
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Command Injection
automagik-genie is a Self-evolving AI agent orchestration framework with Model Context Protocol support
Affected versions of this package are vulnerable to Command Injection via the readTranscriptFromCommit() function. An attacker can execute arbitrary system commands by supplying crafted input to the view_task parameter when reading from an external FORGE_BASE_URL.
Memory Allocation with Excessive Size Value
Affected versions of this package are vulnerable to Memory Allocation with Excessive Size Value through the ReceivePackHandler via add_thin_pack/apply_delta flows when handling crafted thin packs with attacker-controlled delta headers. An attacker can cause excessive memory allocation by pushing a specially crafted thin pack that declares a large destination size, leading to resource exhaustion and potential denial of service. This is only exploitable if the server exposes git-receive-pack functionality and accepts pushes from untrusted or authenticated clients.
Cross-site Scripting (XSS)
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the HTML index page when an authenticated user with upload permissions stores crafted content. An attacker can execute arbitrary JavaScript in the browser of users who browse the affected repository directory, potentially performing actions in the context of the victim's session.
Recent vulnerabilities disclosed by Snyk
- H
Command Injection in degit (npm)- C
Malicious Package in moustick (npm)- C
Malicious Package in cookie-parser-legacy (npm)- M
Arbitrary File Write via Archive Extraction (Zip Slip) in decompress (npm)- H
CSV Injection in json-2-csv (npm)
Snyk security
researchers
have disclosed
3497
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




