
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Eval Injection
n8n-nodes-base is a Base nodes of n8n
Affected versions of this package are vulnerable to Eval Injection. An attacker can execute arbitrary code on the host system by submitting specially crafted form data that is interpreted as an expression.
Note:
This is only exploitable if a workflow contains a form node with a field that interpolates unauthenticated user input and the field value begins with an '=' character, causing double evaluation of the content.
Malicious Package
polyutil is a malicious package. that utilizes typosquatting to infiltrate developer environments via PyPI. Once installed, it executes obfuscated payloads designed to harvest sensitive data, including environment variables, cloud credentials, and SSH keys. This stolen information is exfiltrated to a command-and-control server. The campaign is particularly dangerous due to its use of delayed execution and professional-looking documentation to evade detection and deceive developers.
Deserialization of Untrusted Data
Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the DefaultLevelDBSerializer class. An attacker can execute arbitrary code by injecting a crafted serialized Java object into the LevelDB database files, which is then deserialized during normal aggregation repository operations.
Recent vulnerabilities disclosed by Snyk
- C
Arbitrary Code Injection in unisharp/laravel-filemanager (composer)- M
Infinite loop in bn.js (npm)- H
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in directorytree/imapengine (composer)- M
Regular Expression Denial of Service (ReDoS) in markdown-it (npm)- C
Arbitrary Code Injection in jsonpath (npm)
Snyk security
researchers
have disclosed
3467
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




