Packagist incidents
Recent Packagist vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
HIGHPackagist
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
pterodactyl/panel: before 1.12.3
MEDIUMPackagist
libsodium has Incomplete List of Disallowed Inputs
libsodium has Incomplete List of Disallowed Inputs
paragonie/sodium_compat: 2 → 2.5.0
MEDIUMPackagist
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements
tinymce/tinymce: before 7.0.0
Tooling for Packagist
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.