
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Prototype Pollution
@graphql-tools/utils is a Common package containing utils and types for GraphQL tools
Affected versions of this package are vulnerable to Prototype Pollution via the mergeDeep function, which fails to block reserved property keys such as __proto__, constructor, and prototype before recursively merging source objects into an output object. An attacker who controls a source object passed to mergeDeep can pollute Object.prototype, potentially affecting all objects in the process and enabling further exploitation.
External Control of File Name or Path
docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.
Affected versions of this package are vulnerable to External Control of File Name or Path via the DoclingJSONBackend when processing a DoclingDocument JSON input containing ImageRef fields with local filesystem paths or file:// URIs. An attacker who can supply a malicious JSON document can cause the converter to open arbitrary local files on the host, which are then read by enrichment models or embedded-image export stages, exposing their contents.
Note: This is only exploitable when the application accepts InputFormat.JSON_DOCLING input, which is enabled by default.
Improper Validation of Integrity Check Value
Affected versions of this package are vulnerable to Improper Validation of Integrity Check Value in the CMSAuthenticatedDataParser process. An attacker can cause unauthorized attribute injection by crafting a message where the digestAlgorithm field is absent but authAttrs is present, allowing the insertion of arbitrary authenticated attributes that are not covered by the MAC. This can lead to applications making authorization, routing, or labeling decisions based on attacker-controlled values.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




