Is this vulnerability real, exploited, or noise?
Paste a package, CVE, or security concern. We prove it, explain it, and show the fix.
Accepts: package names, package@version, CVE IDs, CWE IDs, npm/PyPI/crates.io URLs, or prefix syntax (pypi:requests)
Live Security Alerts
View all →Adds a 'prepare' install hook that runs during 'npm install'
package deprecated (blast_radius=1,020): Amazon Bedrock Agents service will no longer be open to new customers starting on July 30, 2026. Existing customers can continue to use the service as normal.
package deprecated (blast_radius=3,383): This package is deprecated. Please use Homebrew (brew install ggcode) or winget (winget install gg.ai.ggcode-cli) instead.
Adds a 'preinstall' install hook that runs during 'npm install'
Adds a 'prepare' install hook that runs during 'npm install'
Notable Vulnerabilities
Updated 2h agon8n Vulnerable to Remote Code Execution via Expression Injection
Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
Langflow has Remote Code Execution in CSV Agent
Weaknesses You Should Know About
View all →Exposure of Sensitive Information to an Unauthorized Actor
Improper Input Validation
Use of Hard-coded Credentials
Improper Control of Generation of Code ('Code Injection')
Execution with Unnecessary Privileges
Permissive Cross-domain Policy with Untrusted Domains
Uncontrolled Resource Consumption
Authorization Bypass Through User-Controlled Key
Package Security Status
Scan from your terminal
Run Shoulder locally to analyze packages before installing them, or scan your entire project for vulnerabilities.
npx @shoulderdev/cli check <package>
npx @shoulderdev/cli trust .