
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
moustick is a malicious package.
This package contains malicious code that fetches and eval() a remote payload from attacker-controlled URL (https://www.jsonkeeper.com/b/MYUKZ) on require() in moustick/index.js. The payload is designed to extract RELAYER_PRIVATE_KEY and JWT_SECRET from the victim's .env file. While this package attempting to impersonate a valid pakage cookie-signature by using the real author name (TJ Holowaychuk) and points to the legitimate visionmedia/node-cookie-signature GitHub repo, there is no connection between that organization and this package authorship. Its content was not removed from the official package manager yet.
Arbitrary Code Execution
modelscope is a ModelScope: bring the notion of Model-as-a-Service to life.
Affected versions of this package are vulnerable to Arbitrary Code Execution from the pipeline interface. There, a user can supply a malicious model that loads arbitrary modules via an acoustic-echo-cancellation task.
Insufficient Granularity of Access Control
org.keycloak:keycloak-server-spi-private is an open source identity and access management solution for modern applications and services.
Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the getMembers() methods that serve the group members endpoint. An admin user with delegated access to read group memberships and users can read user profile attributes that are explicitly configured to be denied by using their delegated administrative access to expose those values over the group membership API.
Recent vulnerabilities disclosed by Snyk
- H
Command Injection in degit (npm)- C
Malicious Package in moustick (npm)- C
Malicious Package in cookie-parser-legacy (npm)- M
Arbitrary File Write via Archive Extraction (Zip Slip) in decompress (npm)- H
CSV Injection in json-2-csv (npm)
Snyk security
researchers
have disclosed
3497
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




