github.com/remix-run/remix
Submitted 8/4/2026, 10:28:01 AM · Status: ok
Risk grade
F
100 / 100
Findings
265
3 critical45 high210 medium7 low0 info0 on CISA KEV0ATT&CK
Showing 265 of 265 findings
Findings
- node-tar: Decompression/parse DoS via unlimited inputgrypeCVE-2026-59873EPSS 0.4%
- When Vitest UI server is listening, arbitrary file can be read and executedgrypeCVE-2026-47429EPSS 1.0%
- tar: node-tar: Denial of Service via crafted gzip bombnode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to …trivyCVE-2026-59873
- Detected private-key: Identified a Private Key, which may compromise cryptographic security and sensitive data encryptionIdentified a Private Key, which may compromise cryptographic security and sensitive data encryption.gitleaks
- brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsgrypeCVE-2026-13149EPSS 0.4%
- brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashgrypeCVE-2026-14257EPSS 0.3%
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationgrypeCVE-2026-69152
- find-my-way: DDoS with HTTP2grypeCVE-2026-47219EPSS 0.5%
- js-yaml: YAML merge-key chains can force quadratic CPU consumptiongrypeCVE-2026-59869EPSS 0.4%
- linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker textgrypeCVE-2026-59887EPSS 0.3%
- LinkifyIt#match scan loop has quadratic algorithmic complexitygrypeCVE-2026-48801EPSS 0.3%
- node-tar: Negative tar entry size causes infinite loop in archive replacegrypeCVE-2026-59874EPSS 0.4%
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591grype
- SVGO removeScripts plugin leaves some executable scripts intactgrype
- tmp has Path Traversal via unsanitized prefix/postfix that enables directory escapegrypeCVE-2026-44705EPSS 0.4%
- undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reusegrypeCVE-2026-6734EPSS 0.4%
- undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesgrypeCVE-2026-13697EPSS 0.3%
- undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgentgrypeCVE-2026-9697EPSS 0.5%
- undici WebSocket client vulnerable to denial of service via fragment count bypassgrypeCVE-2026-12151EPSS 0.8%
- vite: `server.fs.deny` bypass on Windows alternate pathsgrypeCVE-2026-53571EPSS 0.6%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret stCommitted PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)semgreppackages/node-fetch-server/demos/http2/server.key:1
- Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)semgreppackages/data-table-sqlite/src/lib/adapter.ts:346
- Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)semgreppackages/data-table-sqlite/src/lib/adapter.ts:357
- Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)semgreppackages/data-table-sqlite/src/lib/adapter.ts:368
- Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)semgreppackages/data-table-sqlite/src/lib/adapter.ts:437
- Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)semgreppackages/data-table-sqlite/src/lib/adapter.ts:440
- Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)semgrepscripts/publish.ts:162
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-mysql/src/lib/adapter.ts:219
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-mysql/src/lib/adapter.ts:295
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-mysql/src/lib/adapter.ts:306
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-mysql/src/lib/adapter.ts:317
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-mysql/src/lib/adapter.ts:333
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.integration.test.ts:77
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.integration.test.ts:78
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.integration.test.ts:97
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.ts:263
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.ts:274
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.ts:285
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.ts:309
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.ts:310
- SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)semgreppackages/data-table-postgres/src/lib/adapter.ts:564
- find-my-way: DDoS with HTTP2find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function pas…trivyCVE-2026-47219
- js-yaml: js-yaml: Denial of Service via crafted YAML documentsjs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…trivyCVE-2026-59869
- SVGO removeScripts plugin leaves some executable scripts intact### Summary SVGO's removeScripts plugin (disabled by default) removes scripts from the SVG, however executable scripts were left intact in some cases. If a consumer relied on this plugin for sanitization and served them to users, these SVGs could open up doors to XSS. ### Detai…trivy
- tar: Node-tar: Denial of Service via malformed tar archive headernode-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed …trivyCVE-2026-59874
- tmp is a temporary file and directory creator for node.js. Prior to 0. ...tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal …trivyCVE-2026-44705
This report is public.