2026.824.1
5 months ago
5 days ago
Known vulnerabilities in the @paperclipai/shared package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Missing Authentication for Critical Function in several API endpoints that lack proper authentication checks. An attacker can access sensitive data, perform state-changing operations, and obtain internal configuration details by sending unauthenticated requests to exposed endpoints. How to fix Missing Authentication for Critical Function? Upgrade | <2026.416.0 |
Affected versions of this package are vulnerable to Insufficient Granularity of Access Control inadequate authorization checks in the Note: This is only exploitable if the application is running in authenticated mode with open signup enabled and at least one other company with agents exists on the instance. How to fix Insufficient Granularity of Access Control? Upgrade | <2026.416.0 |
Affected versions of this package are vulnerable to Arbitrary Command Injection via the How to fix Arbitrary Command Injection? Upgrade | <2026.416.0 |
Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity via the Note: This is only exploitable if the attacker is an authenticated board user with access to the target company. How to fix Insufficient Verification of Data Authenticity? Upgrade | <2026.416.0 |
Affected versions of this package are vulnerable to External Control of File Name or Path via the How to fix External Control of File Name or Path? Upgrade | <2026.416.0 |
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <2026.416.0 |