
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Incorrect Behavior Order
@anthropic-ai/claude-code is an Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you.
Affected versions of this package are vulnerable to Incorrect Behavior Order via incorrect API key selection during server-managed settings retrieval. When a session authenticates with a Claude Enterprise or Team account, the settings fetch logic incorrectly prioritizes a locally stored API key (from a prior /login or direct configuration write) over the authenticated session credentials. When the settings endpoint rejects that stored key, the session starts without the organization's server-managed policy - including permission deny rules, model restrictions, and managed-only locks - or, if a previously cached copy exists on the machine, continues applying that stale copy without receiving later policy changes, while still operating as the organization's account. Endpoint-managed (MDM or file-based) settings are not affected.
Note: This is only exploitable with local access to a device that has a stored API key; the no-policy case additionally requires that no managed settings have previously been cached on that device.
Inefficient Algorithmic Complexity
httpx2 is a The next generation HTTP client.
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity through the sse. An attacker can cause excessive CPU consumption by sending a long, unterminated line split across many small response chunks from a compromised or malicious SSE endpoint, resulting in quadratic processing time and potential denial of service.
Incorrect Authorization
Affected versions of this package are vulnerable to Incorrect Authorization in SpreadsheetHandlerImpl.updateCellComment(), which writes the supplied text to the target cell without checking whether the active sheet is protected or the cell locked, unlike the edit, cut, and paste handlers in the same class, which consult Spreadsheet.isCellLocked() before writing. A user with access to a rendered spreadsheet can add or alter comments on a protected sheet and on locked cells, and create empty cells by targeting coordinates that hold none, by dispatching the comment update event directly rather than through the UI that withholds it. This requires an authenticated session with a protected spreadsheet rendered to it and no special configuration, and the effect stays within that user's session until the workbook is persisted or shared, at which point the altered comments reach everyone who opens it.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




