← Scan another repo

github.com/remix-run/remix

@ 74adf4921a4f

Submitted 8/4/2026, 10:28:01 AM · Status: ok

Risk grade
F
100 / 100
Findings
265
3 critical45 high210 medium7 low0 info0 on CISA KEV0ATT&CK
Showing 265 of 265 findings

Findings

  • node-tar: Decompression/parse DoS via unlimited input
    grypeCVE-2026-59873EPSS 0.4%
  • When Vitest UI server is listening, arbitrary file can be read and executed
    grypeCVE-2026-47429EPSS 1.0%
  • tar: node-tar: Denial of Service via crafted gzip bomb
    node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to …
    trivyCVE-2026-59873
  • Detected private-key: Identified a Private Key, which may compromise cryptographic security and sensitive data encryption
    Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    gitleaks
  • brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
    grypeCVE-2026-13149EPSS 0.4%
  • brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    grypeCVE-2026-14257EPSS 0.3%
  • brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
    grypeCVE-2026-69152
  • find-my-way: DDoS with HTTP2
    grypeCVE-2026-47219EPSS 0.5%
  • js-yaml: YAML merge-key chains can force quadratic CPU consumption
    grypeCVE-2026-59869EPSS 0.4%
  • linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
    grypeCVE-2026-59887EPSS 0.3%
  • LinkifyIt#match scan loop has quadratic algorithmic complexity
    grypeCVE-2026-48801EPSS 0.3%
  • node-tar: Negative tar entry size causes infinite loop in archive replace
    grypeCVE-2026-59874EPSS 0.4%
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
    grype
  • SVGO removeScripts plugin leaves some executable scripts intact
    grype
  • tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
    grypeCVE-2026-44705EPSS 0.4%
  • undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
    grypeCVE-2026-6734EPSS 0.4%
  • undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
    grypeCVE-2026-13697EPSS 0.3%
  • undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
    grypeCVE-2026-9697EPSS 0.5%
  • undici WebSocket client vulnerable to denial of service via fragment count bypass
    grypeCVE-2026-12151EPSS 0.8%
  • vite: `server.fs.deny` bypass on Windows alternate paths
    grypeCVE-2026-53571EPSS 0.6%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret st
    Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)
    semgreppackages/node-fetch-server/demos/http2/server.key:1
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-sqlite/src/lib/adapter.ts:346
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-sqlite/src/lib/adapter.ts:357
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-sqlite/src/lib/adapter.ts:368
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-sqlite/src/lib/adapter.ts:437
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-sqlite/src/lib/adapter.ts:440
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgrepscripts/publish.ts:162
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-mysql/src/lib/adapter.ts:219
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-mysql/src/lib/adapter.ts:295
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-mysql/src/lib/adapter.ts:306
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-mysql/src/lib/adapter.ts:317
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-mysql/src/lib/adapter.ts:333
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.integration.test.ts:77
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.integration.test.ts:78
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.integration.test.ts:97
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.ts:263
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.ts:274
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.ts:285
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.ts:309
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.ts:310
  • SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    SQL query built by string concatenation with a variable — SQL injection risk. Use parameterized queries / prepared statements. (First-party socbox; Apache-2.0.)
    semgreppackages/data-table-postgres/src/lib/adapter.ts:564
  • find-my-way: DDoS with HTTP2
    find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function pas…
    trivyCVE-2026-47219
  • js-yaml: js-yaml: Denial of Service via crafted YAML documents
    js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…
    trivyCVE-2026-59869
  • SVGO removeScripts plugin leaves some executable scripts intact
    ### Summary SVGO's removeScripts plugin (disabled by default) removes scripts from the SVG, however executable scripts were left intact in some cases. If a consumer relied on this plugin for sanitization and served them to users, these SVGs could open up doors to XSS. ### Detai…
    trivy
  • tar: Node-tar: Denial of Service via malformed tar archive header
    node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed …
    trivyCVE-2026-59874
  • tmp is a temporary file and directory creator for node.js. Prior to 0. ...
    tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal …
    trivyCVE-2026-44705

This report is public.