
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Regular Expression Denial of Service (ReDoS)
basic-ftp is a FTP client for Node.js, supports FTPS over TLS, IPv6, Async/Await, and Typescript.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via unanchored regular expressions in Client.list() (specifically in parseListDOS.ts and parseListUnix.ts). The regex patterns used to parse FTP directory listings lack anchoring and use unbounded quantifiers, causing catastrophic backtracking when a malicious FTP server returns a long line that cannot be matched. A single such line triggers O(n²) CPU work per character, allowing a server to block the Node.js event loop indefinitely.
Arbitrary Code Injection
fsspec is a File-system specification
Affected versions of this package are vulnerable to Arbitrary Code Injection in the reference filesystem process. An attacker can execute arbitrary code by tricking an application into loading a maliciously crafted reference document, such as a Kerchunk metadata file, which leads to unrestricted template evaluation and execution of embedded expressions in the context of the running process.
Incorrect Authorization
Affected versions of this package are vulnerable to Incorrect Authorization in org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals through external MLS commit Remove proposal validation. An attacker can evict an arbitrary group member and take over that slot in the ratchet tree by supplying an external commit that names that member’s LeafIndex while holding only the group’s public GroupInfo. The vulnerable validation counted Remove proposals and bounded the removed leaf index, but it did not verify that the removed leaf was the joiner’s own prior leaf. As a result, any external joiner could submit a Remove for another participant and have other members apply it, forcing that member out of the group and disrupting the user’s session state.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




