snyk-cli

Direct Vulnerabilities

Known vulnerabilities in the snyk-cli package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-56864

<1.1306.4-r1
  • L
CVE-2026-56865

<1.1306.4-r1
  • L
GHSA-hc8v-wwc9-vgxm

<1.1306.3-r1
  • L
GHSA-qgq7-7hm3-q39j

<1.1306.3-r1
  • L
Link Following

<1.1306.3-r1
  • L
Directory Traversal

<1.1306.3-r1
  • L
GHSA-259r-337f-4rfw

<1.1306.2-r3
  • L
CVE-2026-56852

<1.1306.2-r2
  • L
GHSA-jpjm-c3r5-q96r

<1.1306.2-r2
  • L
GHSA-gg3m-vvp2-p2c5

<1.1306.2-r1
  • L
CVE-2026-46600

<1.1306.2-r1
  • L
GHSA-hrxh-6v49-42gf

<1.1306.2-r0
  • L
CVE-2026-39822

<1.1305.2-r2
  • L
GHSA-xcgv-8mv7-v8c7

<1.1305.2-r2
  • L
CVE-2026-42505

<1.1305.2-r2
  • L
GHSA-ff52-ph69-cf7x

<1.1305.2-r2
  • L
GHSA-5wrp-cwcj-q835

<1.1305.2-r1
  • L
GHSA-qpw4-5x99-6vjp

<1.1304.3-r4
  • L
Uncontrolled Memory Allocation

<1.1305.2-r1
  • L
GHSA-q4h4-gmj2-qvw2

<1.1304.3-r4
  • L
GHSA-w879-237q-wc7r

<1.1304.3-r4
  • L
GHSA-rm3j-f69w-wqmq

<1.1304.3-r4
  • L
GHSA-45gg-vh54-h5m9

<1.1304.3-r4
  • L
GHSA-78mq-xcr3-xm33

<1.1304.3-r4
  • L
GHSA-jppx-rxg9-jmrx

<1.1304.3-r4
  • L
GHSA-89gr-r52h-f8rx

<1.1304.3-r4
  • L
GHSA-vgwf-h737-ff37

<1.1304.3-r4
  • L
GHSA-x527-x647-q7gg

<1.1304.3-r4
  • L
GHSA-f5wc-c3c7-36mc

<1.1304.3-r4
  • L
GHSA-9m57-25v3-79x9

<1.1304.3-r4
  • L
GHSA-4279-q6mj-392r

<1.1304.3-r6
  • L
CVE-2026-27145

<1.1304.3-r6
  • L
CVE-2026-42507

<1.1304.3-r6
  • L
GHSA-h524-452v-82p9

<1.1304.3-r6
  • L
GHSA-h3gm-q7m7-mp28

<1.1304.3-r6
  • L
CVE-2026-42504

<1.1304.3-r6
  • L
Cross-site Scripting (XSS)

<1.1304.3-r5
  • L
GHSA-w9p8-pvxh-rxpj

<1.1304.3-r5
  • L
GHSA-cg87-vwwh-xvgj

<1.1304.3-r5
  • L
GHSA-m9x8-m34x-fj9q

<1.1304.3-r5
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.1304.3-r5
  • L
GHSA-5cv4-jp36-h3mw

<1.1304.3-r5
  • L
GHSA-wrh2-89vg-4j9g

<1.1304.3-r5
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.1304.3-r5
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.1304.3-r5
  • L
Resource Exhaustion

<1.1304.3-r5
  • L
Incorrect Type Conversion or Cast

<1.1304.3-r4
  • L
Integer Overflow or Wraparound

<1.1304.3-r4
  • L
Improper Verification of Cryptographic Signature

<1.1304.3-r4
  • L
Missing Authorization

<1.1304.3-r4
  • L
CVE-2026-46598

<1.1304.3-r4
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1.1304.3-r4
  • L
Improper Certificate Validation

<1.1304.3-r4
  • L
Improper Certificate Validation

<1.1304.3-r4
  • L
Deserialization of Untrusted Data

<1.1304.3-r4
  • L
CVE-2026-46595

<1.1304.3-r4
  • L
Out-of-Bounds

<1.1304.3-r4
  • L
Missing Authorization

<1.1304.3-r4
  • L
GHSA-m7cr-m3pv-hgrp

<1.1304.3-r3
  • C
Improper Encoding or Escaping of Output

<1.1304.3-r3
  • L
Directory Traversal

<1.1304.3-r3
  • L
GHSA-crhj-59gh-8x96

<1.1304.3-r3
  • L
GHSA-389r-gv7p-r3rp

<1.1304.2-r3
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<1.1304.2-r3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.1304.2-r2
  • L
GHSA-xmrv-pmrh-hhx2

<1.1304.2-r0
  • H
Insufficiently Protected Credentials

<1.1304.1-r1
  • L
GHSA-3xc5-wrhm-f963

<1.1304.1-r1
  • L
GHSA-hfvc-g4fc-pqhx

<1.1304.1-r0
  • H
Untrusted Search Path

<1.1304.1-r0
  • L
GHSA-77fj-vx54-gvh7

<1.1304.0-r1
  • L
GHSA-92mm-2pjq-r785

<1.1304.0-r2
  • L
CVE-2026-4660

<1.1304.0-r2
  • L
Out-of-bounds Read

<1.1304.0-r1
  • M
Link Following

<1.1304.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.1304.0-r0
  • H
Incorrect Authorization

<1.1304.0-r0
  • L
GHSA-gjvh-7jh8-7xhm

<1.1304.0-r0
  • L
CVE-2026-32280

<1.1304.0-r0
  • L
GHSA-cqrx-3m42-5p5w

<1.1304.0-r0
  • M
Allocation of Resources Without Limits or Throttling

<1.1304.0-r0
  • L
GHSA-7mr4-xjxg-34g6

<1.1304.0-r0
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1.1304.0-r0
  • M
Cross-site Scripting (XSS)

<1.1304.0-r0
  • L
GHSA-x4jj-h2v8-hqqv

<1.1304.0-r0
  • L
GHSA-cfp9-33rc-j74f

<1.1304.0-r0
  • L
GHSA-m4pr-4j3g-9v7v

<1.1304.0-r0
  • H
Improper Certificate Validation

<1.1304.0-r0
  • L
GHSA-xj38-jxc5-rppx

<1.1304.0-r0
  • L
GHSA-jrg3-gfjw-hm96

<1.1304.0-r0
  • C
CVE-2026-27143

<1.1304.0-r0
  • L
GHSA-5w89-2c2x-6x66

<1.1304.0-r0
  • L
Integer Underflow

<1.1303.2-r1
  • L
GHSA-gm2x-2g9h-ccm8

<1.1303.2-r1
  • L
Improper Validation of Array Index

<1.1303.2-r1
  • L
GHSA-jhf3-xxhw-2wpp

<1.1303.2-r1
  • L
Uncaught Exception

<1.1303.2-r3
  • L
GHSA-78h2-9frx-2jm8

<1.1303.2-r3
  • L
Improper Authorization

<1.1303.1-r3
  • L
GHSA-p77j-4mvh-x3m3

<1.1303.1-r3
  • L
Direct Request ('Forced Browsing')

<1.1303.1-r2
  • L
Cross-site Scripting (XSS)

<1.1303.1-r2
  • L
Directory Traversal

<1.1303.1-r2
  • L
GHSA-rv83-g57w-fr8j

<1.1303.1-r2
  • L
GHSA-j3gx-2473-5fp8

<1.1303.1-r2
  • L
GHSA-j4j7-vw47-rhfq

<1.1303.1-r2
  • L
CVE-2025-22871

<1.1296.1-r1
  • L
GHSA-37cx-329c-33x3

<1.1302.1-r3
  • C
CVE-2026-1229

<1.1303.0-r1
  • M
Improper Validation of Integrity Check Value

<1.1302.1-r3
  • L
GHSA-crqm-pwhx-j97f

<1.1293.1-r0
  • L
GHSA-q9hv-hpm4-hj6x

<1.1303.0-r1
  • L
CVE-2024-34156

<1.1293.1-r0
  • L
GHSA-hcg3-q754-cr77

<1.1295.4-r1
  • L
GHSA-g9pc-8g42-g6vq

<1.1296.1-r1
  • L
CVE-2025-22866

<1.1295.2-r1
  • L
GHSA-3whm-j4xm-rv8x

<1.1295.2-r1
  • L
GHSA-f6x5-jh6r-wrfv

<1.1301.0-r1
  • L
CVE-2024-34155

<1.1293.1-r0
  • L
CVE-2024-34158

<1.1293.1-r0
  • L
CVE-2025-58181

<1.1301.0-r1
  • H
Inefficient Regular Expression Complexity

<1.1297.1-r1
  • L
GHSA-5mh9-3jwc-rp59

<1.1301.0-r2
  • L
GHSA-j7vj-rw65-4v26

<1.1293.1-r0
  • L
GHSA-h355-32pf-p2xm

<1.1302.1-r2
  • L
CVE-2024-45337

<1.1294.3-r0
  • L
GHSA-j5w8-q4qc-rx2x

<1.1301.0-r1
  • L
Improper Certificate Validation

<1.1301.0-r2
  • L
GHSA-69f9-h8f9-7vjf

<1.1294.0-r0
  • L
GHSA-qqqw-gm93-qf6m

<1.1294.0-r0
  • L
GHSA-6v2p-p543-phr9

<1.1295.4-r1
  • L
CVE-2025-22868

<1.1295.4-r1
  • C
OS Command Injection

<1.1294.0-r0
  • H
Arbitrary Code Injection

<1.1294.0-r0
  • L
CVE-2025-61732

<1.1302.1-r2
  • L
GHSA-w32m-9786-jp63

<1.1294.3-r1
  • L
Improper Validation of Specified Type of Input

<1.1297.1-r1
  • L
GHSA-8xfx-rj4p-23jm

<1.1293.1-r0
  • L
GHSA-v778-237x-gjrc

<1.1294.3-r0
  • L
CVE-2025-47914

<1.1301.0-r1
  • L
CVE-2025-22869

<1.1295.4-r1
  • L
CVE-2024-45338

<1.1294.3-r1
  • L
GHSA-8jvr-vh7g-f8gx

<1.1302.1-r2
  • C
CVE-2025-68121

<1.1302.1-r2
  • L
GHSA-3f2q-6294-fmq5

<1.1297.1-r1
  • L
GHSA-r9px-m959-cxf4

<1.1294.3-r2
  • L
GHSA-wjrx-6529-hcj3

<1.1298.3-r1
  • L
GHSA-2x5j-vhc8-9cwm

<1.1297.1-r1
  • L
Resource Exhaustion

<1.1294.3-r2
  • L
CVE-2025-8959

<1.1298.3-r1
  • L
Race Condition

<1.1298.2-r1
  • L
GHSA-7c64-f9jr-v9h2

<1.1301.0-r2
  • L
Improper Certificate Validation

<1.1301.0-r2
  • L
GHSA-j5pm-7495-qmr3

<1.1298.2-r1
  • L
GHSA-c77r-fh37-x2px

<1.1293.1-r1
  • L
Arbitrary Argument Injection

<1.1294.3-r2
  • H
Authentication Bypass

<1.1293.1-r1
  • L
CVE-2025-22870

<1.1295.4-r2
  • L
GHSA-qxp5-gwg8-xv66

<1.1295.4-r2
  • L
GHSA-v725-9546-7q7m

<1.1294.3-r2
  • L
CVE-2024-24791

<1.1292.1-r1
  • H
CVE-2024-6257

<1.1291.1-r3
  • M
Information Exposure Through Log Files

<1.1291.1-r2
  • C
CVE-2024-24790

<1.1291.1-r1
  • M
CVE-2024-24789

<1.1291.1-r1
  • L
CVE-2024-24788

<1.1291.0-r1
  • L
CVE-2024-24787

<1.1291.0-r1