
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Insertion of Sensitive Information Into Sent Data
@keycloak/keycloak-admin-ui is a This project is the next generation of the Keycloak Admin UI. It is written with React and PatternFly 4 and uses Vite.
Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data through OrganizationInvitationResource.toRepresentation() in OrganizationInvitationResource.java. An attacker can retrieve the secret invitation link by creating or listing an organization invitation through the admin REST API, then use that link to register new accounts and add them to the organization without manage-users permission or access to the invited mailbox. This lets a delegated organization administrator bypass the intended invitation workflow and create unauthorized organization members.
Notes
- The leaked link was exposed in both the single-invitation
getresponse and the invitationslistresponse, so any caller with organization-invitation read access could recover it without going through the email-delivery path. - The admin console also rendered a “Copy invite link” action from the same response field, so deployments using the web UI exposed the secret link there as well as through the REST API.
Malicious Package
chaintest is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Incomplete List of Disallowed Inputs
org.webjars.npm:dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG.
Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs in the CUSTOM_ELEMENT_HANDLING. An attacker can cause security-relevant attributes to be preserved on allowed custom elements by leveraging the bypass of the afterSanitizeElements hook, which may result in these attributes being re-injected into an HTML sink such as innerHTML and executed in a later context.
Note: This is only exploitable if the application enables CUSTOM_ELEMENT_HANDLING, relies on afterSanitizeElements as a security policy layer, and has custom elements that re-inject preserved attribute values into an HTML sink.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




