chartmuseum

Direct Vulnerabilities

Known vulnerabilities in the chartmuseum package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Untrusted Search Path

<0.16.5-r14
  • L
GHSA-hfvc-g4fc-pqhx

<0.16.5-r14
  • L
GHSA-jpcc-p29g-p8mq

<0.16.5-r13
  • L
CVE-2026-53488

<0.16.5-r13
  • L
CVE-2026-47262

<0.16.5-r13
  • L
GHSA-xhf5-7wjv-pqxp

<0.16.5-r13
  • L
CVE-2026-46680

<0.16.5-r9
  • L
GHSA-fqw6-gf59-qr4w

<0.16.5-r9
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.16.5-r8
  • L
GHSA-mh2q-q3fh-2475

<0.16.5-r5
  • L
Allocation of Resources Without Limits or Throttling

<0.16.5-r5
  • L
GHSA-hr2v-4r36-88hr

<0.16.5-r10
  • L
GHSA-5w89-2c2x-6x66

<0.16.5-r10
  • L
GHSA-jrg3-gfjw-hm96

<0.16.5-r10
  • L
GHSA-m4pr-4j3g-9v7v

<0.16.5-r10
  • L
GHSA-x4jj-h2v8-hqqv

<0.16.5-r10
  • H
Improper Certificate Validation

<0.16.5-r10
  • M
Directory Traversal

<0.16.5-r10
  • M
Allocation of Resources Without Limits or Throttling

<0.16.5-r10
  • L
CVE-2026-32280

<0.16.5-r10
  • L
GHSA-gjvh-7jh8-7xhm

<0.16.5-r10
  • H
Incorrect Authorization

<0.16.5-r10
  • L
GHSA-7mr4-xjxg-34g6

<0.16.5-r10
  • M
Cross-site Scripting (XSS)

<0.16.5-r10
  • H
Allocation of Resources Without Limits or Throttling

<0.16.5-r10
  • L
GHSA-p77j-4mvh-x3m3

<0.16.4-r4
  • L
Improper Authorization

<0.16.4-r4
  • L
Direct Request ('Forced Browsing')

<0.16.4-r3
  • L
Directory Traversal

<0.16.4-r3
  • L
GHSA-j4j7-vw47-rhfq

<0.16.4-r3
  • L
GHSA-rv83-g57w-fr8j

<0.16.4-r3
  • L
Cross-site Scripting (XSS)

<0.16.4-r3
  • L
GHSA-j3gx-2473-5fp8

<0.16.4-r3
  • L
GHSA-h355-32pf-p2xm

<0.16.4-r1
  • L
GHSA-frhw-mqj2-wxw2

<0.16.3-r8
  • L
CVE-2025-47910

<0.16.3-r7
  • L
CVE-2025-58181

<0.16.3-r10
  • L
Asymmetric Resource Consumption (Amplification)

<0.16.4-r0
  • L
GHSA-hjx7-fpxx-mj48

<0.16.3-r8
  • L
GHSA-crqm-pwhx-j97f

<0.16.2-r6
  • L
GHSA-vvgc-356p-c3xw

<0.16.2-r19
  • L
GHSA-8jvr-vh7g-f8gx

<0.16.4-r1
  • L
GHSA-8xfx-rj4p-23jm

<0.16.2-r6
  • L
GHSA-wcw9-47fp-rrfr

<0.16.3-r8
  • L
GHSA-pwhc-rpq9-4c8w

<0.16.3-r9
  • L
GHSA-j5w8-q4qc-rx2x

<0.16.3-r10
  • M
Memory Leak

<0.16.3-r9
  • L
CVE-2025-58183

<0.16.3-r8
  • L
GHSA-cxq7-xw9v-rcv3

<0.16.3-r8
  • L
CVE-2025-22869

<0.16.2-r13
  • H
Origin Validation Error

<0.16.2-r15
  • L
CVE-2025-4673

<0.16.3-r2
  • L
GHSA-7wwx-xj66-r44x

<0.16.3-r8
  • L
Allocation of Resources Without Limits or Throttling

<0.16.3-r6
  • L
GHSA-f9f8-9pmf-xv68

<0.16.3-r6
  • L
Use of Uninitialized Resource

<0.16.3-r6
  • L
CVE-2025-58186

<0.16.3-r8
  • L
GHSA-265r-hfxg-fhmg

<0.16.2-r15
  • L
GHSA-f6x5-jh6r-wrfv

<0.16.3-r10
  • L
GHSA-v778-237x-gjrc

<0.16.2-r8
  • L
Stack-based Buffer Overflow

<0.16.2-r18
  • L
GHSA-qxp5-gwg8-xv66

<0.16.2-r14
  • L
CVE-2025-47912

<0.16.3-r8
  • L
CVE-2025-22866

<0.16.2-r11
  • L
CVE-2025-22868

<0.16.2-r12
  • L
CVE-2024-45338

<0.16.2-r9
  • H
Integer Overflow or Wraparound

<0.16.2-r15
  • L
Information Exposure Through Log Files

<0.16.3-r8
  • L
GHSA-hcg3-q754-cr77

<0.16.2-r13
  • L
Allocation of Resources Without Limits or Throttling

<0.16.2-r18
  • L
GHSA-jwmf-chvc-rf92

<0.16.3-r8
  • L
GHSA-6v2p-p543-phr9

<0.16.2-r12
  • L
CVE-2025-22870

<0.16.2-r14
  • L
GHSA-mh63-6h87-95cp

<0.16.4-r0
  • L
GHSA-557j-xg8c-q2mm

<0.16.3-r3
  • L
GHSA-j7vj-rw65-4v26

<0.16.2-r6
  • H
Incorrect Execution-Assigned Permissions

<0.16.3-r9
  • L
GHSA-m6hq-p25p-ffr2

<0.16.3-r9
  • L
GHSA-29wx-vh33-7x7r

<0.16.2-r7
  • C
CVE-2025-68121

<0.16.4-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.16.3-r8
  • L
GHSA-9h84-qmv7-982p

<0.16.3-r6
  • L
Algorithmic Complexity

<0.16.3-r8
  • L
Allocation of Resources Without Limits or Throttling

<0.16.3-r8
  • L
GHSA-rjcg-56ph-3qvg

<0.16.3-r8
  • L
CVE-2025-47914

<0.16.3-r10
  • L
GHSA-9gcr-gp5f-jw27

<0.16.3-r8
  • L
Improper Certificate Validation

<0.16.3-r8
  • L
CVE-2025-61732

<0.16.4-r1
  • L
GHSA-qh38-484v-w52x

<0.16.3-r8
  • L
CVE-2024-34156

<0.16.2-r6
  • L
CVE-2024-34158

<0.16.2-r6
  • L
GHSA-62jj-gr2r-5c34

<0.16.3-r2
  • H
Arbitrary Code Injection

<0.16.3-r3
  • L
GHSA-w32m-9786-jp63

<0.16.2-r9
  • L
GHSA-3whm-j4xm-rv8x

<0.16.2-r11
  • L
GHSA-447v-2qg4-h8hc

<0.16.3-r8
  • L
GHSA-5xqw-8hwv-wg92

<0.16.2-r18
  • L
GHSA-g9pc-8g42-g6vq

<0.16.2-r17
  • L
GHSA-xw73-rw38-6vjc

<0.16.2-r15
  • L
CVE-2025-22872

<0.16.2-r19
  • L
CVE-2025-61725

<0.16.3-r8
  • L
GHSA-7wrw-r4p8-38rx

<0.16.2-r10
  • L
Allocation of Resources Without Limits or Throttling

<0.16.3-r8
  • L
CVE-2025-22874

<0.16.3-r2
  • L
GHSA-8pjc-487g-w6p2

<0.16.3-r7
  • L
CVE-2024-45341

<0.16.2-r10
  • L
GHSA-3f6r-qh9c-x6mm

<0.16.2-r10
  • L
CVE-2024-45336

<0.16.2-r10
  • L
CVE-2024-34155

<0.16.2-r6
  • L
GHSA-4hfp-h4cw-hj8p

<0.16.2-r18
  • L
GHSA-6f52-wpx2-hvf2

<0.16.3-r2
  • L
CVE-2025-22871

<0.16.2-r17
  • L
Improper Handling of Exceptional Conditions

<0.16.2-r7
  • L
CVE-2024-45337

<0.16.2-r8
  • L
CVE-2024-41110

<0.16.2-r4
  • L
CVE-2024-24791

<0.16.2-r3
  • M
CVE-2024-24789

<0.16.2-r1
  • C
CVE-2024-24790

<0.16.2-r1
  • L
CVE-2024-24787

<0.16.1-r10
  • L
CVE-2024-24788

<0.16.1-r10
  • L
CVE-2023-45288

<0.16.1-r8
  • L
CVE-2024-24786

<0.16.1-r5
  • L
CVE-2023-45290

<0.16.1-r4
  • L
CVE-2023-45289

<0.16.1-r4
  • L
CVE-2024-24784

<0.16.1-r4
  • L
CVE-2024-24783

<0.16.1-r4
  • L
CVE-2024-24785

<0.16.1-r4
  • H
Use of Uninitialized Resource

<0.16.1-r3
  • M
Directory Traversal

<0.16.1-r2
  • M
Cross-site Scripting (XSS)

<0.16.0-r6
  • H
Allocation of Resources Without Limits or Throttling

<0.16.0-r6