
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Cross-site Scripting (XSS)
hbs is an Express.js template engine plugin for Handlebars
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the replaceAsyncValues render path in lib/hbs.js. An attacker can inject script into rendered HTML by supplying attacker-controlled data to a registerAsyncHelper callback that is rendered with {{...}}, causing the helper’s return value to be inserted into the template output without HTML escaping. When the application serves that rendered page to a browser, the payload executes in the victim’s session and can steal data or perform actions as that user. The issue affects both cached and uncached rendering flows, as well as layouts that include the async helper output.
Deserialization of Untrusted Data
flair is an A very simple framework for state-of-the-art NLP
Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the ClusteringModel.load function. An attacker can execute arbitrary code by providing a malicious model file that is loaded through this function.
Notes
- While 0.15.0 states that clustering support was dropped, the module remains present in the distributed artifact and reachable by importing flair.models.clustering directly
Authorization Bypass Through User-Controlled Key
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the DefaultJmsHeaderMapper process. An attacker can redirect handler output or error messages to arbitrary MessageChannel beans by setting crafted JMS properties such as replyChannel, errorChannel, or json__TypeId__, which are copied into message headers and subsequently resolved by downstream framework code.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




