
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Server-side Request Forgery (SSRF)
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the HTTP plugin's redirect-following logic, which checks the URL scope only against the initial URL requested by the frontend and not against subsequent redirect hops. A server on an allowed origin can issue a redirect to any other origin - including localhost services, internal hosts, and cloud metadata endpoints - and the plugin follows the full redirect chain, returning the response to the webview. This allows a network-adjacent attacker to leverage an open redirect or a controlled server to exfiltrate responses from otherwise-denied origins.
Directory Traversal
mpxj is a Python wrapper for the MPXJ Java library for manipulating project files
Affected versions of this package are vulnerable to Directory Traversal via the P3PRXFileReader and SureTrakSTXFileReader file extraction logic in the Primavera P3 PRX and SureTrak STX readers. An attacker can write files to arbitrary locations on the filesystem by supplying a crafted PRX or STX file with path components that escape the intended output directory. When MPXJ processes these files, it builds an output File from the embedded filename and uses it to create the extracted file without sufficient parent-directory containment checks. This can overwrite or create files outside the target directory in applications that import untrusted PRX or STX project data.
Workarounds
- Do not read PRX or STX files from untrusted sources; this prevents a crafted file from forcing MPXJ to write files to arbitrary locations on the filesystem.
Cross-site Scripting (XSS)
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the caption cue text process. An attacker can execute arbitrary scripts in the context of the user's browser by injecting malicious content into closed captions.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.





