이 취약점은 실제인가요, 악용되고 있나요, 아니면 노이즈인가요?
패키지, CVE 또는 보안 우려 사항을 붙여넣으세요. 증명하고, 설명하고, 수정 방법을 보여드립니다.
지원 형식: 패키지 이름, 패키지@버전, CVE ID, CWE ID, npm/PyPI URL
실시간 보안 알림
전체 보기 →Payload delivery from suspicious source: IOC URL + execution capability
2 versions flagged · Latest 2.3.2
Payload delivery from suspicious source: IOC URL + execution capability
Dynamic / forked-detached shell paired with code obfuscation — runtime dropper attribution (no install hook required)
2 versions flagged · Latest 0.48.0
Payload delivery from suspicious source: IOC URL + execution capability
2 versions flagged · Latest 0.1.2
Payload delivery from suspicious source: IOC URL + execution capability
주목할 만한 취약점
Updated 14m agon8n Vulnerable to Remote Code Execution via Expression Injection
Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
Langflow has Remote Code Execution in CSV Agent
주요 탐지 약점
전체 보기 →Exposure of Sensitive Information to an Unauthorized Actor
Improper Input Validation
Use of Hard-coded Credentials
Improper Control of Generation of Code ('Code Injection')
Execution with Unnecessary Privileges
Permissive Cross-domain Policy with Untrusted Domains
Uncontrolled Resource Consumption
Authorization Bypass Through User-Controlled Key
패키지 보안 상태
터미널에서 스캔
Shoulder를 로컬에서 실행하여 설치 전 패키지를 분석하거나 전체 프로젝트의 취약점을 스캔하세요.
npx @shoulderdev/cli check <package>
npx @shoulderdev/cli trust .