See the full list of npm packages compromised in the "Shai-Hulud supply chain attack – Sep 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applicationsVULNERABILITY | AFFECTS | TYPE | PUBLISHED |
---|---|---|---|
| skyvern[,0.2.1) | pip | 25 Jun 2025 |
| psslib[0,] | pip | 25 Jun 2025 |
| langchain[,0.1.12) | pip | 24 Jun 2025 |
| langchain-community[,0.0.28) | pip | 24 Jun 2025 |
| changedetection.io[,0.50.4) | pip | 24 Jun 2025 |
| apache-airflow-providers-snowflake[,6.4.0) | pip | 24 Jun 2025 |
| mlflow[,3.0.0) | pip | 24 Jun 2025 |
| motioneye[0.43.1b1,0.43.1b4) | pip | 23 Jun 2025 |
| inspiremusic[0,] | pip | 23 Jun 2025 |
| letta[0,] | pip | 23 Jun 2025 |
| reflex[0.2.7,0.4.9.post1)[0.5.0a1,0.5.10.post1)[0.6.0a1,0.6.8.post1)[0.7.0a1,0.7.1.post1)[0.7.2.dev1,0.7.2.post1)[0.7.3a1,0.7.3.post1)[0.7.4a0,0.7.4.post1)[0.7.5a1,0.7.5.post1)[0.7.6a0,0.7.6.post1)[0.7.7a1,0.7.7.post1)[0.7.8a1,0.7.8.post1)[0.7.9a1,0.7.9.post1)[0.7.10a1,0.7.10.post1)[0.7.11a1,0.7.11) | pip | 20 Jun 2025 |
| urllib3[,2.5.0) | pip | 19 Jun 2025 |
| urllib3[2.2.0,2.5.0) | pip | 19 Jun 2025 |
| vantage6-server[,4.11.0rc2) | pip | 18 Jun 2025 |
| vantage6-server[,4.11.0rc2) | pip | 18 Jun 2025 |
| mezzanine[,6.1.1) | pip | 18 Jun 2025 |
| xinference[0.15.0,] | pip | 17 Jun 2025 |
| weblate[,5.12.1) | pip | 17 Jun 2025 |
| weblate[,5.12.1) | pip | 17 Jun 2025 |
| pycares[,4.9.0) | pip | 17 Jun 2025 |
| protobuf[,4.25.8)[5.26.0rc1, 5.29.5)[6.30.0rc1, 6.31.1) | pip | 17 Jun 2025 |
| mindspore[2.4.0,] | pip | 16 Jun 2025 |
| salt[,3006.12)[3007.0rc1,3007.4) | pip | 16 Jun 2025 |
| salt[,3006.12)[3007.0rc1,3007.4) | pip | 16 Jun 2025 |
| salt[,3006.12)[3007.0rc1,3007.4) | pip | 16 Jun 2025 |
| salt[,3006.12)[3007.0rc1,3007.4) | pip | 16 Jun 2025 |
| langroid[,0.53.15) | pip | 16 Jun 2025 |
| langroid[,0.53.15) | pip | 16 Jun 2025 |
| salt[3006.0rc1,3006.12)[3007.0rc1,3007.4) | pip | 16 Jun 2025 |
| salt[3007.0,3007.4) | pip | 16 Jun 2025 |