1.2.14
7 months ago
15 days ago
Known vulnerabilities in the local-deep-research package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
local-deep-research is an AI-powered research assistant with deep, iterative analysis using LLMs and web searches Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the logging of sensitive configuration data by the How to fix Insertion of Sensitive Information into Log File? Upgrade | [,1.0.0) |
local-deep-research is an AI-powered research assistant with deep, iterative analysis using LLMs and web searches Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via incomplete HTML sanitization in the client-side PDF export pipeline. An attacker can exploit this vulnerability by supplying crafted HTML or script payloads that bypass the regular expression–based filtering in the How to fix Cross-site Scripting (XSS)? Upgrade | [,1.0.0) |
local-deep-research is an AI-powered research assistant with deep, iterative analysis using LLMs and web searches Affected versions of this package are vulnerable to Open Redirect via the How to fix Open Redirect? Upgrade | [,1.0.0) |
local-deep-research is an AI-powered research assistant with deep, iterative analysis using LLMs and web searches Affected versions of this package are vulnerable to Improper Input Validation via the HTML entity decoding logic in the client-side PDF export pipeline. An attacker can exploit this vulnerability by supplying specially crafted input containing nested or malformed HTML entities that are double-unescaped in the How to fix Improper Input Validation? Upgrade | [,1.0.0) |