hacktribunebeta
IncidentsAlertsNewsletterPricingAbout
Live feedSign in with GitHub
Home / Incidents / Packagist

Packagist incidents

Recent Packagist vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

HIGHPackagist

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

pterodactyl/panel: before 1.12.3

1 month ago
MEDIUMPackagist

libsodium has Incomplete List of Disallowed Inputs

libsodium has Incomplete List of Disallowed Inputs

paragonie/sodium_compat: 2 → 2.5.0

8 months ago
MEDIUMPackagist

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

tinymce/tinymce: before 7.0.0

2 years ago

Tooling for Packagist

Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexMavenNuGetPubPyPIRubyGemsSwiftURLcrates.ionpm
hacktribune
Developer security signal for the stack you actually run.
IncidentsTopicsEcosystemsFrameworksPricingAboutRSS
Incident data: OSV · CISA KEV · EPSS (FIRST)