1.2.1
4 months ago
5 hours ago
Known vulnerabilities in the decepticon-sdk package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
decepticon-sdk is a Decepticon plugin author SDK: protocols, fixtures, scaffolding Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via Note: This is only exploitable when Decepticon is configured with a BYOK OpenAI-compatible backend whose tokenizer preserves special-token IDs (vLLM, SGLang, TGI, and Ollama are confirmed vulnerable); hosted vendors such as OpenAI and Anthropic strip these tokens server-side. How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | [,1.1.17) |