Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

anki2003ta/Museum

https://github.com/anki2003ta/Museum · scanned 2026-08-30 06:42 UTC (1 week, 5 days ago)

350 raw signals (0 security + 350 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 1 week, 5 days ago · v1 · 348 actionable findings from 1 signal source. 2 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Scan summary Repository scanned at 74.7/100 with 100.0% coverage. It contains 211 nodes across 16 cross-layer flows, written primarily in mixed languages. Engine surfaced 350 findings — concentrated in dependencies (177), security (159), quality (7). Risk profile is high: 6 critical, 96 high, 208 medium. Recommended next step: open the dependencies layer findings first — that's where the highest-impact wins live.

Showing 348 of 348 actionable findings. 350 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

critical System graph security Trivy conf 1.00 CVE-2025-23061: mongoose 8.5.1 — package-lock.json
Mongoose search injection vulnerability Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. Package: mongoose Installed: 8.5.1 Fixed in: 8.9.5, 7.8.4, 6.13.6 …
VulnCve 2025 23061
critical System graph security Trivy conf 1.00 CVE-2025-29927: next 14.2.7 — museum-ticket-booking/package-lock.json
nextjs: Authorization Bypass in Next.js Middleware Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authori…
VulnCve 2025 29927
critical System graph security Trivy conf 1.00 CVE-2025-68428: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jspdf: jsPDF Local File Inclusion/Path Traversal vulnerability jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsa…
VulnCve 2025 68428
critical System graph security Trivy conf 1.00 CVE-2025-7783: form-data 3.0.1 — package-lock.json
form-data: Unsafe random function in form-data Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3. Package:…
VulnCve 2025 7783
critical System graph security Trivy conf 1.00 CVE-2025-7783: form-data 4.0.0 — museum-ticket-booking/package-lock.json
form-data: Unsafe random function in form-data Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3. Package:…
VulnCve 2025 7783
critical System graph security Trivy conf 1.00 CVE-2026-31938: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jspdf: jsPDF: Cross site scripting via unsanitized output options jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the crea…
VulnCve 2026 31938
high System graph security Trivy conf 1.00 CVE-2024-21538: cross-spawn 7.0.3 — museum-ticket-booking/package-lock.json
cross-spawn: regular expression denial of service Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by craftin…
VulnCve 2024 21538
high System graph security Trivy conf 1.00 CVE-2024-46982: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js Cache Poisoning Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is s…
VulnCve 2024 46982
high System graph security Trivy conf 1.00 CVE-2024-51479: next 14.2.7 — museum-ticket-booking/package-lock.json
next.js: next: authorization bypass in Next.js Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly …
VulnCve 2024 51479
high System graph security Trivy conf 1.00 CVE-2024-52798: path-to-regexp 0.1.10 — package-lock.json
path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to bac…
VulnCve 2024 52798
high System graph security Trivy conf 1.00 CVE-2024-53900: mongoose 8.5.1 — package-lock.json
Mongoose search injection vulnerability Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. Package: mongoose Installed: 8.5.1 Fixed in: 8.8.3, 7.8.3, 6.13.5, 5.13.23 Severity: HIGH Fix: Upgrade mongoose to 8.8.3, 7.8.3, 6.13.5, 5.13.23
VulnCve 2024 53900
high System graph security Trivy conf 1.00 CVE-2025-12613: cloudinary 1.41.3 — package-lock.json
Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject …
VulnCve 2025 12613
high System graph security Trivy conf 1.00 CVE-2025-12758: validator 13.12.0 — package-lock.json
Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode vari…
VulnCve 2025 12758
high System graph security Trivy conf 1.00 CVE-2025-25977: canvg 3.0.10 — museum-ticket-booking/package-lock.json
canvg: Prototype Pollution Vulneralbility An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement. Package: canvg Installed: 3.0.10 Fixed in: 4.0.3, 3.0.11 Severity: HIGH Fix: Upgrade canvg to 4.0.3, 3.0.11
VulnCve 2025 25977
high System graph security Trivy conf 1.00 CVE-2025-27152: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specifie…
VulnCve 2025 27152
high System graph security Trivy conf 1.00 CVE-2025-29907: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF Bypass Regular Expression Denial of Service (ReDoS) jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitised image urls to the ad…
VulnCve 2025 29907
high System graph security Trivy conf 1.00 CVE-2025-47935: multer 1.4.5-lts.1 — package-lock.json
Multer vulnerable to Denial of Service via memory leaks from unclosed streams Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource exhaustion and memory leak issue due to improper stream handling. When the HTTP request stream emits…
VulnCve 2025 47935
high System graph security Trivy conf 1.00 CVE-2025-47944: multer 1.4.5-lts.1 — package-lock.json
Multer vulnerable to Denial of Service from maliciously crafted requests Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.0 allows an attacker to trigger a Denial of Service (DoS) by sending …
VulnCve 2025 47944
high System graph security Trivy conf 1.00 CVE-2025-48997: multer 1.4.5-lts.1 — package-lock.json
multer: Multer vulnerable to Denial of Service via unhandled exception Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an…
VulnCve 2025 48997
high System graph security Trivy conf 1.00 CVE-2025-57810: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jspdf: jsPDF Denial of Service (DoS) jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method…
VulnCve 2025 57810
high System graph security Trivy conf 1.00 CVE-2025-58754: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios DoS via lack of data size check Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http …
VulnCve 2025 58754
high System graph security Trivy conf 1.00 CVE-2025-7338: multer 1.4.5-lts.1 — package-lock.json
multer: Multer Denial of Service Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. T…
VulnCve 2025 7338
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 3.0.1 — package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.0 — museum-ticket-booking/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 1.1.11 — package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 2.0.1 — package-lock.json
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-14257: brace-expansion 1.1.11 — package-lock.json
brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the lengt…
VulnCve 2026 14257
high System graph security Trivy conf 1.00 CVE-2026-14257: brace-expansion 2.0.1 — package-lock.json
brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the lengt…
VulnCve 2026 14257
high System graph security Trivy conf 1.00 CVE-2026-2359: multer 1.4.5-lts.1 — package-lock.json
multer: Multer: Denial of Service via dropped file upload connections Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially c…
VulnCve 2026 2359
high System graph security Trivy conf 1.00 CVE-2026-24133: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF: jsPDF: Denial of Service due to excessive memory allocation from crafted BMP images jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method results in denial of service. If given the possibility to pass unsanitized image d…
VulnCve 2026 24133
high System graph security Trivy conf 1.00 CVE-2026-24737: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF: jsPDF: Arbitrary code execution via unsanitized input in Acroform module jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the po…
VulnCve 2026 24737
high System graph security Trivy conf 1.00 CVE-2026-25535: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF: denial of service via malicious GIF dimensions jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage` metho…
VulnCve 2026 25535
high System graph security Trivy conf 1.00 CVE-2026-25639: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ a…
VulnCve 2026 25639
high System graph security Trivy conf 1.00 CVE-2026-25755: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF: PDF object injection via unsanitized input in addJS method jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes…
VulnCve 2026 25755
high System graph security Trivy conf 1.00 CVE-2026-25940: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF: PDF injection in AcroForm module allows arbitrary JavaScript execution (RadioButton children) jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript act…
VulnCve 2026 25940
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 3.1.2 — package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-26996: minimatch 5.1.6 — package-lock.json
minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains …
VulnCve 2026 26996
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 3.1.2 — package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27903: minimatch 5.1.6 — package-lock.json
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne(…
VulnCve 2026 27903
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 3.1.2 — package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-27904: minimatch 5.1.6 — package-lock.json
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs prod…
VulnCve 2026 27904
high System graph security Trivy conf 1.00 CVE-2026-31898: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jspdf: jsPDF: Arbitrary code execution via unsanitized input in createAnnotation method jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If…
VulnCve 2026 31898
high System graph security Trivy conf 1.00 CVE-2026-3304: multer 1.4.5-lts.1 — package-lock.json
multer: Multer: Denial of Service via malformed requests Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustio…
VulnCve 2026 3304
high System graph security Trivy conf 1.00 CVE-2026-33671: picomatch 2.3.1 — package-lock.json
picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain pattern…
VulnCve 2026 33671
high System graph security Trivy conf 1.00 CVE-2026-3520: multer 1.4.5-lts.1 — package-lock.json
multer: Multer: Denial of Service via malformed requests Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Us…
VulnCve 2026 3520
high System graph security Trivy conf 1.00 CVE-2026-42033: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: HTTP Transport Hijacking via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) s…
VulnCve 2026 42033
high System graph security Trivy conf 1.00 CVE-2026-42035: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Arbitrary HTTP header injection via prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP …
VulnCve 2026 42035
high System graph security Trivy conf 1.00 CVE-2026-42043: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: NO_PROXY bypass via crafted URL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the …
VulnCve 2026 42043
high System graph security Trivy conf 1.00 CVE-2026-42264: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Prototype pollution allows information disclosure and request manipulation Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the…
VulnCve 2026 42264
high System graph security Trivy conf 1.00 CVE-2026-42334: mongoose 8.5.1 — package-lock.json
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization …
VulnCve 2026 42334
high System graph security Trivy conf 1.00 CVE-2026-44486: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Information disclosure of proxy credentials via HTTP redirects Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent throug…
VulnCve 2026 44486
high System graph security Trivy conf 1.00 CVE-2026-44487: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Information disclosure of proxy credentials via redirect flows Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct re…
VulnCve 2026 44487
high System graph security Trivy conf 1.00 CVE-2026-44488: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Denial of Service due to unenforced request and response size limits Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Appli…
VulnCve 2026 44488
high System graph security Trivy conf 1.00 CVE-2026-44494: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the applicatio…
VulnCve 2026 44494
high System graph security Trivy conf 1.00 CVE-2026-44495: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Information disclosure due to prototype pollution vulnerability Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav…
VulnCve 2026 44495
high System graph security Trivy conf 1.00 CVE-2026-44496: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
VulnCve 2026 44496
high System graph security Trivy conf 1.00 CVE-2026-44573: next 14.2.7 — museum-ticket-booking/package-lock.json
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44578: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-45623: postcss 8.4.31 — museum-ticket-booking/package-lock.json
postcss: PostCSS: Information disclosure and denial of service via crafted CSS input PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PA…
VulnCve 2026 45623
high System graph security Trivy conf 1.00 CVE-2026-4800: lodash 4.17.21 — package-lock.json
lodash: lodash: Arbitrary code execution via untrusted input in template imports Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both p…
VulnCve 2026 4800
high System graph security Trivy conf 1.00 CVE-2026-4867: path-to-regexp 0.1.10 — package-lock.json
path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c o…
VulnCve 2026 4867
high System graph security Trivy conf 1.00 CVE-2026-5079: multer 1.4.5-lts.1 — package-lock.json
multer: Multer: Denial of Service via deeply nested field names in multipart form data Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in fi…
VulnCve 2026 5079
high System graph security Trivy conf 1.00 CVE-2026-64641: next 14.2.7 — museum-ticket-booking/package-lock.json
next: Next.js: Denial of Service via crafted requests to App Router with Server Actions Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at lea…
VulnCve 2026 64641
high System graph security Trivy conf 1.00 CVE-2026-64645: next 14.2.7 — museum-ticket-booking/package-lock.json
next: Next.js: Server-Side Request Forgery vulnerability Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled inp…
VulnCve 2026 64645
high System graph security Trivy conf 1.00 CVE-2026-64649: next 14.2.7 — museum-ticket-booking/package-lock.json
next: Next.js: Server-Side Request Forgery via malicious host redirection in Server Actions Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can ca…
VulnCve 2026 64649
high System graph security Trivy conf 1.00 CVE-2026-67213: nanoid 3.3.7 — museum-ticket-booking/package-lock.json
nanoid: nanoid: Denial of Service via infinite loop in random ID generation nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit conditio…
VulnCve 2026 67213
high System graph security Trivy conf 1.00 CVE-2026-67214: nanoid 3.3.7 — museum-ticket-booking/package-lock.json
nanoid: nanoid: Denial of Service via negative size input in non-secure module functions nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the …
VulnCve 2026 67214
high System graph security Trivy conf 1.00 CVE-2026-69152: brace-expansion 1.1.11 — package-lock.json
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-altern…
VulnCve 2026 69152
high System graph security Trivy conf 1.00 CVE-2026-69152: brace-expansion 2.0.1 — package-lock.json
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-altern…
VulnCve 2026 69152
high System graph security Trivy conf 1.00 CVE-2026-73646: postcss 8.4.31 — museum-ticket-booking/package-lock.json
PostCSS takes a CSS file and provides an API to analyze and modify its ... PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL…
VulnCve 2026 73646
high System graph security Trivy conf 1.00 DS-0002: Image user should not be 'root' — Dockerfile
Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 Severity: HIGH Target: Dockerfile
Misconfig
high System graph security Trivy conf 1.00 GHSA-5j59-xgg2-r9c4: next 14.2.7 — museum-ticket-booking/package-lock.json
Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up It was discovered that the fix for [CVE-2025-55184](https://github.com/advisories/GHSA-2m3v-v2m8-q956) in React Server Components was incomplete and did not fully mitigate denial-of-service conditions across all payload…
VulnGhsa 5j59 xgg2 r9c4
high System graph security Trivy conf 1.00 GHSA-8h8q-6873-q5fj: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js Vulnerable to Denial of Service with Server Components A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-…
VulnGhsa 8h8q 6873 q5fj
high System graph security Trivy conf 1.00 GHSA-h25m-26qc-wcjf: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components A vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x usin…
VulnGhsa h25m 26qc wcjf
high System graph security Trivy conf 1.00 GHSA-mwv6-3258-q52c: next 14.2.7 — museum-ticket-booking/package-lock.json
Next Vulnerable to Denial of Service with Server Components A vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is track…
VulnGhsa mwv6 3258 q52c
high System graph security Trivy conf 1.00 GHSA-q4gf-8mx6-v5v3: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js has a Denial of Service with Server Components A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-238…
VulnGhsa q4gf 8mx6 v5v3
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-35jp-ww65-95wh
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-35jp-ww65-95wh (aka CVE-2026-44494). axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` Aliases: CVE-2026-44494 Advisory: https://osv.dev…
museum-ticket-booking/package.json ScaOsvGhsa 35jp ww65 95wh
high System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-3g43-6gmg-66jw
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3g43-6gmg-66jw (aka CVE-2026-44495). axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge Aliases: CVE-2026-44495 Advisory: …
museum-ticket-booking/package.json ScaOsvGhsa 3g43 6gmg 66jw
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.11: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `1.1.11` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expan…
museum-ticket-booking/package-lock.json ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.11: GHSA-mh99-v99m-4gvg
OSV.dev reports `brace-expansion` at version `1.1.11` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expan…
museum-ticket-booking/package-lock.json ScaOsvGhsa mh99 v99m 4gvg
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.11: GHSA-rgw5-rvv9-x895
OSV.dev reports `brace-expansion` at version `1.1.11` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895 (aka CVE-2026-69152). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expan…
museum-ticket-booking/package-lock.json ScaOsvGhsa rgw5 rvv9 x895
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.1: GHSA-3jxr-9vmj-r5cp
OSV.dev reports `brace-expansion` at version `2.0.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expans…
museum-ticket-booking/package-lock.json ScaOsvGhsa 3jxr 9vmj r5cp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.1: GHSA-mh99-v99m-4gvg
OSV.dev reports `brace-expansion` at version `2.0.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expans…
museum-ticket-booking/package-lock.json ScaOsvGhsa mh99 v99m 4gvg
high System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.1: GHSA-rgw5-rvv9-x895
OSV.dev reports `brace-expansion` at version `2.0.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-rgw5-rvv9-x895 (aka CVE-2026-69152). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expans…
museum-ticket-booking/package-lock.json ScaOsvGhsa rgw5 rvv9 x895
high System graph dependencies dependencies conf 0.90 Vulnerable dependency flatted 3.3.1: GHSA-25h7-pfq9-p65f
OSV.dev reports `flatted` at version `3.3.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-25h7-pfq9-p65f (aka CVE-2026-32141). Note: `flatted` is a transitive dependency — pulled in by another package, not declared directly in a manifest. flatted vulnerable to unboun…
museum-ticket-booking/package-lock.json ScaOsvGhsa 25h7 pfq9 p65f
high System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-5p4m-2wfm-xmqj
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-5p4m-2wfm-xmqj. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. JS-YAML: Quadratic CPU consumption in !!omap reso…
museum-ticket-booking/package-lock.json ScaOsvGhsa 5p4m 2wfm xmqj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.1.2: GHSA-23c5-xmqv-rm74
OSV.dev reports `minimatch` at version `3.1.2` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch ReDoS: nested …
museum-ticket-booking/package-lock.json ScaOsvGhsa 23c5 xmqv rm74
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.1.2: GHSA-3ppc-4f35-3m26
OSV.dev reports `minimatch` at version `3.1.2` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has a ReDoS vi…
museum-ticket-booking/package-lock.json ScaOsvGhsa 3ppc 4f35 3m26
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 3.1.2: GHSA-7r86-cg39-jmmj
OSV.dev reports `minimatch` at version `3.1.2` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has ReDoS: mat…
museum-ticket-booking/package-lock.json ScaOsvGhsa 7r86 cg39 jmmj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 9.0.3: GHSA-23c5-xmqv-rm74
OSV.dev reports `minimatch` at version `9.0.3` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch ReDoS: nested …
museum-ticket-booking/package-lock.json ScaOsvGhsa 23c5 xmqv rm74
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 9.0.3: GHSA-3ppc-4f35-3m26
OSV.dev reports `minimatch` at version `9.0.3` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has a ReDoS vi…
museum-ticket-booking/package-lock.json ScaOsvGhsa 3ppc 4f35 3m26
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 9.0.3: GHSA-7r86-cg39-jmmj
OSV.dev reports `minimatch` at version `9.0.3` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has ReDoS: mat…
museum-ticket-booking/package-lock.json ScaOsvGhsa 7r86 cg39 jmmj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 9.0.5: GHSA-23c5-xmqv-rm74
OSV.dev reports `minimatch` at version `9.0.5` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-23c5-xmqv-rm74 (aka CVE-2026-27904). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch ReDoS: nested …
museum-ticket-booking/package-lock.json ScaOsvGhsa 23c5 xmqv rm74
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 9.0.5: GHSA-3ppc-4f35-3m26
OSV.dev reports `minimatch` at version `9.0.5` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3ppc-4f35-3m26 (aka CVE-2026-26996). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has a ReDoS vi…
museum-ticket-booking/package-lock.json ScaOsvGhsa 3ppc 4f35 3m26
high System graph dependencies dependencies conf 0.90 Vulnerable dependency minimatch 9.0.5: GHSA-7r86-cg39-jmmj
OSV.dev reports `minimatch` at version `9.0.5` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-7r86-cg39-jmmj (aka CVE-2026-27903). Note: `minimatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. minimatch has ReDoS: mat…
museum-ticket-booking/package-lock.json ScaOsvGhsa 7r86 cg39 jmmj
high System graph dependencies dependencies conf 0.90 Vulnerable dependency nanoid 3.3.7: GHSA-28wg-ghj8-5hjv
OSV.dev reports `nanoid` at version `3.3.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-28wg-ghj8-5hjv (aka CVE-2026-67214). Note: `nanoid` is a transitive dependency — pulled in by another package, not declared directly in a manifest. nanoid: non-secure generators …
museum-ticket-booking/package-lock.json ScaOsvGhsa 28wg ghj8 5hjv
high System graph dependencies dependencies conf 0.90 Vulnerable dependency nanoid 3.3.7: GHSA-2v37-7h3g-55p8
OSV.dev reports `nanoid` at version `3.3.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-2v37-7h3g-55p8 (aka CVE-2026-67213). Note: `nanoid` is a transitive dependency — pulled in by another package, not declared directly in a manifest. nanoid: custom generators can …
museum-ticket-booking/package-lock.json ScaOsvGhsa 2v37 7h3g 55p8
high System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-36qx-fr4f-26g5
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573). Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n Aliases: CVE-2026-44573 Advisory: https://osv.dev/vulnerabili…
museum-ticket-booking/package.json ScaOsvGhsa 36qx fr4f 26g5
high System graph dependencies dependencies conf 1.00 Vulnerable dependency postcss 8.4.31: GHSA-6g55-p6wh-862q
OSV.dev reports `postcss` at version `8.4.31` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623). PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments Aliases: CVE-2026-45623 A…
museum-ticket-booking/package.json ScaOsvGhsa 6g55 p6wh 862q
high System graph dependencies dependencies conf 1.00 Vulnerable dependency postcss 8.4.31: GHSA-r28c-9q8g-f849
OSV.dev reports `postcss` at version `8.4.31` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-r28c-9q8g-f849 (aka CVE-2026-73646). PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure Aliases: CVE-2026-7…
museum-ticket-booking/package.json ScaOsvGhsa r28c 9q8g f849
high System graph dependencies dependencies conf 0.90 Vulnerable dependency postcss 8.4.44: GHSA-6g55-p6wh-862q
OSV.dev reports `postcss` at version `8.4.44` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623). PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments Aliases: CVE-2026-45623 A…
museum-ticket-booking/package-lock.json ScaOsvGhsa 6g55 p6wh 862q
high System graph dependencies dependencies conf 0.90 Vulnerable dependency postcss 8.4.44: GHSA-r28c-9q8g-f849
OSV.dev reports `postcss` at version `8.4.44` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-r28c-9q8g-f849 (aka CVE-2026-73646). PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure Aliases: CVE-2026-7…
museum-ticket-booking/package-lock.json ScaOsvGhsa r28c 9q8g f849
medium System graph quality Tests conf 1.00 CI is configured but no tests are detected
A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal.
CI/CDConfig theaterRepo hardening
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph security Trivy conf 1.00 CVE-2024-55565: nanoid 3.3.7 — museum-ticket-booking/package-lock.json
nanoid: nanoid mishandles non-integer values nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. Package: nanoid Installed: 3.3.7 Fixed in: 5.0.9, 3.3.8 Severity: MEDIUM Fix: Upgrade nanoid to 5.0.9, 3.3.8
VulnCve 2024 55565
medium System graph security Trivy conf 1.00 CVE-2024-56332: next 14.2.7 — museum-ticket-booking/package-lock.json
next.js: Next.js Vulnerable to Denial of Service (DoS) with Server Actions Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows atta…
VulnCve 2024 56332
medium System graph security Trivy conf 1.00 CVE-2025-13465: lodash 4.17.21 — package-lock.json
lodash: prototype pollution in _.unset and _.omit functions Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion o…
VulnCve 2025 13465
medium System graph security Trivy conf 1.00 CVE-2025-15284: qs 6.13.0 — museum-ticket-booking/package-lock.json
qs: qs: Denial of Service via improper input validation in array parsing Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed…
VulnCve 2025 15284
medium System graph security Trivy conf 1.00 CVE-2025-15284: qs 6.13.0 — package-lock.json
qs: qs: Denial of Service via improper input validation in array parsing Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed…
VulnCve 2025 15284
medium System graph security Trivy conf 1.00 CVE-2025-15599: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
DOMPurify: DOMPurify: Cross-site scripting DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can in…
VulnCve 2025 15599
medium System graph security Trivy conf 1.00 CVE-2025-26791: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS). Package: dompurify Installed: 2.5.6 Fixed in: 3.2.4 Severity: MEDIUM Fix: Upgrade …
VulnCve 2025 26791
medium System graph security Trivy conf 1.00 CVE-2025-27789: @babel/runtime 7.25.6 — museum-ticket-booking/package-lock.json
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel w…
VulnCve 2025 27789
medium System graph security Trivy conf 1.00 CVE-2025-55173: next 14.2.7 — museum-ticket-booking/package-lock.json
nextjs: Next.js Content Injection Vulnerability for Image Optimization Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization is vulnerable to content injection. The issue allowed attacker-contr…
VulnCve 2025 55173
medium System graph security Trivy conf 1.00 CVE-2025-56200: validator 13.12.0 — package-lock.json
validator.js has a URL validation bypass vulnerability in its isURL function A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference al…
VulnCve 2025 56200
medium System graph security Trivy conf 1.00 CVE-2025-57752: next 14.2.7 — museum-ticket-booking/package-lock.json
nextjs: Next.js Affected by Cache Key Confusion for Image Optimization API Routes Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When imag…
VulnCve 2025 57752
medium System graph security Trivy conf 1.00 CVE-2025-57822: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js Improper Middleware Redirect Handling Leads to SSRF Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorr…
VulnCve 2025 57822
medium System graph security Trivy conf 1.00 CVE-2025-59471: next 14.2.7 — museum-ticket-booking/package-lock.json
next: NextJS Denial of Service in Image Optimizer A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcin…
VulnCve 2025 59471
medium System graph security Trivy conf 1.00 CVE-2025-62718: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback …
VulnCve 2025 62718
medium System graph security Trivy conf 1.00 CVE-2026-0540: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
DOMPurify: DOMPurify: Cross-site scripting vulnerability DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, n…
VulnCve 2026 0540
medium System graph security Trivy conf 1.00 CVE-2026-24040: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF: jsPDF: Cross-User Data Leakage via race condition in addJS method jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment…
VulnCve 2026 24040
medium System graph security Trivy conf 1.00 CVE-2026-24043: jspdf 2.5.1 — museum-ticket-booking/package-lock.json
jsPDF: jsPDF: PDF integrity compromised via arbitrary XML injection in addMetadata function jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata function allows users to inject arbitrary XML. If given the possibility to pass unsan…
VulnCve 2026 24043
medium System graph security Trivy conf 1.00 CVE-2026-27980: next 14.2.7 — museum-ticket-booking/package-lock.json
next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable…
VulnCve 2026 27980
medium System graph security Trivy conf 1.00 CVE-2026-29057: next 14.2.7 — museum-ticket-booking/package-lock.json
next.js: Next.js: HTTP request smuggling in rewrites Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Tr…
VulnCve 2026 29057
medium System graph security Trivy conf 1.00 CVE-2026-2950: lodash 4.17.21 — package-lock.json
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/…
VulnCve 2026 2950
medium System graph security Trivy conf 1.00 CVE-2026-33672: picomatch 2.3.1 — package-lock.json
picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Becau…
VulnCve 2026 33672
medium System graph security Trivy conf 1.00 CVE-2026-33750: brace-expansion 1.1.11 — package-lock.json
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) caus…
VulnCve 2026 33750
medium System graph security Trivy conf 1.00 CVE-2026-33750: brace-expansion 2.0.1 — package-lock.json
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) caus…
VulnCve 2026 33750
medium System graph security Trivy conf 1.00 CVE-2026-40175: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Remote Code Execution via Prototype Pollution escalation Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leverag…
VulnCve 2026 40175
medium System graph security Trivy conf 1.00 CVE-2026-41239: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from u…
VulnCve 2026 41239
medium System graph security Trivy conf 1.00 CVE-2026-41240: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Comm…
VulnCve 2026 41240
medium System graph security Trivy conf 1.00 CVE-2026-41305: postcss 8.4.31 — museum-ticket-booking/package-lock.json
postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifyin…
VulnCve 2026 41305
medium System graph security Trivy conf 1.00 CVE-2026-42034: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Denial of Service via oversized streamed uploads bypassing body limits Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). …
VulnCve 2026 42034
medium System graph security Trivy conf 1.00 CVE-2026-42036: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Denial of Service via unbounded stream consumption when 'responseType: 'stream'' is used Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLe…
VulnCve 2026 42036
medium System graph security Trivy conf 1.00 CVE-2026-42037: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Node.js: Axios: Information disclosure via CRLF injection in multipart Content-Type header Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the…
VulnCve 2026 42037
medium System graph security Trivy conf 1.00 CVE-2026-42038: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Information disclosure due to `no_proxy` bypass Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route t…
VulnCve 2026 42038
medium System graph security Trivy conf 1.00 CVE-2026-42039: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value pas…
VulnCve 2026 42039
medium System graph security Trivy conf 1.00 CVE-2026-42041: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to…
VulnCve 2026 42041
medium System graph security Trivy conf 1.00 CVE-2026-42042: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: XSRF token bypass leading to information disclosure Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXS…
VulnCve 2026 42042
medium System graph security Trivy conf 1.00 CVE-2026-42044: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the ap…
VulnCve 2026 42044
medium System graph security Trivy conf 1.00 CVE-2026-44490: axios 1.7.7 — museum-ticket-booking/package-lock.json
axios: Axios: Information disclosure and denial of service due to prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency i…
VulnCve 2026 44490
medium System graph security Trivy conf 1.00 CVE-2026-44576: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js: Next.js: Cache poisoning vulnerability in React Server Components Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not corr…
VulnCve 2026 44576
medium System graph security Trivy conf 1.00 CVE-2026-44577: next 14.2.7 — museum-ticket-booking/package-lock.json
Next.js: Next.js: Denial of Service via Image Optimization API Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into mem…
VulnCve 2026 44577
medium System graph security Trivy conf 1.00 CVE-2026-44580: next 14.2.7 — museum-ticket-booking/package-lock.json
next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can b…
VulnCve 2026 44580
medium System graph security Trivy conf 1.00 CVE-2026-44581: next 14.2.7 — museum-ticket-booking/package-lock.json
next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scrip…
VulnCve 2026 44581
medium System graph security Trivy conf 1.00 CVE-2026-48038: joi 17.13.3 — package-lock.json
joi: joi: Denial of Service via uncaught RangeError on deeply nested input through recursive link() schemas joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service is possible via an untrapped exception in services validating user-supp…
VulnCve 2026 48038
medium System graph security Trivy conf 1.00 CVE-2026-49458: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks us…
VulnCve 2026 49458
medium System graph security Trivy conf 1.00 CVE-2026-49459: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form…
VulnCve 2026 49459
medium System graph security Trivy conf 1.00 CVE-2026-49978: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing att…
VulnCve 2026 49978
medium System graph security Trivy conf 1.00 CVE-2026-64643: next 14.2.7 — museum-ticket-booking/package-lock.json
next: Next.js: Information disclosure via Server Action ID exposure Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be…
VulnCve 2026 64643
medium System graph security Trivy conf 1.00 CVE-2026-64646: next 14.2.7 — museum-ticket-booking/package-lock.json
next: Next.js: Denial of Service via excessive memory consumption in Server Actions Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Serve…
VulnCve 2026 64646
medium System graph security Trivy conf 1.00 CVE-2026-64647: next 14.2.7 — museum-ticket-booking/package-lock.json
next: Next.js: Information disclosure via server-side request caching Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different req…
VulnCve 2026 64647
medium System graph security Trivy conf 1.00 CVE-2026-64648: next 14.2.7 — museum-ticket-booking/package-lock.json
next: Next.js: Information disclosure via server-side fetch cache Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different reques…
VulnCve 2026 64648
medium System graph security Trivy conf 1.00 CVE-2026-65898: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Cross-site scripting via permanent attribute allowlist pollution DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register…
VulnCve 2026 65898
medium System graph security Trivy conf 1.00 CVE-2026-65902: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Sanitization bypass via hook manipulation DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags / data…
VulnCve 2026 65902
medium System graph security Trivy conf 1.00 CVE-2026-65903: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Security bypass allows injection of malicious content DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAG…
VulnCve 2026 65903
medium System graph security Trivy conf 1.00 CVE-2026-65912: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: URI validation bypass leads to cross-site scripting DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attrib…
VulnCve 2026 65912
medium System graph security Trivy conf 1.00 CVE-2026-65913: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Arra…
VulnCve 2026 65913
medium System graph security Trivy conf 1.00 CVE-2026-65914: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscri…
VulnCve 2026 65914
medium System graph security Trivy conf 1.00 CVE-2026-69153: postcss 8.4.31 — museum-ticket-booking/package-lock.json
postcss: PostCSS: Information disclosure via crafted sourceMappingURL PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unin…
VulnCve 2026 69153
medium System graph security Trivy conf 1.00 CVE-2026-73562: mongoose 8.5.1 — package-lock.json
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter) Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such…
VulnCve 2026 73562
medium System graph security Trivy conf 1.00 CVE-2026-8723: qs 6.13.0 — museum-ticket-booking/package-lock.json
qs: qs: Denial of Service due to improper handling of null/undefined array elements ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of…
VulnCve 2026 8723
medium System graph security Trivy conf 1.00 CVE-2026-8723: qs 6.13.0 — package-lock.json
qs: qs: Denial of Service due to improper handling of null/undefined array elements ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of…
VulnCve 2026 8723
medium System graph dependencies dependencies conf 0.90 Dependency @stripe/react-stripe-js is two or more major versions behind
`@stripe/react-stripe-js` is pinned at `2.8.0` in `museum-ticket-booking/package.json` while the latest release on the npm registry is `6.8.2` — 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upg…
museum-ticket-booking/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency @stripe/stripe-js is two or more major versions behind
`@stripe/stripe-js` is pinned at `4.4.0` in `museum-ticket-booking/package.json` while the latest release on the npm registry is `9.14.0` — 5 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade …
museum-ticket-booking/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency ejs is two or more major versions behind
`ejs` is pinned at `3.1.10` in `package.json` while the latest release on the npm registry is `6.0.1` — 3 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `ejs` to `6.0.1`.
package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency jspdf is two or more major versions behind
`jspdf` is pinned at `2.5.1` in `museum-ticket-booking/package.json` while the latest release on the npm registry is `4.2.1` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `jspdf` to `4…
museum-ticket-booking/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency jspdf-autotable is two or more major versions behind
`jspdf-autotable` is pinned at `3.8.3` in `museum-ticket-booking/package.json` while the latest release on the npm registry is `5.0.8` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `js…
museum-ticket-booking/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency next is two or more major versions behind
`next` is pinned at `14.2.7` in `museum-ticket-booking/package.json` while the latest release on the npm registry is `16.3.3` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `next` to `1…
museum-ticket-booking/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency react-datepicker is two or more major versions behind
`react-datepicker` is pinned at `7.3.0` in `museum-ticket-booking/package.json` while the latest release on the npm registry is `9.1.0` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `r…
museum-ticket-booking/package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency stripe is two or more major versions behind
`stripe` is pinned at `16.9.0` in `museum-ticket-booking/package.json` while the latest release on the npm registry is `22.6.0` — 6 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `stripe` t…
museum-ticket-booking/package.json FreshnessOutdated
medium System graph hardware Security conf 1.00 Dockerfile runs as root: Dockerfile
No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image.
Container
medium System graph security Trivy conf 1.00 GHSA-42h9-826w-cgv3: axios 1.7.7 — museum-ticket-booking/package-lock.json
Axios: Excessive recursion in formDataToJSON can cause denial of service ## Summary Axios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData …
VulnGhsa 42h9 826w cgv3
medium System graph security Trivy conf 1.00 GHSA-55q2-fjhq-7xh7: dompurify 2.5.6 — museum-ticket-booking/package-lock.json
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS ### Summary During `IN_PLACE` sanitization, a hook that removes an element can leave that element's detached descendants executable. A descendant image can retain its attacker-provided `onload` handler and fire aft…
VulnGhsa 55q2 fjhq 7xh7
medium System graph security Trivy conf 1.00 GHSA-7q8q-rj6j-mhjq: axios 1.7.7 — museum-ticket-booking/package-lock.json
Axios: Nested axios option objects can consume polluted prototype values ## Summary Axios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`. The top-level merged config is protected with a null prototype, but…
VulnGhsa 7q8q rj6j mhjq
medium System graph security Trivy conf 1.00 GHSA-jqh4-m9w3-8hp9: axios 1.7.7 — museum-ticket-booking/package-lock.json
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` ## Summary axios’ fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: "fetch"` and rely on `maxBodyLengt…
VulnGhsa jqh4 m9w3 8hp9
medium System graph security Trivy conf 1.00 GHSA-mmx7-hfxf-jppx: axios 1.7.7 — museum-ticket-booking/package-lock.json
Axios: Prototype pollution gadgets can alter axios request construction ## Summary axios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in the bodyless method alia…
VulnGhsa mmx7 hfxf jppx
medium System graph security Trivy conf 1.00 GHSA-pmv8-rq9r-6j72: axios 1.7.7 — museum-ticket-booking/package-lock.json
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service ## Summary Axios versions starting with `0.28.0` contain uncontrolled recursion in `formDataToJSON`, which is exposed as `axios.formToJSON()` and used internally when axios serialises `FormData` with `Content-Type: application/json`…
VulnGhsa pmv8 rq9r 6j72
medium System graph security Trivy conf 1.00 GHSA-r4q5-vmmm-2653: follow-redirects 1.15.6 — museum-ticket-booking/package-lock.json
follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets ## Summary When an HTTP request follows a cross-domain redirect (301/302/307/308), `follow-redirects` only strips `authorization`, `proxy-authorization`, and `cookie` headers (matched by regex at index.js:469-47…
VulnGhsa r4q5 vmmm 2653
medium System graph cicd CI/CD security conf 1.00 2 occurrences GitHub Action is tag-pinned rather than SHA-pinned
actions-ecosystem/action-create-comment@v1 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA.
2 files, 2 locations
.github/workflows/greet-issue.yml:19
.github/workflows/issue-open-close.yml:15
CI/CD securitySupply chainGithub actions
medium System graph security security conf 0.65 Insecure pattern 'dangerous_innerhtml' in museum-ticket-booking/pages/index.tsx:281
Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible.
museum-ticket-booking/pages/index.tsx:281 Dangerous innerhtml
medium System graph quality Tests conf 1.00 Very low test-to-source ratio
0 test file(s) for 35 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths.
Coverage
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency @babel/runtime 7.25.6: GHSA-968p-4wvh-cqc8
OSV.dev reports `@babel/runtime` at version `7.25.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-968p-4wvh-cqc8. Note: `@babel/runtime` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisor…
museum-ticket-booking/package-lock.json ScaOsvGhsa 968p 4wvh cqc8
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency ajv 6.12.6: GHSA-2g4f-4pwh-qvx6
OSV.dev reports `ajv` at version `6.12.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-2g4f-4pwh-qvx6 (aka CVE-2025-69873). Note: `ajv` is a transitive dependency — pulled in by another package, not declared directly in a manifest. ajv has ReDoS when using `$data` op…
museum-ticket-booking/package-lock.json ScaOsvGhsa 2g4f 4pwh qvx6
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-3p68-rc4w-qgx5
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3p68-rc4w-qgx5. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-3p68-rc4w-qgx5 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 3p68 rc4w qgx5
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-3w6x-2g7m-8v23
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3w6x-2g7m-8v23. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-3w6x-2g7m-8v23 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 3w6x 2g7m 8v23
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-42h9-826w-cgv3
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-42h9-826w-cgv3. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-42h9-826w-cgv3 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 42h9 826w cgv3
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-43fc-jf86-j433
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-43fc-jf86-j433. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-43fc-jf86-j433 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 43fc jf86 j433
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-445q-vr5w-6q77
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-445q-vr5w-6q77. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-445q-vr5w-6q77 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 445q vr5w 6q77
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-4hjh-wcwx-xvwj
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-4hjh-wcwx-xvwj. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-4hjh-wcwx-xvwj Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 4hjh wcwx xvwj
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-5c9x-8gcm-mpgx
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-5c9x-8gcm-mpgx. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-5c9x-8gcm-mpgx Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 5c9x 8gcm mpgx
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-62hf-57xw-28j9
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-62hf-57xw-28j9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-62hf-57xw-28j9 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 62hf 57xw 28j9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-6chq-wfr3-2hj9
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-6chq-wfr3-2hj9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-6chq-wfr3-2hj9 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 6chq wfr3 2hj9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-777c-7fjr-54vf
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-777c-7fjr-54vf. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-777c-7fjr-54vf Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 777c 7fjr 54vf
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-7q8q-rj6j-mhjq
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-7q8q-rj6j-mhjq. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-7q8q-rj6j-mhjq Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 7q8q rj6j mhjq
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-898c-q2cr-xwhg
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-898c-q2cr-xwhg. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-898c-q2cr-xwhg Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 898c q2cr xwhg
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-fvcv-3m26-pcqx
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-fvcv-3m26-pcqx. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-fvcv-3m26-pcqx Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa fvcv 3m26 pcqx
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-hfxv-24rg-xrqf
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-hfxv-24rg-xrqf. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-hfxv-24rg-xrqf Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa hfxv 24rg xrqf
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-j5f8-grm9-p9fc
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-j5f8-grm9-p9fc. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-j5f8-grm9-p9fc Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa j5f8 grm9 p9fc
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-jqh4-m9w3-8hp9
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-jqh4-m9w3-8hp9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jqh4-m9w3-8hp9 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa jqh4 m9w3 8hp9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-jr5f-v2jv-69x6
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-jr5f-v2jv-69x6. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-jr5f-v2jv-69x6 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa jr5f v2jv 69x6
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-m7pr-hjqh-92cm
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-m7pr-hjqh-92cm. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-m7pr-hjqh-92cm Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa m7pr hjqh 92cm
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-mmx7-hfxf-jppx
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-mmx7-hfxf-jppx. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-mmx7-hfxf-jppx Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa mmx7 hfxf jppx
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-p92q-9vqr-4j8v
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-p92q-9vqr-4j8v. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-p92q-9vqr-4j8v Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa p92q 9vqr 4j8v
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-pf86-5x62-jrwf
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-pf86-5x62-jrwf. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-pf86-5x62-jrwf Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa pf86 5x62 jrwf
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-pmv8-rq9r-6j72
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-pmv8-rq9r-6j72. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-pmv8-rq9r-6j72 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa pmv8 rq9r 6j72
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-pmwg-cvhr-8vh7
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-pmwg-cvhr-8vh7. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-pmwg-cvhr-8vh7 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa pmwg cvhr 8vh7
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-q8qp-cvcw-x6jj
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-q8qp-cvcw-x6jj. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-q8qp-cvcw-x6jj Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa q8qp cvcw x6jj
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-vf2m-468p-8v99
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-vf2m-468p-8v99. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-vf2m-468p-8v99 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa vf2m 468p 8v99
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-w9j2-pvgh-6h63
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-w9j2-pvgh-6h63. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-w9j2-pvgh-6h63 Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa w9j2 pvgh 6h63
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-xhjh-pmcv-23jw
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-xhjh-pmcv-23jw. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-xhjh-pmcv-23jw Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa xhjh pmcv 23jw
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency axios 1.7.7: GHSA-xx6v-rp6x-q39c
OSV.dev reports `axios` at version `1.7.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-xx6v-rp6x-q39c. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-xx6v-rp6x-q39c Fix: upgrade `axios` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa xx6v rp6x q39c
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 1.1.11: GHSA-f886-m6hf-6m8v
OSV.dev reports `brace-expansion` at version `1.1.11` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expan…
museum-ticket-booking/package-lock.json ScaOsvGhsa f886 m6hf 6m8v
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency brace-expansion 2.0.1: GHSA-f886-m6hf-6m8v
OSV.dev reports `brace-expansion` at version `2.0.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-f886-m6hf-6m8v (aka CVE-2026-33750). Note: `brace-expansion` is a transitive dependency — pulled in by another package, not declared directly in a manifest. brace-expans…
museum-ticket-booking/package-lock.json ScaOsvGhsa f886 m6hf 6m8v
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency canvg 3.0.10: GHSA-v2mw-5mch-w8c5
OSV.dev reports `canvg` at version `3.0.10` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-v2mw-5mch-w8c5. Note: `canvg` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `canvg` is an optional dependency — installs ma…
museum-ticket-booking/package-lock.json ScaOsvGhsa v2mw 5mch w8c5
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency cloudinary 1.41.3: GHSA-g4mf-96x5-5m2c
OSV.dev reports `cloudinary` at version `1.41.3` (resolved in `package-lock.json`) is affected by GHSA-g4mf-96x5-5m2c. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-g4mf-96x5-5m2c Fix: upgrade `cloudinary` past the affected range per the advisory.
package.json ScaOsvGhsa g4mf 96x5 5m2c
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency cross-spawn 7.0.3: GHSA-3xgq-45jj-v275
OSV.dev reports `cross-spawn` at version `7.0.3` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3xgq-45jj-v275. Note: `cross-spawn` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: http…
museum-ticket-booking/package-lock.json ScaOsvGhsa 3xgq 45jj v275
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-39q2-94rc-95cp
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-39q2-94rc-95cp (aka CVE-2026-65903). Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an o…
museum-ticket-booking/package-lock.json ScaOsvGhsa 39q2 94rc 95cp
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-55q2-fjhq-7xh7
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-55q2-fjhq-7xh7. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa 55q2 fjhq 7xh7
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-76mc-f452-cxcm
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-76mc-f452-cxcm. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa 76mc f452 cxcm
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-c2j3-45gr-mqc4
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-c2j3-45gr-mqc4. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa c2j3 45gr mqc4
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-cj63-jhhr-wcxv
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-cj63-jhhr-wcxv. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa cj63 jhhr wcxv
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-cjmm-f4jc-qw8r
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-cjmm-f4jc-qw8r. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa cjmm f4jc qw8r
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-cmwh-pvxp-8882
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-cmwh-pvxp-8882. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa cmwh pvxp 8882
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-crv5-9vww-q3g8
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-crv5-9vww-q3g8. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa crv5 9vww q3g8
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-h7mw-gpvr-xq4m
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-h7mw-gpvr-xq4m. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa h7mw gpvr xq4m
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-h8r8-wccr-v5f2
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-h8r8-wccr-v5f2. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa h8r8 wccr v5f2
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-hpcv-96wg-7vj8
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-hpcv-96wg-7vj8. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa hpcv 96wg 7vj8
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-r47g-fvhr-h676
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-r47g-fvhr-h676. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa r47g fvhr h676
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-rp9w-3fw7-7cwq
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-rp9w-3fw7-7cwq. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa rp9w 3fw7 7cwq
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-v2wj-7wpq-c8vv
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-v2wj-7wpq-c8vv. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa v2wj 7wpq c8vv
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-v8jm-5vwx-cfxm
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-v8jm-5vwx-cfxm. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa v8jm 5vwx cfxm
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-vhxf-7vqr-mrjg
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-vhxf-7vqr-mrjg. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa vhxf 7vqr mrjg
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-vxr8-fq34-vvx9
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-vxr8-fq34-vvx9. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa vxr8 fq34 vvx9
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency dompurify 2.5.6: GHSA-x4vx-rjvf-j5p4
OSV.dev reports `dompurify` at version `2.5.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-x4vx-rjvf-j5p4. Note: `dompurify` is a transitive dependency — pulled in by another package, not declared directly in a manifest. Note: `dompurify` is an optional dependency — …
museum-ticket-booking/package-lock.json ScaOsvGhsa x4vx rjvf j5p4
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency flatted 3.3.1: GHSA-rf6f-7fwh-wjgh
OSV.dev reports `flatted` at version `3.3.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-rf6f-7fwh-wjgh. Note: `flatted` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.…
museum-ticket-booking/package-lock.json ScaOsvGhsa rf6f 7fwh wjgh
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency follow-redirects 1.15.6: GHSA-r4q5-vmmm-2653
OSV.dev reports `follow-redirects` at version `1.15.6` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-r4q5-vmmm-2653. Note: `follow-redirects` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Adv…
museum-ticket-booking/package-lock.json ScaOsvGhsa r4q5 vmmm 2653
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency form-data 4.0.0: GHSA-fjxv-7rqg-78g4
OSV.dev reports `form-data` at version `4.0.0` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-fjxv-7rqg-78g4. Note: `form-data` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://…
museum-ticket-booking/package-lock.json ScaOsvGhsa fjxv 7rqg 78g4
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency form-data 4.0.0: GHSA-hmw2-7cc7-3qxx
OSV.dev reports `form-data` at version `4.0.0` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-hmw2-7cc7-3qxx. Note: `form-data` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://…
museum-ticket-booking/package-lock.json ScaOsvGhsa hmw2 7cc7 3qxx
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency glob 10.3.10: GHSA-5j98-mcp5-4vw2
OSV.dev reports `glob` at version `10.3.10` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-5j98-mcp5-4vw2. Note: `glob` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.dev/…
museum-ticket-booking/package-lock.json ScaOsvGhsa 5j98 mcp5 4vw2
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency joi 17.13.3: GHSA-q7cg-457f-vx79
OSV.dev reports `joi` at version `17.13.3` (resolved in `package-lock.json`) is affected by GHSA-q7cg-457f-vx79. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-q7cg-457f-vx79 Fix: upgrade `joi` past the affected range per the advisory.
package.json ScaOsvGhsa q7cg 457f vx79
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-52cp-r559-cp3m
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-52cp-r559-cp3m. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.…
museum-ticket-booking/package-lock.json ScaOsvGhsa 52cp r559 cp3m
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-h67p-54hq-rp68
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-h67p-54hq-rp68. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.…
museum-ticket-booking/package-lock.json ScaOsvGhsa h67p 54hq rp68
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency js-yaml 4.1.0: GHSA-mh29-5h37-fv8m
OSV.dev reports `js-yaml` at version `4.1.0` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-mh29-5h37-fv8m. Note: `js-yaml` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.…
museum-ticket-booking/package-lock.json ScaOsvGhsa mh29 5h37 fv8m
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-67pg-wm7f-q7fj
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-67pg-wm7f-q7fj. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-67pg-wm7f-q7fj Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 67pg wm7f q7fj
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-7x6v-j9x4-qf24
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-7x6v-j9x4-qf24. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-7x6v-j9x4-qf24 Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 7x6v j9x4 qf24
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-8mvj-3j78-4qmw
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-8mvj-3j78-4qmw. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-8mvj-3j78-4qmw Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 8mvj 3j78 4qmw
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-95fx-jjr5-f39c
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-95fx-jjr5-f39c. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-95fx-jjr5-f39c Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 95fx jjr5 f39c
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-9vjf-qc39-jprp
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-9vjf-qc39-jprp. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-9vjf-qc39-jprp Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 9vjf qc39 jprp
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-cjw8-79x6-5cj4
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-cjw8-79x6-5cj4. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-cjw8-79x6-5cj4 Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa cjw8 79x6 5cj4
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-f8cm-6447-x5h2
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-f8cm-6447-x5h2. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-f8cm-6447-x5h2 Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa f8cm 6447 x5h2
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-p5xg-68wr-hm3m
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-p5xg-68wr-hm3m. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-p5xg-68wr-hm3m Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa p5xg 68wr hm3m
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-pqxr-3g65-p328
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-pqxr-3g65-p328. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-pqxr-3g65-p328 Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa pqxr 3g65 p328
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-vm32-vv63-w422
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-vm32-vv63-w422. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-vm32-vv63-w422 Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa vm32 vv63 w422
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-w532-jxjh-hjhj
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-w532-jxjh-hjhj. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-w532-jxjh-hjhj Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa w532 jxjh hjhj
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency jspdf 2.5.1: GHSA-wfv2-pwc8-crg5
OSV.dev reports `jspdf` at version `2.5.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-wfv2-pwc8-crg5. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-wfv2-pwc8-crg5 Fix: upgrade `jspdf` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa wfv2 pwc8 crg5
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency mongoose 8.5.1: GHSA-664h-wqgq-64gw
OSV.dev reports `mongoose` at version `8.5.1` (resolved in `package-lock.json`) is affected by GHSA-664h-wqgq-64gw. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-664h-wqgq-64gw Fix: upgrade `mongoose` past the affected range per the advisory.
package.json ScaOsvGhsa 664h wqgq 64gw
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency mongoose 8.5.1: GHSA-m7xq-9374-9rvx
OSV.dev reports `mongoose` at version `8.5.1` (resolved in `package-lock.json`) is affected by GHSA-m7xq-9374-9rvx. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-m7xq-9374-9rvx Fix: upgrade `mongoose` past the affected range per the advisory.
package.json ScaOsvGhsa m7xq 9374 9rvx
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency mongoose 8.5.1: GHSA-vg7j-7cwx-8wgw
OSV.dev reports `mongoose` at version `8.5.1` (resolved in `package-lock.json`) is affected by GHSA-vg7j-7cwx-8wgw. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-vg7j-7cwx-8wgw Fix: upgrade `mongoose` past the affected range per the advisory.
package.json ScaOsvGhsa vg7j 7cwx 8wgw
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency mongoose 8.5.1: GHSA-wpg9-53fq-2r8h
OSV.dev reports `mongoose` at version `8.5.1` (resolved in `package-lock.json`) is affected by GHSA-wpg9-53fq-2r8h. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-wpg9-53fq-2r8h Fix: upgrade `mongoose` past the affected range per the advisory.
package.json ScaOsvGhsa wpg9 53fq 2r8h
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-44fp-w29j-9vj5
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-44fp-w29j-9vj5. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-44fp-w29j-9vj5 Fix: …
package.json ScaOsvGhsa 44fp w29j 9vj5
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-4pg4-qvpc-4q3h
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-4pg4-qvpc-4q3h. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-4pg4-qvpc-4q3h Fix: …
package.json ScaOsvGhsa 4pg4 qvpc 4q3h
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-5528-5vmv-3xc2
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-5528-5vmv-3xc2. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-5528-5vmv-3xc2 Fix: …
package.json ScaOsvGhsa 5528 5vmv 3xc2
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-72gw-mp4g-v24j
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-72gw-mp4g-v24j. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-72gw-mp4g-v24j Fix: …
package.json ScaOsvGhsa 72gw mp4g v24j
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-fjgf-rc76-4x9p
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-fjgf-rc76-4x9p. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-fjgf-rc76-4x9p Fix: …
package.json ScaOsvGhsa fjgf rc76 4x9p
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-g5hg-p3ph-g8qg
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-g5hg-p3ph-g8qg. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-g5hg-p3ph-g8qg Fix: …
package.json ScaOsvGhsa g5hg p3ph g8qg
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-v52c-386h-88mc
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-v52c-386h-88mc. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-v52c-386h-88mc Fix: …
package.json ScaOsvGhsa v52c 386h 88mc
medium System graph dependencies dependencies conf 0.70 Vulnerable dependency multer 1.4.5-lts.1: GHSA-xf7r-hgr6-v32p
OSV.dev reports `multer` at version `1.4.5-lts.1` (declared in `package.json`) is affected by GHSA-xf7r-hgr6-v32p. Note: `1.4.5-lts.1` is the declared floor of a range — the installed version may be newer. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-xf7r-hgr6-v32p Fix: …
package.json ScaOsvGhsa xf7r hgr6 v32p
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency nanoid 3.3.7: GHSA-mwcw-c2x4-8c55
OSV.dev reports `nanoid` at version `3.3.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-mwcw-c2x4-8c55. Note: `nanoid` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://osv.de…
museum-ticket-booking/package-lock.json ScaOsvGhsa mwcw c2x4 8c55
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-3g8h-86w9-wvmq
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 3g8h 86w9 wvmq
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-3h52-269p-cp9r
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3h52-269p-cp9r. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-3h52-269p-cp9r Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 3h52 269p cp9r
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-3x4c-7xq6-9pq8
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3x4c-7xq6-9pq8. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-3x4c-7xq6-9pq8 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 3x4c 7xq6 9pq8
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-4342-x723-ch2f
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-4342-x723-ch2f. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-4342-x723-ch2f Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 4342 x723 ch2f
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-4633-3j49-mh5q
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-4633-3j49-mh5q. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 4633 3j49 mh5q
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-4c39-4ccg-62r3
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 4c39 4ccg 62r3
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-5j59-xgg2-r9c4
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-5j59-xgg2-r9c4. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-5j59-xgg2-r9c4 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 5j59 xgg2 r9c4
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-68g3-v927-f742
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-68g3-v927-f742. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 68g3 v927 f742
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-7gfc-8cq8-jh5f
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-7gfc-8cq8-jh5f. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-7gfc-8cq8-jh5f Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 7gfc 8cq8 jh5f
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-7m27-7ghc-44w9
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-7m27-7ghc-44w9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-7m27-7ghc-44w9 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 7m27 7ghc 44w9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-89xv-2m56-2m9x
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 89xv 2m56 2m9x
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-8h8q-6873-q5fj
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 8h8q 6873 q5fj
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-955p-x3mx-jcvp
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 955p x3mx jcvp
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-9g9p-9gw9-jx7f
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-9g9p-9gw9-jx7f. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-9g9p-9gw9-jx7f Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa 9g9p 9gw9 jx7f
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-c4j6-fc7j-m34r
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa c4j6 fc7j m34r
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-f82v-jwr5-mffw
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-f82v-jwr5-mffw. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-f82v-jwr5-mffw Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa f82v jwr5 mffw
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-ffhc-5mcf-pf4q
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa ffhc 5mcf pf4q
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-g5qg-72qw-gw5v
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-g5qg-72qw-gw5v. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-g5qg-72qw-gw5v Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa g5qg 72qw gw5v
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-ggv3-7p47-pfv8
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-ggv3-7p47-pfv8. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-ggv3-7p47-pfv8 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa ggv3 7p47 pfv8
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-gp8f-8m3g-qvj9
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-gp8f-8m3g-qvj9. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-gp8f-8m3g-qvj9 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa gp8f 8m3g qvj9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-gx5p-jg67-6x7h
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa gx5p jg67 6x7h
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-h25m-26qc-wcjf
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-h25m-26qc-wcjf. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-h25m-26qc-wcjf Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa h25m 26qc wcjf
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-h64f-5h5j-jqjh
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa h64f 5h5j jqjh
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-m99w-x7hq-7vfj
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa m99w x7hq 7vfj
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-mwv6-3258-q52c
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-mwv6-3258-q52c. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-mwv6-3258-q52c Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa mwv6 3258 q52c
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-p9j2-gv94-2wf4
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa p9j2 gv94 2wf4
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-q4gf-8mx6-v5v3
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-q4gf-8mx6-v5v3. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-q4gf-8mx6-v5v3 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa q4gf 8mx6 v5v3
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-qpjv-v59x-3qc4
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-qpjv-v59x-3qc4. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-qpjv-v59x-3qc4 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa qpjv v59x 3qc4
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-vfv6-92ff-j949
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-vfv6-92ff-j949. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa vfv6 92ff j949
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-wfc6-r584-vfw7
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7 Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa wfc6 r584 vfw7
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency next 14.2.7: GHSA-xv57-4mr9-wg8v
OSV.dev reports `next` at version `14.2.7` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-xv57-4mr9-wg8v. No summary published yet. Advisory: https://osv.dev/vulnerability/GHSA-xv57-4mr9-wg8v Fix: upgrade `next` past the affected range per the advisory.
museum-ticket-booking/package.json ScaOsvGhsa xv57 4mr9 wg8v
medium System graph dependencies dependencies conf 0.90 Vulnerable dependency picomatch 2.3.1: GHSA-3v7f-55p6-f55p
OSV.dev reports `picomatch` at version `2.3.1` (resolved in `museum-ticket-booking/package-lock.json`) is affected by GHSA-3v7f-55p6-f55p. Note: `picomatch` is a transitive dependency — pulled in by another package, not declared directly in a manifest. No summary published yet. Advisory: https://…
museum-ticket-booking/package-lock.json ScaOsvGhsa 3v7f 55p6 f55p

Showing first 300 of 348. Refine filters or use the findings page for deep search.

For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/9177c925-64f4-4724-8ecc-6e5ecd1976ca/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/9177c925-64f4-4724-8ecc-6e5ecd1976ca/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.