Skip to content

Conversation

@Ibrahimrahhal
Copy link
Contributor

Screen.Recording.2025-10-11.at.9.33.36.AM.mov

@corgea-staging
Copy link

🐕 Corgea found the following new SCA issues in the codebase:

Package CVE Severity Version Fixed Version Ecosystem Summary
axios CVE-2025-58754 HIGH 1.7.9 0.30.2 npm Axios is vulnerable to DoS attack through lack of data size check

Showing 1 out of 1 findings. See full results

@corgea
Copy link

corgea bot commented Oct 11, 2025

🐕 Corgea found the following new SCA issues in the codebase:

Package CVE Severity Version Fixed Version Ecosystem Summary
axios CVE-2025-58754 HIGH 1.7.9 0.30.2 npm Axios is vulnerable to DoS attack through lack of data size check
form-data CVE-2025-7783 CRITICAL 4.0.1 4.0.4 npm form-data uses unsafe random function in form-data for choosing boundary
esbuild N/A MEDIUM 0.21.5 0.25.0 npm esbuild enables any website to send any requests to the development server and read the response
tmp CVE-2025-54798 LOW 0.2.3 0.2.4 npm tmp allows arbitrary temporary file / directory write via symbolic link dir parameter
vite CVE-2025-58751 LOW 5.4.19 5.4.20 npm Vite middleware may serve files starting with the same name with the public directory

Showing 5 out of 6 findings. See full results

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants