Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Cross-site Scripting (XSS)
jodit is a Jodit is awesome and usefully wysiwyg editor with filebrowser
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the sanitizeHTMLElement. An attacker can execute arbitrary JavaScript in the context of the user's browser by crafting a malicious href attribute that bypasses incomplete normalization checks. This can be triggered when a victim clicks a specially crafted link rendered from stored editor content.
UNIX Symbolic Link (Symlink) Following
proot-distro is a PRoot-Distro is a lightweight rootless Linux container management utility built around proot.
Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following in the proot_distro/commands/install.py function and the equivalent process in helpers/docker.py when extracting a tar archive containing a symlink whose target is an absolute host path. An attacker can overwrite arbitrary files on the host system with the privileges of the Termux process by supplying a malicious tar archive containing such a symlink and a subsequent file entry that traverses through it.
Directory Traversal
Affected versions of this package are vulnerable to Directory Traversal through the move and remove folder operations in FileSystemNotebookRepo. An authenticated attacker with permission to rename notes or use folder operations can supply .. or URL-encoded traversal segments in a note or folder path to make Zeppelin move, write, or delete files and directories outside the configured notebook root. This can corrupt or remove filesystem content beyond the notebook directory and break notebook management for affected users.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.