {"text": "CVE-2026-48522: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "398f7c0886f6723a", "scanner": "scanner-primary", "fingerprint": "10d45d6df7a6f197", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48522"]}}, {"ruleId": "scanner-5728cdec0dc11919", "level": "warning", "message": {"text": "CVE-2026-48523: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "626f80e71164bc6f", "scanner": "scanner-primary", "fingerprint": "5728cdec0dc11919", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48523"]}}, {"ruleId": "scanner-4ba6012c73817cff", "level": "warning", "message": {"text": "CVE-2026-48525: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "ac36236fcc88958d", "scanner": "scanner-primary", "fingerprint": "4ba6012c73817cff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48525"]}}, {"ruleId": "scanner-898e5e1bfb2fa7db", "level": "note", "message": {"text": "CVE-2026-48524: pyjwt 2.12.1 \u2014 uv.lock"}, "properties": {"repobilityId": "11b232edb016b81d", "scanner": "scanner-primary", "fingerprint": "898e5e1bfb2fa7db", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48524"]}}, {"ruleId": "scanner-b549bf95b003cf48", "level": "warning", "message": {"text": "CVE-2026-28684: python-dotenv 1.2.1 \u2014 uv.lock"}, "properties": {"repobilityId": "e1ca1360dfe2097c", "scanner": "scanner-primary", "fingerprint": "b549bf95b003cf48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-28684"]}}, {"ruleId": "scanner-a46c3e2c18f75245", "level": "error", "message": {"text": "CVE-2026-24486: python-multipart 0.0.20 \u2014 uv.lock"}, "properties": {"repobilityId": "3827b6838d8e33af", "scanner": "scanner-primary", "fingerprint": "a46c3e2c18f75245", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24486"]}}, {"ruleId": "scanner-d1caad244fd2a309", "level": "error", "message": {"text": "CVE-2026-42561: python-multipart 0.0.20 \u2014 uv.lock"}, "properties": {"repobilityId": "01c79a8395fad1cf", "scanner": "scanner-primary", "fingerprint": "d1caad244fd2a309", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42561"]}}, {"ruleId": "scanner-b217658f9afadfa5", "level": "error", "message": {"text": "CVE-2026-53539: python-multipart 0.0.20 \u2014 uv.lock"}, "properties": {"repobilityId": "25b2742cc7a21766", "scanner": "scanner-primary", "fingerprint": "b217658f9afadfa5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53539"]}}, {"ruleId": "scanner-0651fe3acb9d9b53", "level": "warning", "message": {"text": "CVE-2026-40347: python-multipart 0.0.20 \u2014 uv.lock"}, "properties": {"repobilityId": "680bb151a8e1f602", "scanner": "scanner-primary", "fingerprint": "0651fe3acb9d9b53", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-40347"]}}, {"ruleId": "scanner-6989ea5c3149368a", "level": "note", "message": {"text": "CVE-2026-53537: python-multipart 0.0.20 \u2014 uv.lock"}, "properties": {"repobilityId": "f480cda055939429", "scanner": "scanner-primary", "fingerprint": "6989ea5c3149368a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53537"]}}, {"ruleId": "scanner-89f71c3ba44f9ad6", "level": "note", "message": {"text": "CVE-2026-53538: python-multipart 0.0.20 \u2014 uv.lock"}, "properties": {"repobilityId": "2458c0fb8d686551", "scanner": "scanner-primary", "fingerprint": "89f71c3ba44f9ad6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53538"]}}, {"ruleId": "scanner-ce31dd15888fefca", "level": "note", "message": {"text": "CVE-2026-53540: python-multipart 0.0.20 \u2014 uv.lock"}, "properties": {"repobilityId": "68c69c7c120812e6", "scanner": "scanner-primary", "fingerprint": "ce31dd15888fefca", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53540"]}}, {"ruleId": "scanner-f0bc6a832539e0bf", "level": "warning", "message": {"text": "CVE-2026-25645: requests 2.32.5 \u2014 uv.lock"}, "properties": {"repobilityId": "b5480ea7888fdcde", "scanner": "scanner-primary", "fingerprint": "f0bc6a832539e0bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25645"]}}, {"ruleId": "scanner-a0a3fca4e88f57a5", "level": "error", "message": {"text": "CVE-2025-62727: starlette 0.48.0 \u2014 uv.lock"}, "properties": {"repobilityId": "c25ea36e930d4897", "scanner": "scanner-primary", "fingerprint": "a0a3fca4e88f57a5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-62727"]}}, {"ruleId": "scanner-469ff7519151f326", "level": "error", "message": {"text": "CVE-2026-48818: starlette 0.48.0 \u2014 uv.lock"}, "properties": {"repobilityId": "5fd9b65620eff6b1", "scanner": "scanner-primary", "fingerprint": "469ff7519151f326", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48818"]}}, {"ruleId": "scanner-a275dfce4ece1a3e", "level": "error", "message": {"text": "CVE-2026-54283: starlette 0.48.0 \u2014 uv.lock"}, "properties": {"repobilityId": "a28cb20663a761ec", "scanner": "scanner-primary", "fingerprint": "a275dfce4ece1a3e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54283"]}}, {"ruleId": "scanner-81f16d9c11134448", "level": "warning", "message": {"text": "CVE-2026-48710: starlette 0.48.0 \u2014 uv.lock"}, "properties": {"repobilityId": "e8ddf94c396d6dd1", "scanner": "scanner-primary", "fingerprint": "81f16d9c11134448", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48710"]}}, {"ruleId": "scanner-9290c3728bbbc080", "level": "warning", "message": {"text": "CVE-2026-48817: starlette 0.48.0 \u2014 uv.lock"}, "properties": {"repobilityId": "315c33072892be6b", "scanner": "scanner-primary", "fingerprint": "9290c3728bbbc080", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48817"]}}, {"ruleId": "scanner-9815506a5fd59a31", "level": "note", "message": {"text": "CVE-2026-54282: starlette 0.48.0 \u2014 uv.lock"}, "properties": {"repobilityId": "9b07991a62551363", "scanner": "scanner-primary", "fingerprint": "9815506a5fd59a31", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54282"]}}, {"ruleId": "scanner-5ce2e929f54e2a70", "level": "error", "message": {"text": "CVE-2025-66418: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "dcb7e0bb7988e04d", "scanner": "scanner-primary", "fingerprint": "5ce2e929f54e2a70", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66418"]}}, {"ruleId": "scanner-b32d2265f744fa8b", "level": "error", "message": {"text": "CVE-2025-66471: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "0c097a3351bee8fd", "scanner": "scanner-primary", "fingerprint": "b32d2265f744fa8b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-66471"]}}, {"ruleId": "scanner-e01e826fca9ae59b", "level": "error", "message": {"text": "CVE-2026-21441: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "2c59e72d5030b432", "scanner": "scanner-primary", "fingerprint": "e01e826fca9ae59b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-21441"]}}, {"ruleId": "scanner-79d12b66c3169372", "level": "error", "message": {"text": "CVE-2026-44431: urllib3 2.5.0 \u2014 uv.lock"}, "properties": {"repobilityId": "3621668d4ee670ac", "scanner": "scanner-primary", "fingerprint": "79d12b66c3169372", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44431"]}}, {"ruleId": "scanner-c38d176017a7d97d", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.29.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "a045d60ba000bd09", "scanner": "scanner-primary", "fingerprint": "c38d176017a7d97d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-107a662d2fb41a27", "level": "error", "message": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "44cdfc006b6f756c", "scanner": "scanner-primary", "fingerprint": "107a662d2fb41a27", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29087"]}}, {"ruleId": "scanner-7fcc3811554042e3", "level": "warning", "message": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "2f9a261c16670e7b", "scanner": "scanner-primary", "fingerprint": "7fcc3811554042e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39406"]}}, {"ruleId": "scanner-8c9631d6ae9b64db", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "d36b6c638966b8ee", "scanner": "scanner-primary", "fingerprint": "8c9631d6ae9b64db", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-0f89c2515ddb3c0e", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "8e1c21be5ef9d90c", "scanner": "scanner-primary", "fingerprint": "0f89c2515ddb3c0e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-b4cc352c5ed57ff9", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 5.0.4 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "f556916f14568130", "scanner": "scanner-primary", "fingerprint": "b4cc352c5ed57ff9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-79926b04bb9dc553", "level": "warning", "message": {"text": "CVE-2026-33750: brace-expansion 5.0.4 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "c33d10557194a08a", "scanner": "scanner-primary", "fingerprint": "79926b04bb9dc553", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33750"]}}, {"ruleId": "scanner-57a0947952533fa5", "level": "warning", "message": {"text": "CVE-2026-45149: brace-expansion 5.0.4 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "58b8bf6a52ebf522", "scanner": "scanner-primary", "fingerprint": "57a0947952533fa5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45149"]}}, {"ruleId": "scanner-6948ec052945adbd", "level": "note", "message": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "3b915c267337a235", "scanner": "scanner-primary", "fingerprint": "6948ec052945adbd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-g7r4-m6w7-qqqr"]}}, {"ruleId": "scanner-3dd5566d8502f6b8", "level": "error", "message": {"text": "CVE-2026-30827: express-rate-limit 8.2.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "86f622e1e0120d46", "scanner": "scanner-primary", "fingerprint": "3dd5566d8502f6b8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-30827"]}}, {"ruleId": "scanner-4268959e22171d57", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "bcfa5d7763e16351", "scanner": "scanner-primary", "fingerprint": "4268959e22171d57", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-30c88963157ac2d2", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "4ef08645a04e8a72", "scanner": "scanner-primary", "fingerprint": "30c88963157ac2d2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-06d4fa2851ae629e", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "cc7214df5e88325a", "scanner": "scanner-primary", "fingerprint": "06d4fa2851ae629e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-0108b600cdc0fd59", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "82d10deb8c253e7f", "scanner": "scanner-primary", "fingerprint": "0108b600cdc0fd59", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-88b5ec286643f49a", "level": "error", "message": {"text": "CVE-2026-29045: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "5c9938e56546b852", "scanner": "scanner-primary", "fingerprint": "88b5ec286643f49a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29045"]}}, {"ruleId": "scanner-4487a6e72f1d1bf3", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "02ee7a79b01847d7", "scanner": "scanner-primary", "fingerprint": "4487a6e72f1d1bf3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-d1d3a2339543d00c", "level": "warning", "message": {"text": "CVE-2026-29085: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "05d702523b5962a5", "scanner": "scanner-primary", "fingerprint": "d1d3a2339543d00c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29085"]}}, {"ruleId": "scanner-fdf242442712363d", "level": "warning", "message": {"text": "CVE-2026-29086: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "523bbb7764fbf2d2", "scanner": "scanner-primary", "fingerprint": "fdf242442712363d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29086"]}}, {"ruleId": "scanner-d13e7c997311b14a", "level": "warning", "message": {"text": "CVE-2026-39407: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "71646090ab2f0242", "scanner": "scanner-primary", "fingerprint": "d13e7c997311b14a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39407"]}}, {"ruleId": "scanner-c63d710368013501", "level": "warning", "message": {"text": "CVE-2026-39408: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "bef30915f4b65b9a", "scanner": "scanner-primary", "fingerprint": "c63d710368013501", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39408"]}}, {"ruleId": "scanner-8adb77bfe044dffc", "level": "warning", "message": {"text": "CVE-2026-39409: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "396d5c55102520a5", "scanner": "scanner-primary", "fingerprint": "8adb77bfe044dffc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39409"]}}, {"ruleId": "scanner-c9e3a43ab1c8dd1c", "level": "warning", "message": {"text": "CVE-2026-39410: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "28575ad439d87666", "scanner": "scanner-primary", "fingerprint": "c9e3a43ab1c8dd1c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39410"]}}, {"ruleId": "scanner-17b86a53ea9b7ea1", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "0855b27250fb8a76", "scanner": "scanner-primary", "fingerprint": "17b86a53ea9b7ea1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-0067293f3f6ea463", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "dbebab1ef04c6be1", "scanner": "scanner-primary", "fingerprint": "0067293f3f6ea463", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-7b1e249ab5ae2a08", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "0e54df51213d3dd8", "scanner": "scanner-primary", "fingerprint": "7b1e249ab5ae2a08", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-2acf26e5069e9142", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "182df4f384ffb582", "scanner": "scanner-primary", "fingerprint": "2acf26e5069e9142", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-b53e3fc75c770005", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "596aa7cebfd86a08", "scanner": "scanner-primary", "fingerprint": "b53e3fc75c770005", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-75e408356666940a", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "f092c8b20f174270", "scanner": "scanner-primary", "fingerprint": "75e408356666940a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-3100ac49c2c74748", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "a7637b5ac5155398", "scanner": "scanner-primary", "fingerprint": "3100ac49c2c74748", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-b36074f92b29ef1f", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "55bc567bd7cc1bcd", "scanner": "scanner-primary", "fingerprint": "b36074f92b29ef1f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-a504bfd6b249a689", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "0ed729969653ba7c", "scanner": "scanner-primary", "fingerprint": "a504bfd6b249a689", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-164d47f20399a832", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "380a560226b55684", "scanner": "scanner-primary", "fingerprint": "164d47f20399a832", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-e2af7995f9414b8a", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "5b32a5dbba39898e", "scanner": "scanner-primary", "fingerprint": "e2af7995f9414b8a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-93c094f8e0739c71", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "4c01fed92660ece2", "scanner": "scanner-primary", "fingerprint": "93c094f8e0739c71", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-f24bcc38a1284694", "level": "warning", "message": {"text": "CVE-2026-56761: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "a52c258d4f481641", "scanner": "scanner-primary", "fingerprint": "f24bcc38a1284694", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-56761"]}}, {"ruleId": "scanner-5c346faa63ee483a", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "ab97fa7efe0aeb6e", "scanner": "scanner-primary", "fingerprint": "5c346faa63ee483a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-753728d22037fe15", "level": "warning", "message": {"text": "CVE-2026-59896: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "a3c9f9160adf29ee", "scanner": "scanner-primary", "fingerprint": "753728d22037fe15", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59896"]}}, {"ruleId": "scanner-4580e474aa4c4e08", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "c3df7c5b2d2a204f", "scanner": "scanner-primary", "fingerprint": "4580e474aa4c4e08", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-2bff54afcabe5429", "level": "warning", "message": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "0f73baeaee2eae92", "scanner": "scanner-primary", "fingerprint": "2bff54afcabe5429", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-26pp-8wgv-hjvm"]}}, {"ruleId": "scanner-075abf73c8344301", "level": "warning", "message": {"text": "GHSA-v8w9-8mx6-g223: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "fa5ac2166d796b30", "scanner": "scanner-primary", "fingerprint": "075abf73c8344301", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-v8w9-8mx6-g223"]}}, {"ruleId": "scanner-7126e4092fbad58d", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.12.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "53dcc15a012f863f", "scanner": "scanner-primary", "fingerprint": "7126e4092fbad58d", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-23a525950146b86d", "level": "warning", "message": {"text": "CVE-2026-42338: ip-address 10.0.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "3c33a78c36f723e3", "scanner": "scanner-primary", "fingerprint": "23a525950146b86d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42338"]}}, {"ruleId": "scanner-df8a2c547785f1b9", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "bfe21129ea156e5f", "scanner": "scanner-primary", "fingerprint": "df8a2c547785f1b9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-44562751a63d30bc", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "c83d83bc655df904", "scanner": "scanner-primary", "fingerprint": "44562751a63d30bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-ca42b4dbcd015428", "level": "error", "message": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "62892647ff5a4066", "scanner": "scanner-primary", "fingerprint": "ca42b4dbcd015428", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4926"]}}, {"ruleId": "scanner-c577108a7764d391", "level": "warning", "message": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "a1c05be4b0f69b2d", "scanner": "scanner-primary", "fingerprint": "c577108a7764d391", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4923"]}}, {"ruleId": "scanner-efebd015f93ca5d6", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "30d4155433142d5a", "scanner": "scanner-primary", "fingerprint": "efebd015f93ca5d6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-b281200026504e4f", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "3a77223924860d2f", "scanner": "scanner-primary", "fingerprint": "b281200026504e4f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-5bbb91f82589dcc3", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "30d4155433142d5a", "scanner": "scanner-primary", "fingerprint": "5bbb91f82589dcc3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-e2a37be63feebaaf", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "3a77223924860d2f", "scanner": "scanner-primary", "fingerprint": "e2a37be63feebaaf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-fa6e52f30ee550c2", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "352438b79320a00c", "scanner": "scanner-primary", "fingerprint": "fa6e52f30ee550c2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-3c5b2d1395b25db8", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.15.0 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "75941398c7d1fb87", "scanner": "scanner-primary", "fingerprint": "3c5b2d1395b25db8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-925f0a6961ff4942", "level": "error", "message": {"text": "CVE-2026-39363: vite 7.3.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "cb316e2e2a2f71e3", "scanner": "scanner-primary", "fingerprint": "925f0a6961ff4942", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39363"]}}, {"ruleId": "scanner-dae9ee1dc677bbad", "level": "error", "message": {"text": "CVE-2026-39364: vite 7.3.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "54d30b7498797359", "scanner": "scanner-primary", "fingerprint": "dae9ee1dc677bbad", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39364"]}}, {"ruleId": "scanner-c5f7f83a25ebd581", "level": "error", "message": {"text": "CVE-2026-53571: vite 7.3.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "4de4248e18b0e81e", "scanner": "scanner-primary", "fingerprint": "c5f7f83a25ebd581", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53571"]}}, {"ruleId": "scanner-27780c5a9a52d03c", "level": "warning", "message": {"text": "CVE-2026-39365: vite 7.3.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "707f3894d04eebf0", "scanner": "scanner-primary", "fingerprint": "27780c5a9a52d03c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39365"]}}, {"ruleId": "scanner-72745f95799ce14e", "level": "warning", "message": {"text": "CVE-2026-53632: vite 7.3.1 \u2014 vis/package-lock.json"}, "properties": {"repobilityId": "2ddd1f084b61b30f", "scanner": "scanner-primary", "fingerprint": "72745f95799ce14e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-7210ec2587942dd7", "level": "note", "message": {"text": "CVE-2026-8769: @ai-sdk/provider-utils 3.0.20 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "5a72892407578b89", "scanner": "scanner-primary", "fingerprint": "7210ec2587942dd7", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8769"]}}, {"ruleId": "scanner-b196e4a3e2a3c1d6", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.28.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e337ab01124cc467", "scanner": "scanner-primary", "fingerprint": "b196e4a3e2a3c1d6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-0bab4e876461f561", "level": "error", "message": {"text": "CVE-2026-29087: @hono/node-server 1.19.9 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "3a7251f8318b2348", "scanner": "scanner-primary", "fingerprint": "0bab4e876461f561", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29087"]}}, {"ruleId": "scanner-4b547ec73919cb7a", "level": "warning", "message": {"text": "CVE-2026-39406: @hono/node-server 1.19.9 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "42a2a2cff7b3d02c", "scanner": "scanner-primary", "fingerprint": "4b547ec73919cb7a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39406"]}}, {"ruleId": "scanner-7d075d79a112d77f", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.9 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "5ec6bf8145d77a1c", "scanner": "scanner-primary", "fingerprint": "7d075d79a112d77f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-10c4ef93b1c765e6", "level": "error", "message": {"text": "CVE-2026-25547: @isaacs/brace-expansion 5.0.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "91d0824aa62b35d4", "scanner": "scanner-primary", "fingerprint": "10c4ef93b1c765e6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25547"]}}, {"ruleId": "scanner-cf0e2dd25b161941", "level": "error", "message": {"text": "CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "9e1e5518c013f473", "scanner": "scanner-primary", "fingerprint": "cf0e2dd25b161941", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-25536"]}}, {"ruleId": "scanner-fc895e164bc4ceb2", "level": "warning", "message": {"text": "CVE-2025-69873: ajv 8.17.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "04ac43565b486fad", "scanner": "scanner-primary", "fingerprint": "fc895e164bc4ceb2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-69873"]}}, {"ruleId": "scanner-1acbe20ab940f1e2", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "c7d92de9e080f62b", "scanner": "scanner-primary", "fingerprint": "1acbe20ab940f1e2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-7d3312872ada341d", "level": "warning", "message": {"text": "CVE-2026-0540: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "f715cab783d99349", "scanner": "scanner-primary", "fingerprint": "7d3312872ada341d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-0540"]}}, {"ruleId": "scanner-ecdb4f2c486b6725", "level": "warning", "message": {"text": "CVE-2026-41238: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "27bd19d1a0bf129e", "scanner": "scanner-primary", "fingerprint": "ecdb4f2c486b6725", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41238"]}}, {"ruleId": "scanner-b688eed9bef55eb0", "level": "warning", "message": {"text": "CVE-2026-41239: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "2c6b44d4baca8ff9", "scanner": "scanner-primary", "fingerprint": "b688eed9bef55eb0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41239"]}}, {"ruleId": "scanner-6a812220cd6b4070", "level": "warning", "message": {"text": "CVE-2026-41240: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "1cece1679193457b", "scanner": "scanner-primary", "fingerprint": "6a812220cd6b4070", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41240"]}}, {"ruleId": "scanner-a914709f2b88b050", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "2b8b00dfea20e15a", "scanner": "scanner-primary", "fingerprint": "a914709f2b88b050", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-6fa151b70a7b5506", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "75c1e64287721fe9", "scanner": "scanner-primary", "fingerprint": "6fa151b70a7b5506", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-4bffe58345140531", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "cf050cba5605d8c6", "scanner": "scanner-primary", "fingerprint": "4bffe58345140531", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-879b9dc0e3dc252b", "level": "warning", "message": {"text": "GHSA-39q2-94rc-95cp: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "896b9ecd8cfc70f8", "scanner": "scanner-primary", "fingerprint": "879b9dc0e3dc252b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-39q2-94rc-95cp"]}}, {"ruleId": "scanner-6c8c9b5836c07f15", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "66a02bb7b3c5de03", "scanner": "scanner-primary", "fingerprint": "6c8c9b5836c07f15", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-e58eb9f0dd11166f", "level": "warning", "message": {"text": "GHSA-cj63-jhhr-wcxv: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "525ce186797595fc", "scanner": "scanner-primary", "fingerprint": "e58eb9f0dd11166f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cj63-jhhr-wcxv"]}}, {"ruleId": "scanner-b080e3d9d369b2cb", "level": "warning", "message": {"text": "GHSA-cjmm-f4jc-qw8r: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "a7bc1a87da220dbe", "scanner": "scanner-primary", "fingerprint": "b080e3d9d369b2cb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cjmm-f4jc-qw8r"]}}, {"ruleId": "scanner-d01c531a02213674", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "8aa5a56c33315a3f", "scanner": "scanner-primary", "fingerprint": "d01c531a02213674", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-c87e8fd756d5baee", "level": "warning", "message": {"text": "GHSA-h8r8-wccr-v5f2: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "516a49183f50f54a", "scanner": "scanner-primary", "fingerprint": "c87e8fd756d5baee", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-h8r8-wccr-v5f2"]}}, {"ruleId": "scanner-98863c560715b0fe", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "34904be9ab0ce7b6", "scanner": "scanner-primary", "fingerprint": "98863c560715b0fe", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-5ed598a8b4edc673", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e4b1f4512f08ccd3", "scanner": "scanner-primary", "fingerprint": "5ed598a8b4edc673", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-d93daf6ab91f1ec2", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "f7e135356d2f19e8", "scanner": "scanner-primary", "fingerprint": "d93daf6ab91f1ec2", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-88cdd13c9bbe5294", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "38da1643ba15162e", "scanner": "scanner-primary", "fingerprint": "88cdd13c9bbe5294", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-fee4a428e0674a05", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "fccbe80a85016114", "scanner": "scanner-primary", "fingerprint": "fee4a428e0674a05", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-5bf90cb7f7922abe", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "729c4f8ae414be78", "scanner": "scanner-primary", "fingerprint": "5bf90cb7f7922abe", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-9155feee87bb6d21", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "90628b495d195f42", "scanner": "scanner-primary", "fingerprint": "9155feee87bb6d21", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-2e4ca98c74754b4a", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "a69a18c128ae72cd", "scanner": "scanner-primary", "fingerprint": "2e4ca98c74754b4a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-373ac01d284957d9", "level": "error", "message": {"text": "CVE-2026-29045: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "7007d9956e5a37a7", "scanner": "scanner-primary", "fingerprint": "373ac01d284957d9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29045"]}}, {"ruleId": "scanner-1e61824af2a9be18", "level": "error", "message": {"text": "CVE-2026-54290: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "9444e9dccca3ee52", "scanner": "scanner-primary", "fingerprint": "1e61824af2a9be18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54290"]}}, {"ruleId": "scanner-2e93d56161fcc472", "level": "warning", "message": {"text": "CVE-2026-24398: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "8a4c2907712b1252", "scanner": "scanner-primary", "fingerprint": "2e93d56161fcc472", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24398"]}}, {"ruleId": "scanner-b7c9dc11e39abecf", "level": "warning", "message": {"text": "CVE-2026-24472: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "86174c0678751e33", "scanner": "scanner-primary", "fingerprint": "b7c9dc11e39abecf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24472"]}}, {"ruleId": "scanner-0ec3d1ef43e221d6", "level": "warning", "message": {"text": "CVE-2026-24473: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "55aaede7e9b010ff", "scanner": "scanner-primary", "fingerprint": "0ec3d1ef43e221d6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24473"]}}, {"ruleId": "scanner-e13829dbd09a6af1", "level": "warning", "message": {"text": "CVE-2026-24771: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "3089ac2706f99106", "scanner": "scanner-primary", "fingerprint": "e13829dbd09a6af1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24771"]}}, {"ruleId": "scanner-4cf66fb5bd58ee40", "level": "warning", "message": {"text": "CVE-2026-29085: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "03d682c8cd9adcd6", "scanner": "scanner-primary", "fingerprint": "4cf66fb5bd58ee40", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29085"]}}, {"ruleId": "scanner-dfea9aa23f1d514c", "level": "warning", "message": {"text": "CVE-2026-29086: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "a0c70355042fffd8", "scanner": "scanner-primary", "fingerprint": "dfea9aa23f1d514c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-29086"]}}, {"ruleId": "scanner-f39ec9259517d7e5", "level": "warning", "message": {"text": "CVE-2026-39407: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "312a84223aec7a47", "scanner": "scanner-primary", "fingerprint": "f39ec9259517d7e5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39407"]}}, {"ruleId": "scanner-edcecc7732b13eac", "level": "warning", "message": {"text": "CVE-2026-39408: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "d8f14267e13f23b6", "scanner": "scanner-primary", "fingerprint": "edcecc7732b13eac", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39408"]}}, {"ruleId": "scanner-17e47b91f999bd4c", "level": "warning", "message": {"text": "CVE-2026-39409: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "09af9b1166277793", "scanner": "scanner-primary", "fingerprint": "17e47b91f999bd4c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39409"]}}, {"ruleId": "scanner-a3b0014746510b7c", "level": "warning", "message": {"text": "CVE-2026-39410: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "9dacfb879d4c7023", "scanner": "scanner-primary", "fingerprint": "a3b0014746510b7c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39410"]}}, {"ruleId": "scanner-761ccc35f3630f24", "level": "warning", "message": {"text": "CVE-2026-44455: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "f7c090be734870ea", "scanner": "scanner-primary", "fingerprint": "761ccc35f3630f24", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44455"]}}, {"ruleId": "scanner-f97514d90418e674", "level": "warning", "message": {"text": "CVE-2026-44456: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "09ea7ec1e91f5f36", "scanner": "scanner-primary", "fingerprint": "f97514d90418e674", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44456"]}}, {"ruleId": "scanner-f0a24e9a022159d7", "level": "warning", "message": {"text": "CVE-2026-44457: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "2393b508de3ed809", "scanner": "scanner-primary", "fingerprint": "f0a24e9a022159d7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44457"]}}, {"ruleId": "scanner-1ad005499172c672", "level": "warning", "message": {"text": "CVE-2026-44458: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "9dea544b0944b90a", "scanner": "scanner-primary", "fingerprint": "1ad005499172c672", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44458"]}}, {"ruleId": "scanner-0d278c944f822375", "level": "warning", "message": {"text": "CVE-2026-47673: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "88786a9c6cba822c", "scanner": "scanner-primary", "fingerprint": "0d278c944f822375", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47673"]}}, {"ruleId": "scanner-7c1c584330425995", "level": "warning", "message": {"text": "CVE-2026-47674: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e86b934c29779bd5", "scanner": "scanner-primary", "fingerprint": "7c1c584330425995", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47674"]}}, {"ruleId": "scanner-4fcf8db694852abd", "level": "warning", "message": {"text": "CVE-2026-47675: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "f81c80a6409028cb", "scanner": "scanner-primary", "fingerprint": "4fcf8db694852abd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47675"]}}, {"ruleId": "scanner-2bdb2520dbe9b176", "level": "warning", "message": {"text": "CVE-2026-47676: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "3b0e1d000e78fd16", "scanner": "scanner-primary", "fingerprint": "2bdb2520dbe9b176", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-47676"]}}, {"ruleId": "scanner-f59c19c46247e129", "level": "warning", "message": {"text": "CVE-2026-54286: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "40a3920da9b729d8", "scanner": "scanner-primary", "fingerprint": "f59c19c46247e129", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54286"]}}, {"ruleId": "scanner-4b145303565ab831", "level": "warning", "message": {"text": "CVE-2026-54287: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "cfcda4c39228475e", "scanner": "scanner-primary", "fingerprint": "4b145303565ab831", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54287"]}}, {"ruleId": "scanner-78eb82845dd2276e", "level": "warning", "message": {"text": "CVE-2026-54288: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "82930d2091fc83a4", "scanner": "scanner-primary", "fingerprint": "78eb82845dd2276e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54288"]}}, {"ruleId": "scanner-9e24cfc01a1b9c2a", "level": "warning", "message": {"text": "CVE-2026-54289: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "92bb0df7a56a208c", "scanner": "scanner-primary", "fingerprint": "9e24cfc01a1b9c2a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54289"]}}, {"ruleId": "scanner-840fa19ba09b1d42", "level": "warning", "message": {"text": "CVE-2026-56761: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "4c4fb7ad83963097", "scanner": "scanner-primary", "fingerprint": "840fa19ba09b1d42", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-56761"]}}, {"ruleId": "scanner-46096b62670097dc", "level": "warning", "message": {"text": "CVE-2026-59895: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "d6097a3036c982b8", "scanner": "scanner-primary", "fingerprint": "46096b62670097dc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59895"]}}, {"ruleId": "scanner-c99a2a7dec7d2b48", "level": "warning", "message": {"text": "CVE-2026-59897: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "f4ee272f0d19dd97", "scanner": "scanner-primary", "fingerprint": "c99a2a7dec7d2b48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59897"]}}, {"ruleId": "scanner-4eb3111d5258074a", "level": "warning", "message": {"text": "GHSA-26pp-8wgv-hjvm: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "91c11089f1ff5591", "scanner": "scanner-primary", "fingerprint": "4eb3111d5258074a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-26pp-8wgv-hjvm"]}}, {"ruleId": "scanner-3b592d18aa740727", "level": "warning", "message": {"text": "GHSA-v8w9-8mx6-g223: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "ddc1d3ad2af9c766", "scanner": "scanner-primary", "fingerprint": "3b592d18aa740727", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-v8w9-8mx6-g223"]}}, {"ruleId": "scanner-ace9aa5b776e6fb8", "level": "note", "message": {"text": "CVE-2026-44459: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "77e7b6c911945a91", "scanner": "scanner-primary", "fingerprint": "ace9aa5b776e6fb8", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44459"]}}, {"ruleId": "scanner-bba1f14ea170d9c3", "level": "note", "message": {"text": "GHSA-gq3j-xvxp-8hrf: hono 4.11.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "612b1f0ee1081a3e", "scanner": "scanner-primary", "fingerprint": "bba1f14ea170d9c3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gq3j-xvxp-8hrf"]}}, {"ruleId": "scanner-132a88cf5c46dee7", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "a25fce113718d11d", "scanner": "scanner-primary", "fingerprint": "132a88cf5c46dee7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-764d9e66a5dbf4cc", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "eff437f78c22c0ab", "scanner": "scanner-primary", "fingerprint": "764d9e66a5dbf4cc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-558492ef3c161650", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "768d6f72760268ec", "scanner": "scanner-primary", "fingerprint": "558492ef3c161650", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-7081b8a400505bf9", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "1692a550f8d5e8df", "scanner": "scanner-primary", "fingerprint": "7081b8a400505bf9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-816fff617a91a18f", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "3bb4909e6f160e72", "scanner": "scanner-primary", "fingerprint": "816fff617a91a18f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-e3dce40b47cd10e9", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "768d6f72760268ec", "scanner": "scanner-primary", "fingerprint": "e3dce40b47cd10e9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-856845249921821e", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "3bb4909e6f160e72", "scanner": "scanner-primary", "fingerprint": "856845249921821e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-33d99886d828b994", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.12.2 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "4896e407d4de072d", "scanner": "scanner-primary", "fingerprint": "33d99886d828b994", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-d792de696b217f57", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.12.2 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "14bade9d7e035a4b", "scanner": "scanner-primary", "fingerprint": "d792de696b217f57", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-1227c8a1e556bd5f", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.12.2 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "b641b66631283ce3", "scanner": "scanner-primary", "fingerprint": "1227c8a1e556bd5f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-18174bd7db43e408", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.12.2 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "8f3385dd72e81b2b", "scanner": "scanner-primary", "fingerprint": "18174bd7db43e408", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-50abbf3f7a5b9d11", "level": "error", "message": {"text": "CVE-2026-26996: minimatch 10.1.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "b1efc34f967804eb", "scanner": "scanner-primary", "fingerprint": "50abbf3f7a5b9d11", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-26996"]}}, {"ruleId": "scanner-0bb79d54e9a8f36a", "level": "error", "message": {"text": "CVE-2026-27903: minimatch 10.1.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "42583ee997b23931", "scanner": "scanner-primary", "fingerprint": "0bb79d54e9a8f36a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27903"]}}, {"ruleId": "scanner-622725ff45a8b907", "level": "error", "message": {"text": "CVE-2026-27904: minimatch 10.1.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "47e577bec337dfaa", "scanner": "scanner-primary", "fingerprint": "622725ff45a8b907", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27904"]}}, {"ruleId": "scanner-052241e669c85f95", "level": "error", "message": {"text": "CVE-2026-4926: path-to-regexp 8.3.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "87700bc3515aef8f", "scanner": "scanner-primary", "fingerprint": "052241e669c85f95", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4926"]}}, {"ruleId": "scanner-6ba185bbf38c0476", "level": "warning", "message": {"text": "CVE-2026-4923: path-to-regexp 8.3.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "db80a564c34756a0", "scanner": "scanner-primary", "fingerprint": "6ba185bbf38c0476", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4923"]}}, {"ruleId": "scanner-94c7ca87f18d61ca", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 2.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "9b02d23672a20d13", "scanner": "scanner-primary", "fingerprint": "94c7ca87f18d61ca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-5e87f0baf6eac872", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 2.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "4de4002f93ed9af3", "scanner": "scanner-primary", "fingerprint": "5e87f0baf6eac872", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-e5ddea67eea573ca", "level": "error", "message": {"text": "CVE-2026-33671: picomatch 4.0.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "9b02d23672a20d13", "scanner": "scanner-primary", "fingerprint": "e5ddea67eea573ca", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33671"]}}, {"ruleId": "scanner-b6b7ba331901df48", "level": "warning", "message": {"text": "CVE-2026-33672: picomatch 4.0.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "4de4002f93ed9af3", "scanner": "scanner-primary", "fingerprint": "b6b7ba331901df48", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33672"]}}, {"ruleId": "scanner-936b05795ab3555e", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.5.6 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "ec981160862bd975", "scanner": "scanner-primary", "fingerprint": "936b05795ab3555e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-70d4e0e473d83c12", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "f4ebdc290c2e2b0e", "scanner": "scanner-primary", "fingerprint": "70d4e0e473d83c12", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-3c1181a521e88fe4", "level": "note", "message": {"text": "CVE-2026-2391: qs 6.14.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "6e32c7b9b3db61a2", "scanner": "scanner-primary", "fingerprint": "3c1181a521e88fe4", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2391"]}}, {"ruleId": "scanner-1c74db0c2bfb0994", "level": "error", "message": {"text": "CVE-2026-27606: rollup 4.56.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "2093cd9268b8bd2b", "scanner": "scanner-primary", "fingerprint": "1c74db0c2bfb0994", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-27606"]}}, {"ruleId": "scanner-876259069f5195e3", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e6fe637fa2839979", "scanner": "scanner-primary", "fingerprint": "876259069f5195e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-00133e8d69c95772", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 13.0.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e6fe637fa2839979", "scanner": "scanner-primary", "fingerprint": "00133e8d69c95772", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-b26cb6d5c5913830", "level": "error", "message": {"text": "CVE-2026-39363: vite 7.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "a9ed20652c351a6a", "scanner": "scanner-primary", "fingerprint": "b26cb6d5c5913830", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39363"]}}, {"ruleId": "scanner-b79b533a5c5a1c1f", "level": "error", "message": {"text": "CVE-2026-39364: vite 7.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e32a09eb774173e3", "scanner": "scanner-primary", "fingerprint": "b79b533a5c5a1c1f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39364"]}}, {"ruleId": "scanner-19da828fdd50d440", "level": "error", "message": {"text": "CVE-2026-53571: vite 7.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "8aa25d9af3bf286d", "scanner": "scanner-primary", "fingerprint": "19da828fdd50d440", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53571"]}}, {"ruleId": "scanner-03ac5d3544c4801f", "level": "warning", "message": {"text": "CVE-2026-39365: vite 7.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "b6a468c93e84ee41", "scanner": "scanner-primary", "fingerprint": "03ac5d3544c4801f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-39365"]}}, {"ruleId": "scanner-c4156c4d4d707d2d", "level": "warning", "message": {"text": "CVE-2026-53632: vite 7.3.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "12fba0e159982443", "scanner": "scanner-primary", "fingerprint": "c4156c4d4d707d2d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53632"]}}, {"ruleId": "scanner-79b21bd939f88b58", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: docs/zh/customization/agents.md"}, "properties": {"repobilityId": "3ab3b0e8988b2ceb", "scanner": "scanner-primary", "fingerprint": "79b21bd939f88b58", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "agents_md"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/zh/customization/agents.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7709eb2299adaebd", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: tests_e2e/AGENTS.md"}, "properties": {"repobilityId": "becf9400ffef0933", "scanner": "scanner-primary", "fingerprint": "7709eb2299adaebd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "agents_md"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests_e2e/AGENTS.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f74542df7406817", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: src/kimi_cli/acp/AGENTS.md"}, "properties": {"repobilityId": "a38201ea871f2c13", "scanner": "scanner-primary", "fingerprint": "0f74542df7406817", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "agents_md"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/acp/AGENTS.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-73b54cc38905de2f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: src/kimi_cli/skills/kimi-cli-help/SKILL.md"}, "properties": {"repobilityId": "63fe21b09826794c", "scanner": "scanner-primary", "fingerprint": "73b54cc38905de2f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/skills/kimi-cli-help/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-14e9677aff48a310", "level": "error", "message": {"text": "SkillSpector RA1 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md"}, "properties": {"repobilityId": "80ebfc7c9eea598e", "scanner": "scanner-primary", "fingerprint": "14e9677aff48a310", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "rogue-agent", "RA1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/skills/skill-creator/SKILL.md"}, "region": {"startLine": 224}}}]}, {"ruleId": "scanner-4ee2a071395dd2e8", "level": "warning", "message": {"text": "SkillSpector RA2 (rogue-agent) in src/kimi_cli/skills/skill-creator/SKILL.md"}, "properties": {"repobilityId": "b351c314b24a6936", "scanner": "scanner-primary", "fingerprint": "4ee2a071395dd2e8", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "rogue-agent", "RA2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/skills/skill-creator/SKILL.md"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-a43404708c48f220", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in web/src/components/ai-elements/code-block.tsx:419"}, "properties": {"repobilityId": "75865d306e9ee926", "scanner": "scanner-primary", "fingerprint": "a43404708c48f220", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/components/ai-elements/code-block.tsx"}, "region": {"startLine": 419}}}]}, {"ruleId": "scanner-4292cffb9a39534b", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in src/kimi_cli/vis/app.py:53"}, "properties": {"repobilityId": "62e342c5c035ea88", "scanner": "scanner-primary", "fingerprint": "4292cffb9a39534b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/vis/app.py"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-963d9472199fa641", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8bb646243ac4c0f0", "scanner": "scanner-primary", "fingerprint": "963d9472199fa641", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docs-pages.yml"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-3a05273fbb31c1df", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "73a14ed98a2df354", "scanner": "scanner-primary", "fingerprint": "3a05273fbb31c1df", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docs-pages.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-036625a4cc85c58d", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2c790762c6103dbb", "scanner": "scanner-primary", "fingerprint": "036625a4cc85c58d", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-kimi-sdk.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-54e209731d934268", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9f91649092657e03", "scanner": "scanner-primary", "fingerprint": "54e209731d934268", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-pykaos.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-92fd18f7960ea0fc", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "87740ea8070256bb", "scanner": "scanner-primary", "fingerprint": "92fd18f7960ea0fc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-pykaos.yml"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-a2fc7b9381819720", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e81b52af9d469ddb", "scanner": "scanner-primary", "fingerprint": "a2fc7b9381819720", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/typos.yml"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-e3fd8280f24592fa", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a9b2fb39d7e5697d", "scanner": "scanner-primary", "fingerprint": "e3fd8280f24592fa", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-docs.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-ef24c99fc93818e8", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "4c0bacf63a766bbe", "scanner": "scanner-primary", "fingerprint": "ef24c99fc93818e8", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-kimi-cli.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-20c80f3ff485f877", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "eedb80b1c07fc90a", "scanner": "scanner-primary", "fingerprint": "20c80f3ff485f877", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-kimi-cli.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-13e6f6c2dc7231e1", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b02dce573442c046", "scanner": "scanner-primary", "fingerprint": "13e6f6c2dc7231e1", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-kimi-cli.yml"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-057ebf0f76b942cc", "level": "error", "message": {"text": "GitHub Action tracks a moving branch"}, "properties": {"repobilityId": "d0d415c7807871db", "scanner": "scanner-primary", "fingerprint": "057ebf0f76b942cc", "layer": "cicd", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-kimi-cli.yml"}, "region": {"startLine": 279}}}]}, {"ruleId": "scanner-6785afae3935ea7a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5ab7ea7c9d10c631", "scanner": "scanner-primary", "fingerprint": "6785afae3935ea7a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-kosong.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-f8b9ecdd9768fcb2", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f7f5e6f90f86a810", "scanner": "scanner-primary", "fingerprint": "f8b9ecdd9768fcb2", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-kosong.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-fb0f46e2443b4e3b", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "caad3b46e3fe7c1a", "scanner": "scanner-primary", "fingerprint": "fb0f46e2443b4e3b", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-kimi-sdk.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-a3ad83d51fda4321", "level": "note", "message": {"text": "Very large file: tests/tools/test_agent_tool.py (1611 lines)"}, "properties": {"repobilityId": "f3ea4321ed23e10e", "scanner": "scanner-primary", "fingerprint": "a3ad83d51fda4321", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3941a6629417d748", "level": "note", "message": {"text": "Very large file: tests/core/test_kimisoul_background_wait.py (1463 lines)"}, "properties": {"repobilityId": "0826653490ee8f21", "scanner": "scanner-primary", "fingerprint": "3941a6629417d748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-136ff6a927d8e60b", "level": "note", "message": {"text": "Very large file: tests/core/test_skill.py (1841 lines)"}, "properties": {"repobilityId": "b01986e938b3e16e", "scanner": "scanner-primary", "fingerprint": "136ff6a927d8e60b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ffd74846139d70a5", "level": "note", "message": {"text": "Very large file: tests/telemetry/test_instrumentation.py (1381 lines)"}, "properties": {"repobilityId": "60b1ef0acd26775e", "scanner": "scanner-primary", "fingerprint": "ffd74846139d70a5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-1bf300717fe5895f", "level": "note", "message": {"text": "Very large file: web/src/hooks/useSessionStream.ts (3102 lines)"}, "properties": {"repobilityId": "30935495739fbe53", "scanner": "scanner-primary", "fingerprint": "1bf300717fe5895f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b4acc33a13184b55", "level": "note", "message": {"text": "Very large file: web/src/features/sessions/sessions.tsx (1274 lines)"}, "properties": {"repobilityId": "f0e3c5f6b1174d79", "scanner": "scanner-primary", "fingerprint": "b4acc33a13184b55", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e71025c013849db2", "level": "note", "message": {"text": "Very large file: src/kimi_cli/ui/shell/__init__.py (1551 lines)"}, "properties": {"repobilityId": "61028fe8a281b710", "scanner": "scanner-primary", "fingerprint": "e71025c013849db2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-82da86aab5549546", "level": "note", "message": {"text": "Very large file: src/kimi_cli/ui/shell/prompt.py (2259 lines)"}, "properties": {"repobilityId": "80518320430debf1", "scanner": "scanner-primary", "fingerprint": "82da86aab5549546", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-cd29667973cece46", "level": "note", "message": {"text": "Very large file: src/kimi_cli/soul/kimisoul.py (1963 lines)"}, "properties": {"repobilityId": "8e2aafd49201b60b", "scanner": "scanner-primary", "fingerprint": "cd29667973cece46", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-98eecf7aa017d4cb", "level": "note", "message": {"text": "96 TODO/FIXME markers"}, "properties": {"repobilityId": "4b38c118003e07d2", "scanner": "scanner-primary", "fingerprint": "98eecf7aa017d4cb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["maintenance"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "e8762d5ea99036ed", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "c181dacc8b2b9981", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "8532239abf6b2bc9", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-75454790e0c325b0", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 tests_ai/scripts/run.py:49"}, "properties": {"repobilityId": "afdb292dafecc165", "scanner": "scanner-primary", "fingerprint": "75454790e0c325b0", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests_ai/scripts/run.py"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-4f764ba2b88fde08", "level": "note", "message": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 scripts/telemetry_debug_server.py:104"}, "properties": {"repobilityId": "f7c4b4de232d46e7", "scanner": "scanner-primary", "fingerprint": "4f764ba2b88fde08", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-6e65416f9e6d0900", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in packages/kosong/src/kosong/_generate.py:64"}, "properties": {"repobilityId": "dc6a0cf60c47a5b6", "scanner": "scanner-primary", "fingerprint": "6e65416f9e6d0900", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4863aff295561d55", "level": "note", "message": {"text": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/mock.py:40"}, "properties": {"repobilityId": "04183c5c9ee8ba62", "scanner": "scanner-primary", "fingerprint": "4863aff295561d55", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-5fefab07eb160b85", "level": "note", "message": {"text": "Legacy-named symbol `OpenAILegacy` in packages/kosong/src/kosong/chat_provider/chaos.py:152"}, "properties": {"repobilityId": "3aeaaff29e960f2d", "scanner": "scanner-primary", "fingerprint": "5fefab07eb160b85", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8b33baf6704058e4", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in packages/kosong/src/kosong/chat_provider/kimi.py:327"}, "properties": {"repobilityId": "7d14a895466e2656", "scanner": "scanner-primary", "fingerprint": "8b33baf6704058e4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-73dce4bdea8868d3", "level": "note", "message": {"text": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/echo/scripted_echo.py:44"}, "properties": {"repobilityId": "8ed5a18b2629017d", "scanner": "scanner-primary", "fingerprint": "73dce4bdea8868d3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-d58ec04aae9a385f", "level": "note", "message": {"text": "Stub function `thinking_effort` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/chat_provider/echo/echo.py:67"}, "properties": {"repobilityId": "33a19a83be002367", "scanner": "scanner-primary", "fingerprint": "d58ec04aae9a385f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-6f2e2dd4b58a0f1f", "level": "note", "message": {"text": "Legacy-named symbol `openai_legacy` in packages/kosong/src/kosong/contrib/chat_provider/openai_legacy.py:38"}, "properties": {"repobilityId": "a3bd5f4a4359ae28", "scanner": "scanner-primary", "fingerprint": "6f2e2dd4b58a0f1f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-96de48ccf491ad75", "level": "note", "message": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/openai_legacy.py:246"}, "properties": {"repobilityId": "272cb7509940207c", "scanner": "scanner-primary", "fingerprint": "96de48ccf491ad75", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-63e9b9539b8fc07a", "level": "note", "message": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/anthropic.py:529"}, "properties": {"repobilityId": "62ca9d4f0f29e265", "scanner": "scanner-primary", "fingerprint": "63e9b9539b8fc07a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-532fd1dca8ad2a97", "level": "note", "message": {"text": "Legacy-named symbol `OpenAILegacy` in packages/kosong/src/kosong/contrib/chat_provider/openai_responses.py:95"}, "properties": {"repobilityId": "e48a4b934fdb175d", "scanner": "scanner-primary", "fingerprint": "532fd1dca8ad2a97", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3a76d946fc06a406", "level": "note", "message": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/openai_responses.py:478"}, "properties": {"repobilityId": "dde998579f62467d", "scanner": "scanner-primary", "fingerprint": "3a76d946fc06a406", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-5e8b787ebd50f8f6", "level": "note", "message": {"text": "Stub function `trace_id` (body is just `pass`/`return`) \u2014 packages/kosong/src/kosong/contrib/chat_provider/google_genai.py:253"}, "properties": {"repobilityId": "4fd3a4226aa411d5", "scanner": "scanner-primary", "fingerprint": "5e8b787ebd50f8f6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-ee011fc3cd67720c", "level": "note", "message": {"text": "Legacy-named symbol `lineNumberOld` in web/src/components/ui/diff/index.tsx:147"}, "properties": {"repobilityId": "08edf9a6e0f5a169", "scanner": "scanner-primary", "fingerprint": "ee011fc3cd67720c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-680943cc25494261", "level": "note", "message": {"text": "Legacy-named symbol `OpenaiLegacy` in web/src/lib/api/models/ProviderType.ts:22"}, "properties": {"repobilityId": "bc19811387a9c141", "scanner": "scanner-primary", "fingerprint": "680943cc25494261", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-99a5883e262b3e61", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 examples/custom-kimi-soul/main.py:79"}, "properties": {"repobilityId": "ce35f4d384bebf85", "scanner": "scanner-primary", "fingerprint": "99a5883e262b3e61", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/custom-kimi-soul/main.py"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-4358bfed3c2714dc", "level": "note", "message": {"text": "Legacy-named symbol `files_to_copy` in src/kimi_cli/session_fork.py:315"}, "properties": {"repobilityId": "d88d466d111bf9d2", "scanner": "scanner-primary", "fingerprint": "4358bfed3c2714dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-21cdda6c41e8befc", "level": "note", "message": {"text": "Legacy-named symbol `openai_legacy` in src/kimi_cli/config.py:50"}, "properties": {"repobilityId": "623692d7658ce2fa", "scanner": "scanner-primary", "fingerprint": "21cdda6c41e8befc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-72214a1add7122fe", "level": "note", "message": {"text": "Legacy-named symbol `openai_legacy` in src/kimi_cli/llm.py:34"}, "properties": {"repobilityId": "f79d2b4ff9cdaddd", "scanner": "scanner-primary", "fingerprint": "72214a1add7122fe", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-e654319617156b87", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/notifications/manager.py:55"}, "properties": {"repobilityId": "2d1a8967bf358f15", "scanner": "scanner-primary", "fingerprint": "e654319617156b87", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-c3c1f1734f6ff415", "level": "note", "message": {"text": "Stub function `flush` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/print/visualize.py:38"}, "properties": {"repobilityId": "8b3cf2ab7d520037", "scanner": "scanner-primary", "fingerprint": "c3c1f1734f6ff415", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-656f260ec7a72182", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/ui/shell/__init__.py:1163"}, "properties": {"repobilityId": "65f7e25b53e51355", "scanner": "scanner-primary", "fingerprint": "656f260ec7a72182", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2ec9b7c313c6d377", "level": "note", "message": {"text": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_btw_panel.py:199"}, "properties": {"repobilityId": "85a145e37ff469f0", "scanner": "scanner-primary", "fingerprint": "2ec9b7c313c6d377", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-4c67cc1104319a06", "level": "note", "message": {"text": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_approval_panel.py:389"}, "properties": {"repobilityId": "c2a1e027a4e623af", "scanner": "scanner-primary", "fingerprint": "4c67cc1104319a06", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-4835dca9ddf8ee02", "level": "note", "message": {"text": "Stub function `running_prompt_placeholder` (body is just `pass`/`return`) \u2014 src/kimi_cli/ui/shell/visualize/_question_panel.py:377"}, "properties": {"repobilityId": "336ad7d311d7bab0", "scanner": "scanner-primary", "fingerprint": "4835dca9ddf8ee02", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-6bfe6d546f2d14b3", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/cli/plugin.py:145"}, "properties": {"repobilityId": "93818780c00ae84f", "scanner": "scanner-primary", "fingerprint": "6bfe6d546f2d14b3", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/cli/plugin.py"}, "region": {"startLine": 145}}}]}, {"ruleId": "scanner-b6aaf2a9a1c9f2b3", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/cli/toad.py:71"}, "properties": {"repobilityId": "f4792aa691635b34", "scanner": "scanner-primary", "fingerprint": "b6aaf2a9a1c9f2b3", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/cli/toad.py"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-41836e44672e85f8", "level": "note", "message": {"text": "Stub function `close` (body is just `pass`/`return`) \u2014 src/kimi_cli/acp/kaos.py:22"}, "properties": {"repobilityId": "cabc07c89b7ba6eb", "scanner": "scanner-primary", "fingerprint": "41836e44672e85f8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-63df3d8f50464b7f", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/soul/toolset.py:226"}, "properties": {"repobilityId": "c632e30f2abc0ffb", "scanner": "scanner-primary", "fingerprint": "63df3d8f50464b7f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-bc7fb9ec28e33da5", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/tools/background/__init__.py:247"}, "properties": {"repobilityId": "233856c8ab3baa35", "scanner": "scanner-primary", "fingerprint": "bc7fb9ec28e33da5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a5b46bf493bf6b6c", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/background/worker.py:188"}, "properties": {"repobilityId": "93cc922cfa73daef", "scanner": "scanner-primary", "fingerprint": "a5b46bf493bf6b6c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7e8329d5f1ccd13c", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 src/kimi_cli/background/worker.py:23"}, "properties": {"repobilityId": "8295dde683afe5de", "scanner": "scanner-primary", "fingerprint": "7e8329d5f1ccd13c", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/background/worker.py"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-aec9ada46b4974cd", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in src/kimi_cli/background/manager.py:393"}, "properties": {"repobilityId": "e30f1afaa398ed30", "scanner": "scanner-primary", "fingerprint": "aec9ada46b4974cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "6dae5e6ab1c76f95", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "b5b3b3b10f6ec7e6", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-700227e33027cc35", "level": "error", "message": {"text": "FastAPI POST `import_session` without auth dependency \u2014 src/kimi_cli/vis/api/sessions.py:606"}, "properties": {"repobilityId": "e42de7f66c42d83e", "scanner": "scanner-primary", "fingerprint": "700227e33027cc35", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/vis/api/sessions.py"}, "region": {"startLine": 606}}}]}, {"ruleId": "scanner-bd59ba5827b980d0", "level": "error", "message": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/kimi_cli/vis/api/sessions.py:673"}, "properties": {"repobilityId": "637cda631ebc431b", "scanner": "scanner-primary", "fingerprint": "bd59ba5827b980d0", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/vis/api/sessions.py"}, "region": {"startLine": 673}}}]}, {"ruleId": "scanner-a2cee554867be179", "level": "error", "message": {"text": "FastAPI PATCH `update_global_config` without auth dependency \u2014 src/kimi_cli/web/api/config.py:128"}, "properties": {"repobilityId": "328fc65b7727d068", "scanner": "scanner-primary", "fingerprint": "a2cee554867be179", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/config.py"}, "region": {"startLine": 128}}}]}, {"ruleId": "scanner-fb615a26750dbb23", "level": "error", "message": {"text": "FastAPI PUT `update_config_toml` without auth dependency \u2014 src/kimi_cli/web/api/config.py:187"}, "properties": {"repobilityId": "ace1dcbd0b4e7649", "scanner": "scanner-primary", "fingerprint": "fb615a26750dbb23", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/config.py"}, "region": {"startLine": 187}}}]}, {"ruleId": "scanner-c6676c2f8b2ab02a", "level": "error", "message": {"text": "FastAPI POST `open_in` without auth dependency \u2014 src/kimi_cli/web/api/open_in.py:176"}, "properties": {"repobilityId": "133398db6d106cf9", "scanner": "scanner-primary", "fingerprint": "c6676c2f8b2ab02a", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/open_in.py"}, "region": {"startLine": 176}}}]}, {"ruleId": "scanner-34615ef32843ca78", "level": "error", "message": {"text": "FastAPI POST `create_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:299"}, "properties": {"repobilityId": "bf83f05a8a023525", "scanner": "scanner-primary", "fingerprint": "34615ef32843ca78", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/sessions.py"}, "region": {"startLine": 299}}}]}, {"ruleId": "scanner-57b4b1641e20bcef", "level": "error", "message": {"text": "FastAPI POST `upload_session_file` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:379"}, "properties": {"repobilityId": "3cdb3161f53b1a99", "scanner": "scanner-primary", "fingerprint": "57b4b1641e20bcef", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/sessions.py"}, "region": {"startLine": 379}}}]}, {"ruleId": "scanner-1cc7c652314a7f6c", "level": "error", "message": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:565"}, "properties": {"repobilityId": "2cb9d0957f48de72", "scanner": "scanner-primary", "fingerprint": "1cc7c652314a7f6c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/sessions.py"}, "region": {"startLine": 565}}}]}, {"ruleId": "scanner-2790e447b726ec75", "level": "error", "message": {"text": "FastAPI PATCH `update_session` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:586"}, "properties": {"repobilityId": "1a83925585d65acb", "scanner": "scanner-primary", "fingerprint": "2790e447b726ec75", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/sessions.py"}, "region": {"startLine": 586}}}]}, {"ruleId": "scanner-2e9cf0d3da523edf", "level": "error", "message": {"text": "FastAPI POST `fork_session_endpoint` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:684"}, "properties": {"repobilityId": "e1c0d40785ee12fb", "scanner": "scanner-primary", "fingerprint": "2e9cf0d3da523edf", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/sessions.py"}, "region": {"startLine": 684}}}]}, {"ruleId": "scanner-e24f02913f1907b6", "level": "error", "message": {"text": "FastAPI POST `generate_session_title` without auth dependency \u2014 src/kimi_cli/web/api/sessions.py:749"}, "properties": {"repobilityId": "9757ef6ff8dd1206", "scanner": "scanner-primary", "fingerprint": "e24f02913f1907b6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/kimi_cli/web/api/sessions.py"}, "region": {"startLine": 749}}}]}, {"ruleId": "scanner-212575d3b04067ab", "level": "error", "message": {"text": "Vulnerable dependency js-yaml 3.14.2: GHSA-52cp-r559-cp3m"}, "properties": {"repobilityId": "55522dc7c85b667a", "scanner": "scanner-primary", "fingerprint": "212575d3b04067ab", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-52cp-r559-cp3m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b41e333292639b42", "level": "warning", "message": {"text": "Vulnerable dependency js-yaml 3.14.2: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": "7fd8c6f05bbc0277", "scanner": "scanner-primary", "fingerprint": "b41e333292639b42", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h67p-54hq-rp68"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e2b56e6094d27e56", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-6m6c-36f7-fhxh"}, "properties": {"repobilityId": "e4a5d296c1d6cc75", "scanner": "scanner-primary", "fingerprint": "e2b56e6094d27e56", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6m6c-36f7-fhxh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6946d88015c8d257", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-87f9-hvmw-gh4p"}, "properties": {"repobilityId": "88653ae8bfe2e256", "scanner": "scanner-primary", "fingerprint": "6946d88015c8d257", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-87f9-hvmw-gh4p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f1688d50c54451b", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-ghcm-xqfw-q4vr"}, "properties": {"repobilityId": "e0e52fa5ace444a4", "scanner": "scanner-primary", "fingerprint": "0f1688d50c54451b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ghcm-xqfw-q4vr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-09f823568694d4c6", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.12.2: GHSA-xcj9-5m2h-648r"}, "properties": {"repobilityId": "0d6b772ac912c9a8", "scanner": "scanner-primary", "fingerprint": "09f823568694d4c6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xcj9-5m2h-648r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1d254dd8a8f495c7", "level": "error", "message": {"text": "Vulnerable dependency uuid 11.1.0: GHSA-w5hq-g745-h8pq"}, "properties": {"repobilityId": "692968c2393ef8c7", "scanner": "scanner-primary", "fingerprint": "1d254dd8a8f495c7", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w5hq-g745-h8pq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97f2892f18113d2d", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "90685dbb72b15019", "scanner": "scanner-primary", "fingerprint": "97f2892f18113d2d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ddfe3289ae22d5a3", "level": "error", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "d9b9604813f5ec55", "scanner": "scanner-primary", "fingerprint": "ddfe3289ae22d5a3", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb9159bcc344c6f1", "level": "warning", "message": {"text": "Vulnerable dependency vite 5.4.21: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "6d8cd9b06e1669ff", "scanner": "scanner-primary", "fingerprint": "eb9159bcc344c6f1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-caa469ae1d48826a", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2fqr-mr3j-6wp8"}, "properties": {"repobilityId": "7ef4cda3aabc8a78", "scanner": "scanner-primary", "fingerprint": "caa469ae1d48826a", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2fqr-mr3j-6wp8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8a11b8a9a73becc5", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-2vrm-gr82-f7m5"}, "properties": {"repobilityId": "f85c0b73b2e5a699", "scanner": "scanner-primary", "fingerprint": "8a11b8a9a73becc5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-2vrm-gr82-f7m5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f554ec6b83a12ddb", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-3wq7-rqq7-wx6j"}, "properties": {"repobilityId": "9f3813a15fb8afb3", "scanner": "scanner-primary", "fingerprint": "f554ec6b83a12ddb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3wq7-rqq7-wx6j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6bb9cc560c27851b", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4fvr-rgm6-gqmc"}, "properties": {"repobilityId": "731e09e18014b328", "scanner": "scanner-primary", "fingerprint": "6bb9cc560c27851b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4fvr-rgm6-gqmc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9697c24aa4e094dc", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-4m7w-qmgq-4wj5"}, "properties": {"repobilityId": "9c6bc4a985c874aa", "scanner": "scanner-primary", "fingerprint": "9697c24aa4e094dc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4m7w-qmgq-4wj5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6605999a5655046d", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hf-3vf5-4wqf"}, "properties": {"repobilityId": "0cc90cb870a1dd35", "scanner": "scanner-primary", "fingerprint": "6605999a5655046d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hf-3vf5-4wqf"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b04019ff778e11e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-63hw-fmq6-xxg2"}, "properties": {"repobilityId": "f9bc9509fc24935f", "scanner": "scanner-primary", "fingerprint": "1b04019ff778e11e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-63hw-fmq6-xxg2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a7f24e42ab71a0c5", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-966j-vmvw-g2g9"}, "properties": {"repobilityId": "11a33473ddd7cf1e", "scanner": "scanner-primary", "fingerprint": "a7f24e42ab71a0c5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-966j-vmvw-g2g9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-31e8a3e4292fccca", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-9x8q-7h8h-wcw9"}, "properties": {"repobilityId": "f4283f27a3d602f3", "scanner": "scanner-primary", "fingerprint": "31e8a3e4292fccca", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9x8q-7h8h-wcw9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2eea30546fee0e81", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-c427-h43c-vf67"}, "properties": {"repobilityId": "8462de36b474aab5", "scanner": "scanner-primary", "fingerprint": "2eea30546fee0e81", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c427-h43c-vf67"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffc2cec7e38f5655", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-g3cq-j2xw-wf74"}, "properties": {"repobilityId": "1e2a14ee29866652", "scanner": "scanner-primary", "fingerprint": "ffc2cec7e38f5655", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g3cq-j2xw-wf74"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-647bb06712718701", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hcc4-c3v8-rx92"}, "properties": {"repobilityId": "65700a967284d0be", "scanner": "scanner-primary", "fingerprint": "647bb06712718701", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hcc4-c3v8-rx92"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b53fe845d091f72e", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hg6j-4rv6-33pg"}, "properties": {"repobilityId": "25b722ac25954261", "scanner": "scanner-primary", "fingerprint": "b53fe845d091f72e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hg6j-4rv6-33pg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4e025c42aa4a9bea", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-hpj7-wq8m-9hgp"}, "properties": {"repobilityId": "785aa05368258fea", "scanner": "scanner-primary", "fingerprint": "4e025c42aa4a9bea", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hpj7-wq8m-9hgp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d40361292f797c15", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-jg22-mg44-37j8"}, "properties": {"repobilityId": "1e8d545951768da3", "scanner": "scanner-primary", "fingerprint": "d40361292f797c15", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jg22-mg44-37j8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9d1383d39fd08f35", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m5qp-6w8w-w647"}, "properties": {"repobilityId": "5e89d6a5e54f1947", "scanner": "scanner-primary", "fingerprint": "9d1383d39fd08f35", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m5qp-6w8w-w647"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c7fc364b8230458f", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-m6qw-4cw2-hm4m"}, "properties": {"repobilityId": "c9911bc967c559ca", "scanner": "scanner-primary", "fingerprint": "c7fc364b8230458f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m6qw-4cw2-hm4m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b3e3b387bad0d80", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-mwh4-6h8g-pg8w"}, "properties": {"repobilityId": "8a3d3232f9818b84", "scanner": "scanner-primary", "fingerprint": "4b3e3b387bad0d80", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mwh4-6h8g-pg8w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29bf4996aa48ac34", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-p998-jp59-783m"}, "properties": {"repobilityId": "161f251789517fb3", "scanner": "scanner-primary", "fingerprint": "29bf4996aa48ac34", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p998-jp59-783m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-42f7dbd34eeac13c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-w2fm-2cpv-w7v5"}, "properties": {"repobilityId": "d7d32d1b01aa0b47", "scanner": "scanner-primary", "fingerprint": "42f7dbd34eeac13c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w2fm-2cpv-w7v5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c0708c829148ab52", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: GHSA-xcgm-r5h9-7989"}, "properties": {"repobilityId": "040d52aad6fb3751", "scanner": "scanner-primary", "fingerprint": "c0708c829148ab52", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xcgm-r5h9-7989"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-efe96a59942df855", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2094"}, "properties": {"repobilityId": "0387c1b85d74f4ed", "scanner": "scanner-primary", "fingerprint": "efe96a59942df855", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2094"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bdd5476454137428", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2095"}, "properties": {"repobilityId": "5f31e99c2c55d644", "scanner": "scanner-primary", "fingerprint": "bdd5476454137428", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2095"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-36a9ed9825abec46", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2097"}, "properties": {"repobilityId": "8bea7c3c251f6060", "scanner": "scanner-primary", "fingerprint": "36a9ed9825abec46", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2097"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4e6d996955fe2aee", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2098"}, "properties": {"repobilityId": "2ad0ecab9d274e71", "scanner": "scanner-primary", "fingerprint": "4e6d996955fe2aee", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2098"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ed2b8963814a1237", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2100"}, "properties": {"repobilityId": "24c78effaa40eebf", "scanner": "scanner-primary", "fingerprint": "ed2b8963814a1237", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2100"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8459238f0f24dfa9", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2101"}, "properties": {"repobilityId": "a2ecfb4978b6e1ef", "scanner": "scanner-primary", "fingerprint": "8459238f0f24dfa9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2101"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cfd946f083c3fdd", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2102"}, "properties": {"repobilityId": "1e2b4731b536ce8a", "scanner": "scanner-primary", "fingerprint": "7cfd946f083c3fdd", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2102"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-178e037badb1d97c", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2103"}, "properties": {"repobilityId": "4b55e4d387e0e786", "scanner": "scanner-primary", "fingerprint": "178e037badb1d97c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2103"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cc4eeaf5812e4da5", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2104"}, "properties": {"repobilityId": "c521ccce96eb012b", "scanner": "scanner-primary", "fingerprint": "cc4eeaf5812e4da5", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2104"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d86f28942ec95de6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2105"}, "properties": {"repobilityId": "fb3ead7c796bac7f", "scanner": "scanner-primary", "fingerprint": "d86f28942ec95de6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2105"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d844c2ae1a8955ff", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2106"}, "properties": {"repobilityId": "4457047245c0c2cd", "scanner": "scanner-primary", "fingerprint": "d844c2ae1a8955ff", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2106"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3bed74be25763b6", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2108"}, "properties": {"repobilityId": "cc65385679179c2e", "scanner": "scanner-primary", "fingerprint": "b3bed74be25763b6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2108"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9dbd79f569e97d08", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2109"}, "properties": {"repobilityId": "e496766550d548d2", "scanner": "scanner-primary", "fingerprint": "9dbd79f569e97d08", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2109"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-385291c68642e7c3", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2110"}, "properties": {"repobilityId": "4a93247cae6650d6", "scanner": "scanner-primary", "fingerprint": "385291c68642e7c3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2110"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b071ccd679537de1", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2111"}, "properties": {"repobilityId": "d6e2cc234947d8ce", "scanner": "scanner-primary", "fingerprint": "b071ccd679537de1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2111"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-184e843d542d2f54", "level": "warning", "message": {"text": "Vulnerable dependency aiohttp 3.13.3: PYSEC-2026-2113"}, "properties": {"repobilityId": "567f6f5b1b73c5da", "scanner": "scanner-primary", "fingerprint": "184e843d542d2f54", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2113"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e020a884ce691a0", "level": "warning", "message": {"text": "Vulnerable dependency lxml 6.0.2: GHSA-vfmq-68hx-4jfw"}, "properties": {"repobilityId": "683b60e1b81ffebe", "scanner": "scanner-primary", "fingerprint": "5e020a884ce691a0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfmq-68hx-4jfw"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-21895d371778d4fc", "level": "warning", "message": {"text": "Vulnerable dependency lxml 6.0.2: PYSEC-2026-87"}, "properties": {"repobilityId": "b8cac1718ed3ecae", "scanner": "scanner-primary", "fingerprint": "21895d371778d4fc", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-87"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28778d523a11cc4f", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.27.1: GHSA-hvrp-rf83-w775"}, "properties": {"repobilityId": "ba84a07be0b7a1a1", "scanner": "scanner-primary", "fingerprint": "28778d523a11cc4f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hvrp-rf83-w775"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-11e70092a10b83a9", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.27.1: GHSA-jpw9-pfvf-9f58"}, "properties": {"repobilityId": "5f11b5eb63285ba4", "scanner": "scanner-primary", "fingerprint": "11e70092a10b83a9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jpw9-pfvf-9f58"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-531df51c5b1c0a8b", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.27.1: GHSA-vj7q-gjh5-988w"}, "properties": {"repobilityId": "dfc0a611789a8911", "scanner": "scanner-primary", "fingerprint": "531df51c5b1c0a8b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vj7q-gjh5-988w"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b17bbc17fb18785d", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3481"}, "properties": {"repobilityId": "36b1ee2781ae541a", "scanner": "scanner-primary", "fingerprint": "b17bbc17fb18785d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3481"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-097486ce09a16abb", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3482"}, "properties": {"repobilityId": "629e2a531f5ea307", "scanner": "scanner-primary", "fingerprint": "097486ce09a16abb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3482"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-945ffc2907864939", "level": "warning", "message": {"text": "Vulnerable dependency mcp 1.27.1: PYSEC-2026-3483"}, "properties": {"repobilityId": "13af8166218c9995", "scanner": "scanner-primary", "fingerprint": "945ffc2907864939", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3483"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-26b6f8b3807a7d11", "level": "error", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-45hq-cxwh-f6vc"}, "properties": {"repobilityId": "aa3b14739bbef72b", "scanner": "scanner-primary", "fingerprint": "26b6f8b3807a7d11", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-45hq-cxwh-f6vc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e179a0cd7e264c13", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-4x4j-2g7c-83w6"}, "properties": {"repobilityId": "91e8a03e577bae02", "scanner": "scanner-primary", "fingerprint": "e179a0cd7e264c13", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4x4j-2g7c-83w6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d3a36f07ef177754", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-5x94-69rx-g8h2"}, "properties": {"repobilityId": "2d4c8223e6626769", "scanner": "scanner-primary", "fingerprint": "d3a36f07ef177754", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-5x94-69rx-g8h2"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5384747de2e37c98", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-62p4-gmf7-7g93"}, "properties": {"repobilityId": "e653fe36805aafaa", "scanner": "scanner-primary", "fingerprint": "5384747de2e37c98", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-62p4-gmf7-7g93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f8beff4a9af5c5be", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-6r8x-57c9-28j4"}, "properties": {"repobilityId": "1b486a2481908eff", "scanner": "scanner-primary", "fingerprint": "f8beff4a9af5c5be", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6r8x-57c9-28j4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f8488f3a91f8df65", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-8v84-f9pq-wr9x"}, "properties": {"repobilityId": "ef47e84b0e5ae1e5", "scanner": "scanner-primary", "fingerprint": "f8488f3a91f8df65", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8v84-f9pq-wr9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7602a07828225ac7", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-9hw9-ch79-4vh6"}, "properties": {"repobilityId": "37c76b536a5e3ca7", "scanner": "scanner-primary", "fingerprint": "7602a07828225ac7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-9hw9-ch79-4vh6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6c920ed71172c7ef", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-fj7v-r99m-22gq"}, "properties": {"repobilityId": "8c5f2bae30f4808b", "scanner": "scanner-primary", "fingerprint": "6c920ed71172c7ef", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-fj7v-r99m-22gq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae690675f1331b95", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-jjj6-mw9f-p565"}, "properties": {"repobilityId": "8c12a8bae91406e6", "scanner": "scanner-primary", "fingerprint": "ae690675f1331b95", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-jjj6-mw9f-p565"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-92d8e588e496021f", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-pg7v-jwj7-p798"}, "properties": {"repobilityId": "8a8b9d176a7eab87", "scanner": "scanner-primary", "fingerprint": "92d8e588e496021f", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-pg7v-jwj7-p798"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-06c84b207e834da7", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-phj9-mv4w-65pm"}, "properties": {"repobilityId": "d63a858112ef3b9e", "scanner": "scanner-primary", "fingerprint": "06c84b207e834da7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-phj9-mv4w-65pm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-70b58a986e4ca70b", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-vjc4-5qp5-m44j"}, "properties": {"repobilityId": "688ba43d96b2dd12", "scanner": "scanner-primary", "fingerprint": "70b58a986e4ca70b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vjc4-5qp5-m44j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f29ea915376b373", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: GHSA-xj96-63gp-2gmr"}, "properties": {"repobilityId": "679c10bad6992102", "scanner": "scanner-primary", "fingerprint": "4f29ea915376b373", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xj96-63gp-2gmr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dfd30679f5478158", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2253"}, "properties": {"repobilityId": "891c3462b41343de", "scanner": "scanner-primary", "fingerprint": "dfd30679f5478158", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2253"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-967f2045d8f37ea1", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2254"}, "properties": {"repobilityId": "7241fed9159a329f", "scanner": "scanner-primary", "fingerprint": "967f2045d8f37ea1", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2254"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3e0e9722f366f4c4", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-2256"}, "properties": {"repobilityId": "405c39729d33471e", "scanner": "scanner-primary", "fingerprint": "3e0e9722f366f4c4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2256"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4302a20b8a3a5346", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3451"}, "properties": {"repobilityId": "5b67c7a9904cbe1c", "scanner": "scanner-primary", "fingerprint": "4302a20b8a3a5346", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3451"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b7917dff4db13603", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3452"}, "properties": {"repobilityId": "acdbadc9bebb3b65", "scanner": "scanner-primary", "fingerprint": "b7917dff4db13603", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3452"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ad66eec714af149", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3453"}, "properties": {"repobilityId": "f72507b3412cd61f", "scanner": "scanner-primary", "fingerprint": "0ad66eec714af149", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3453"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7601908cb7bf2225", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3454"}, "properties": {"repobilityId": "fd76508ac4181e95", "scanner": "scanner-primary", "fingerprint": "7601908cb7bf2225", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3454"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad0db56c4ac414b9", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3493"}, "properties": {"repobilityId": "45d81e171a4d5c15", "scanner": "scanner-primary", "fingerprint": "ad0db56c4ac414b9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3493"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e5171d7207f6b07", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3494"}, "properties": {"repobilityId": "c6d9c611a8cbcab2", "scanner": "scanner-primary", "fingerprint": "6e5171d7207f6b07", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3494"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f2f22e193493c3c", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3495"}, "properties": {"repobilityId": "380af25374980d21", "scanner": "scanner-primary", "fingerprint": "8f2f22e193493c3c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3495"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-979def41aaef6c02", "level": "warning", "message": {"text": "Vulnerable dependency pillow 12.2.0: PYSEC-2026-3496"}, "properties": {"repobilityId": "2872a86f1c3df355", "scanner": "scanner-primary", "fingerprint": "979def41aaef6c02", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-3496"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pyproject.toml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4fe508fe435c3eb", "level": "warning", "message": {"text": "Vulnerable dependency python-dotenv 1.2.1: GHSA-mf9w-mj56-hr94"}, "properties": {"repobilityId": "c0b0f199ae9f3260", "scanner": "scanner-primary", "fingerprint": "f4fe508fe435c3eb", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mf9w-mj56-hr94"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-739fa31a9483e558", "level": "warning", "message": {"text": "Vulnerable dependency python-dotenv 1.2.1: PYSEC-2026-2270"}, "properties": {"repobilityId": "13b6671508444c05", "scanner": "scanner-primary", "fingerprint": "739fa31a9483e558", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "PYSEC-2026-2270"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "uv.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-983c20c586ea3ae3", "level": "error", "message": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-52cp-r559-cp3m"}, "properties": {"repobilityId": "bb9354b1169e66e2", "scanner": "scanner-primary", "fingerprint": "983c20c586ea3ae3", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-52cp-r559-cp3m"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f431c20b53cfc9c", "level": "warning", "message": {"text": "Vulnerable dependency js-yaml 4.1.1: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": "2e7af66f705e9148", "scanner": "scanner-primary", "fingerprint": "6f431c20b53cfc9c", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h67p-54hq-rp68"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df6c3416105c8180", "level": "error", "message": {"text": "Vulnerable dependency uuid 13.0.0: GHSA-w5hq-g745-h8pq"}, "properties": {"repobilityId": "00de2562f5f346b0", "scanner": "scanner-primary", "fingerprint": "df6c3416105c8180", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-w5hq-g745-h8pq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f37aa0dcec16e6fe", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.2.4: GHSA-4w7w-66w2-5vf9"}, "properties": {"repobilityId": "7fa56b6d6f1f8e64", "scanner": "scanner-primary", "fingerprint": "f37aa0dcec16e6fe", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-4w7w-66w2-5vf9", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-669deaa7cb137589", "level": "error", "message": {"text": "Vulnerable dependency vite 7.2.4: GHSA-fx2h-pf6j-xcff"}, "properties": {"repobilityId": "2eee4d05c78c73f6", "scanner": "scanner-primary", "fingerprint": "669deaa7cb137589", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-fx2h-pf6j-xcff", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f93f6e98eae25194", "level": "error", "message": {"text": "Vulnerable dependency vite 7.2.4: GHSA-p9ff-h696-f583"}, "properties": {"repobilityId": "f1d2ee7673642680", "scanner": "scanner-primary", "fingerprint": "f93f6e98eae25194", "layer": "dependencies", "severity": "high", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-p9ff-h696-f583", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1fafdba5bbf26059", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.2.4: GHSA-v2wj-q39q-566r"}, "properties": {"repobilityId": "ceac3a583589f0a7", "scanner": "scanner-primary", "fingerprint": "1fafdba5bbf26059", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-v2wj-q39q-566r", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5cc790d06c2d9b3b", "level": "warning", "message": {"text": "Vulnerable dependency vite 7.2.4: GHSA-v6wh-96g9-6wx3"}, "properties": {"repobilityId": "5cd2168d7258bc0b", "scanner": "scanner-primary", "fingerprint": "5cc790d06c2d9b3b", "layer": "dependencies", "severity": "medium", "confidence": 0.7, "tags": ["dependency", "sca", "osv", "GHSA-v6wh-96g9-6wx3", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6c267888a2469717", "level": "warning", "message": {"text": "Vulnerable dependency @isaacs/brace-expansion 5.0.0: GHSA-7h2j-956f-4vf2"}, "properties": {"repobilityId": "186e348e58e9af75", "scanner": "scanner-primary", "fingerprint": "6c267888a2469717", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7h2j-956f-4vf2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b42bec48d22ccce8", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-39q2-94rc-95cp"}, "properties": {"repobilityId": "61f08753a18c0b3a", "scanner": "scanner-primary", "fingerprint": "b42bec48d22ccce8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-39q2-94rc-95cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f92adac25e76894", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-76mc-f452-cxcm"}, "properties": {"repobilityId": "13b61e5d95a03ef4", "scanner": "scanner-primary", "fingerprint": "8f92adac25e76894", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-76mc-f452-cxcm", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0ec2dd47549a346", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-c2j3-45gr-mqc4"}, "properties": {"repobilityId": "17d9b81628af7cbe", "scanner": "scanner-primary", "fingerprint": "b0ec2dd47549a346", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-c2j3-45gr-mqc4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3b28afcd2e4da07", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-cj63-jhhr-wcxv"}, "properties": {"repobilityId": "1b22f3515d03f8a3", "scanner": "scanner-primary", "fingerprint": "b3b28afcd2e4da07", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-cj63-jhhr-wcxv", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e1203c81bfd4f38", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-cjmm-f4jc-qw8r"}, "properties": {"repobilityId": "a16f4ac3f8690875", "scanner": "scanner-primary", "fingerprint": "5e1203c81bfd4f38", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-cjmm-f4jc-qw8r", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7974be37e2a06d82", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-cmwh-pvxp-8882"}, "properties": {"repobilityId": "46e7221483875da7", "scanner": "scanner-primary", "fingerprint": "7974be37e2a06d82", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-cmwh-pvxp-8882", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86e7673338c6205b", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-crv5-9vww-q3g8"}, "properties": {"repobilityId": "7bb226e4f8868fbe", "scanner": "scanner-primary", "fingerprint": "86e7673338c6205b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-crv5-9vww-q3g8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b776610a93e32745", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-gvmj-g25r-r7wr"}, "properties": {"repobilityId": "60edabdd408e847d", "scanner": "scanner-primary", "fingerprint": "b776610a93e32745", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gvmj-g25r-r7wr", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e406a031b72ae55", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-h7mw-gpvr-xq4m"}, "properties": {"repobilityId": "c69b9b3b99925805", "scanner": "scanner-primary", "fingerprint": "6e406a031b72ae55", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h7mw-gpvr-xq4m", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-807cfbec9f23850a", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-h8r8-wccr-v5f2"}, "properties": {"repobilityId": "913a9942701bb2b7", "scanner": "scanner-primary", "fingerprint": "807cfbec9f23850a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-h8r8-wccr-v5f2", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c1babea11b5cb953", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-hpcv-96wg-7vj8"}, "properties": {"repobilityId": "210e1d59e6154513", "scanner": "scanner-primary", "fingerprint": "c1babea11b5cb953", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hpcv-96wg-7vj8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-42fe30043e8586e6", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-r47g-fvhr-h676"}, "properties": {"repobilityId": "2ff0213ba1285230", "scanner": "scanner-primary", "fingerprint": "42fe30043e8586e6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r47g-fvhr-h676", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cd6874b117e2b95b", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-rp9w-3fw7-7cwq"}, "properties": {"repobilityId": "a50262a4afde16ac", "scanner": "scanner-primary", "fingerprint": "cd6874b117e2b95b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rp9w-3fw7-7cwq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4be24907e8e459c9", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-v2wj-7wpq-c8vv"}, "properties": {"repobilityId": "00c82420bfc99f41", "scanner": "scanner-primary", "fingerprint": "4be24907e8e459c9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v2wj-7wpq-c8vv", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7bb85b8174ffddfb", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-v9jr-rg53-9pgp"}, "properties": {"repobilityId": "2690e3a7d82df59b", "scanner": "scanner-primary", "fingerprint": "7bb85b8174ffddfb", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v9jr-rg53-9pgp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-efb3aaf7fc3e8fb6", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-vxr8-fq34-vvx9"}, "properties": {"repobilityId": "dbd7b2ad8a3b5c79", "scanner": "scanner-primary", "fingerprint": "efb3aaf7fc3e8fb6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vxr8-fq34-vvx9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0bef337d3dbdff1", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.3.1: GHSA-x4vx-rjvf-j5p4"}, "properties": {"repobilityId": "66279a31a7873051", "scanner": "scanner-primary", "fingerprint": "b0bef337d3dbdff1", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-x4vx-rjvf-j5p4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b38b41feba2d0049", "level": "warning", "message": {"text": "Vulnerable dependency esbuild 0.21.5: GHSA-67mh-4wv8-2f99"}, "properties": {"repobilityId": "be00f073db852f14", "scanner": "scanner-primary", "fingerprint": "b38b41feba2d0049", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-67mh-4wv8-2f99", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a26446024ab210b8", "level": "error", "message": {"text": "Vulnerable dependency linkify-it 5.0.0: GHSA-22p9-wv53-3rq4"}, "properties": {"repobilityId": "b141a67d3dd0eff8", "scanner": "scanner-primary", "fingerprint": "a26446024ab210b8", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-22p9-wv53-3rq4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72ae09e814e9225e", "level": "warning", "message": {"text": "Vulnerable dependency linkify-it 5.0.0: GHSA-v245-v573-v5vm"}, "properties": {"repobilityId": "f628c57d04e907c7", "scanner": "scanner-primary", "fingerprint": "72ae09e814e9225e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v245-v573-v5vm", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7ed851b2680410c6", "level": "warning", "message": {"text": "Vulnerable dependency lodash-es 4.17.22: GHSA-f23m-r3pf-42rh"}, "properties": {"repobilityId": "ba5b3270f83b6cc1", "scanner": "scanner-primary", "fingerprint": "7ed851b2680410c6", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f23m-r3pf-42rh", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4208ccad857d3060", "level": "error", "message": {"text": "Vulnerable dependency lodash-es 4.17.22: GHSA-r5fr-rjxr-66jc"}, "properties": {"repobilityId": "8835d7e3fad91db0", "scanner": "scanner-primary", "fingerprint": "4208ccad857d3060", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r5fr-rjxr-66jc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3048e345e321e32a", "level": "warning", "message": {"text": "Vulnerable dependency markdown-it 14.1.0: GHSA-38c4-r59v-3vqw"}, "properties": {"repobilityId": "6261f3c22545eeb3", "scanner": "scanner-primary", "fingerprint": "3048e345e321e32a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-38c4-r59v-3vqw", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0bcdf712124063e", "level": "warning", "message": {"text": "Vulnerable dependency markdown-it 14.1.0: GHSA-6v5v-wf23-fmfq"}, "properties": {"repobilityId": "01a88a20352ee866", "scanner": "scanner-primary", "fingerprint": "b0bcdf712124063e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6v5v-wf23-fmfq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-74224f48f5eea0ee", "level": "error", "message": {"text": "Vulnerable dependency minimatch 10.1.1: GHSA-23c5-xmqv-rm74"}, "properties": {"repobilityId": "e0c871f5ede81d5e", "scanner": "scanner-primary", "fingerprint": "74224f48f5eea0ee", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-23c5-xmqv-rm74", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-da30265ba3ffaafd", "level": "error", "message": {"text": "Vulnerable dependency minimatch 10.1.1: GHSA-3ppc-4f35-3m26"}, "properties": {"repobilityId": "0dbb5fb10e6add01", "scanner": "scanner-primary", "fingerprint": "da30265ba3ffaafd", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3ppc-4f35-3m26", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff378d2aaf4654c7", "level": "error", "message": {"text": "Vulnerable dependency minimatch 10.1.1: GHSA-7r86-cg39-jmmj"}, "properties": {"repobilityId": "41fd44312bbb9c78", "scanner": "scanner-primary", "fingerprint": "ff378d2aaf4654c7", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7r86-cg39-jmmj", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-65995639c3a75424", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "b8944461c8644339", "scanner": "scanner-primary", "fingerprint": "65995639c3a75424", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2b61b17e63d0c84", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "6c83605d3aa8fcef", "scanner": "scanner-primary", "fingerprint": "d2b61b17e63d0c84", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-067de11778c7b000", "level": "error", "message": {"text": "Vulnerable dependency preact 10.28.1: GHSA-36hm-qxxp-pg3m"}, "properties": {"repobilityId": "50e48ce479902b98", "scanner": "scanner-primary", "fingerprint": "067de11778c7b000", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-36hm-qxxp-pg3m", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4d2e0b474519a79d", "level": "warning", "message": {"text": "Vulnerable dependency rollup 4.54.0: GHSA-mw96-cpmx-2vgc"}, "properties": {"repobilityId": "ebbc23df1b6d7736", "scanner": "scanner-primary", "fingerprint": "4d2e0b474519a79d", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mw96-cpmx-2vgc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb7af4c61120c534", "level": "warning", "message": {"text": "Vulnerable dependency lodash-es 4.17.21: GHSA-f23m-r3pf-42rh"}, "properties": {"repobilityId": "7b3f6fdf7d11ec7d", "scanner": "scanner-primary", "fingerprint": "eb7af4c61120c534", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f23m-r3pf-42rh", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5dd81c81becbf0", "level": "error", "message": {"text": "Vulnerable dependency lodash-es 4.17.21: GHSA-r5fr-rjxr-66jc"}, "properties": {"repobilityId": "ac56e476e2fa190f", "scanner": "scanner-primary", "fingerprint": "aa5dd81c81becbf0", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r5fr-rjxr-66jc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/bun.lock"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c551a312a19d4b32", "level": "warning", "message": {"text": "Dependency ai is two or more major versions behind"}, "properties": {"repobilityId": "901a7747e551a770", "scanner": "scanner-primary", "fingerprint": "c551a312a19d4b32", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-461956b7cb09e112", "level": "note", "message": {"text": "Dependency diff is a major version behind"}, "properties": {"repobilityId": "ebecd15583d90dd0", "scanner": "scanner-primary", "fingerprint": "461956b7cb09e112", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7edef27cb5011917", "level": "note", "message": {"text": "Dependency js-yaml is a major version behind"}, "properties": {"repobilityId": "a439aa97ff005402", "scanner": "scanner-primary", "fingerprint": "7edef27cb5011917", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3b7570e32489e46f", "level": "note", "message": {"text": "Dependency lucide-react is a major version behind"}, "properties": {"repobilityId": "1e5345fe9b16a9af", "scanner": "scanner-primary", "fingerprint": "3b7570e32489e46f", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ee979033c0becf23", "level": "note", "message": {"text": "Dependency nanoid is a major version behind"}, "properties": {"repobilityId": "81961ac3c68569b7", "scanner": "scanner-primary", "fingerprint": "ee979033c0becf23", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ec26d8f79d4f1591", "level": "error", "message": {"text": "Dangling fetch: POST /api/open-in (vis/src/lib/api.ts:263)"}, "properties": {"repobilityId": "95963f1d8a95a792", "scanner": "scanner-primary", "fingerprint": "ec26d8f79d4f1591", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "vis/src/lib/api.ts"}, "region": {"startLine": 263}}}]}, {"ruleId": "scanner-1abbf23209de6710", "level": "error", "message": {"text": "Dangling fetch: POST /api/open-in (web/src/features/chat/open-in-shared.ts:76)"}, "properties": {"repobilityId": "e872a3361606e47e", "scanner": "scanner-primary", "fingerprint": "1abbf23209de6710", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/features/chat/open-in-shared.ts"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-7e6d161776b758bd", "level": "note", "message": {"text": "16 backend endpoints not called by scanned frontend"}, "properties": {"repobilityId": "3c8e96670c5e1f9f", "scanner": "scanner-primary", "fingerprint": "7e6d161776b758bd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}