Ist diese Schwachstelle real, ausgenutzt oder nur Rauschen?
Fügen Sie ein Paket, CVE oder Sicherheitsbedenken ein. Wir beweisen es, erklären es und zeigen die Lösung.
Akzeptiert: Paketnamen, Paket@Version, CVE-IDs, CWE-IDs, npm/PyPI-URLs
Live-Sicherheitswarnungen
Alle anzeigen →Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed
3 versions flagged · Latest 0.10.0
OIDC trusted-publisher / SLSA provenance attestation lost vs prior version — publishing pipeline bypassed (account takeover or stolen token signature)
OIDC trusted-publisher / SLSA provenance attestation lost vs prior version — publishing pipeline bypassed (account takeover or stolen token signature)
OIDC trusted-publisher / SLSA provenance attestation lost vs prior version — publishing pipeline bypassed (account takeover or stolen token signature)
Publisher email transitioned to a known anonymous-by-design / burner provider — account-takeover signal
Bemerkenswerte Schwachstellen
Updated 1h agon8n Vulnerable to Remote Code Execution via Expression Injection
Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
Langflow has Remote Code Execution in CSV Agent
Häufigste erkannte Schwächen
Alle anzeigen →Exposure of Sensitive Information to an Unauthorized Actor
Improper Input Validation
Use of Hard-coded Credentials
Improper Control of Generation of Code ('Code Injection')
Execution with Unnecessary Privileges
Permissive Cross-domain Policy with Untrusted Domains
Uncontrolled Resource Consumption
Authorization Bypass Through User-Controlled Key
Paket-Sicherheitsstatus
Scannen Sie von Ihrem Terminal
Führen Sie Shoulder lokal aus, um Pakete vor der Installation zu analysieren, oder scannen Sie Ihr gesamtes Projekt auf Schwachstellen.
npx @shoulderdev/cli check <package>
npx @shoulderdev/cli trust .