
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
adril7123 is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Deserialization of Untrusted Data
smolagents is a 🤗 smolagents: a barebones library for agents. Agents write python code to call tools or orchestrate other agents.
Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the parsing of pickle data. An attacker can execute arbitrary code by sending specially crafted pickle data to the service.
Note:
The report was rejected for being out of scope for the bug bounty program.
The package maintainers closed the case as a duplicate of another report.
See the security policy for more information.
Deserialization of Untrusted Data
Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the GetAsanaObject processor, which uses generic Java object serialization and deserialization without filtering. An attacker can execute arbitrary code by supplying crafted serialized objects to the configured cache server.
Note:
This is only exploitable if the system is running with the GetAsanaObject processor and the attacker has direct access to the configured cache server.
Recent vulnerabilities disclosed by Snyk
- M
Remote Code Execution (RCE) in n8n-workflow (npm)- M
Remote Code Execution (RCE) in n8n-nodes-base (npm)- M
Remote Code Execution (RCE) in @n8n/config (npm)- M
Cross-site Request Forgery (CSRF) in fastapi-sso (pip)- M
Cross-site Scripting (XSS) in @tiptap/extension-link (npm)
Snyk security
researchers
have disclosed
3454
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




