Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Cross-site Scripting (XSS)
jodit is a Jodit is awesome and usefully wysiwyg editor with filebrowser
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the sanitizeHTMLElement. An attacker can execute arbitrary JavaScript in the context of the user's browser by crafting a malicious href attribute that bypasses incomplete normalization checks. This can be triggered when a victim clicks a specially crafted link rendered from stored editor content.
Directory Traversal
copier is an A library for rendering project templates.
Affected versions of this package are vulnerable to Directory Traversal via percent-encoded parent-directory segments or encoded path separators in template URLs. An attacker can execute unsafe template features from a repository outside the trusted prefix by crafting a URL that bypasses trusted repository checks after user interaction.
Directory Traversal
Affected versions of this package are vulnerable to Directory Traversal through the move and remove folder operations in FileSystemNotebookRepo. An authenticated attacker with permission to rename notes or use folder operations can supply .. or URL-encoded traversal segments in a note or folder path to make Zeppelin move, write, or delete files and directories outside the configured notebook root. This can corrupt or remove filesystem content beyond the notebook directory and break notebook management for affected users.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.