Repository navigation
Expand file tree
/
Copy pathclaude-code.jsonl
More file actions
165 lines (165 loc) · 165 KB
/
Copy pathclaude-code.jsonl
File metadata and controls
165 lines (165 loc) · 165 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
{"cve_id":"CVE-2017-16100","variant":"fixed","cve_explanation":"Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method. \n\n\n\n## Recommendation\n\n- Use an alternative dns resolver\n- Do not allow untrusted input into `dns-sync.resolve()`","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16003","variant":"fixed","cve_explanation":"windows-build-tools is a module for installing C++ Build Tools for Windows using npm. windows-build-tools versions below 1.0.0 download resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.","cve_explanation_source":"osv","original_explanations":["Download of sensitive file through insecure connection"],"detected_issues":[{"file":"src/download.js","explanation":"SSL/TLS certificate verification is disabled (strictSSL: false) when downloading executable installers. This allows Man-in-the-Middle attackers to intercept the HTTPS connection and replace the downloaded executables (BuildTools_Full.exe and python-2.7.11.msi) with malicious payloads. When these executables are subsequently run with elevated privileges, arbitrary code execution occurs on the victim's machine.","position":{"begin":{"line":34,"column":1},"end":{"line":34,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The single detected issue does not match the exact CVE vulnerability. The CVE concerns HTTP downloads vulnerable to MITM. The detection points to HTTPS with disabled SSL verification, indicating a flaw in the fix implementation (incomplete mitigation of MITM risks) rather than the original HTTP issue. Security impact (MITM RCE) is similar, but not the same instance or attack vector as the CVE.\""}
{"cve_id":"CVE-2017-16029","variant":"fixed","cve_explanation":"Affected versions of `hostr` are vulnerable to directory traversal which allows attackers to read files outside the current directory by sending `../` in the url path for GET requests.\n\n\n## Recommendation\n\nUpgrade to version 2.3.6 or later.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[{"file":"lib/routes/statics.js","explanation":"The path traversal sanitization is inadequate and can be bypassed. The regex patterns `replace(/\\/\\.\\./, \"\")` and `replace(/\\.\\.\\//,\"\")` only remove the first occurrence of path traversal sequences (no global flag). Additionally, it fails to handle: (1) URL-encoded sequences like `%2e%2e%2f` or `%2f%2e%2e`, (2) nested traversal like `....//` which becomes `../` after replacement, (3) mixed encoding variations. This allows an attacker to read arbitrary files outside the web root, including sensitive files like `/etc/passwd`, environment files, or application source code.","position":{"begin":{"line":27,"column":1},"end":{"line":27,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The detected issue in the fixed code identifies flaws in the path traversal sanitization logic added as the fix (inadequate regex replacements that miss bypasses like encodings and nested sequences). This is an evaluation of the fix's incompleteness, enabling path traversal via advanced techniques, but not the original CVE's direct '../' exploitation due to lack of any sanitization. Per guidelines, issues flagging 'inadequate', 'bypassable', or 'incomplete' fixes do not match the original CVE, as they concern fix quality rather than the resolved original vulnerability. No issue describes the exact original vulnerability; thus, no match."}
{"cve_id":"CVE-2018-1000096","variant":"fixed","cve_explanation":"brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.","cve_explanation_source":"osv","original_explanations":["Disabling certificate validation"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16100","variant":"unfixed","cve_explanation":"Affected versions of `dns-sync` have an arbitrary command execution vulnerability in the `resolve()` method. \n\n\n\n## Recommendation\n\n- Use an alternative dns resolver\n- Do not allow untrusted input into `dns-sync.resolve()`","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"lib/dns-sync.js","explanation":"The 'hostname' parameter is directly concatenated into a shell command without any sanitization or escaping. The util.format call on line 19 builds a command string that includes the hostname parameter unquoted, which is then executed via shell.exec(). An attacker who controls the hostname input can inject arbitrary shell commands.","position":{"begin":{"line":19,"column":1},"end":{"line":19,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue describes the precise vulnerability in CVE-2017-16100: command injection leading to arbitrary command execution in the resolve() method through unsanitized 'hostname' input concatenated into a shell command via util.format and shell.exec(). Same impact (arbitrary RCE), same attack pattern (command injection from library input), and same instance (dns-sync.js resolve() method)."}
{"cve_id":"CVE-2017-16224","variant":"fixed","cve_explanation":"st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. (\"%2e%2e\", \"%2e.\", \".%2e\").","cve_explanation_source":"osv","original_explanations":["Server-side URL redirect"],"detected_issues":[{"file":"st.js","explanation":"Path traversal vulnerability due to decodeURIComponent being called AFTER the directory traversal check. The code first decodes single URL encoding (%2e → .), then checks for '..' patterns, but then calls decodeURIComponent() afterward which decodes any remaining encoded characters. An attacker can use double URL encoding (%252e%252e) to bypass the traversal check: %252e is first decoded to %2e (not '.'), passes the '..' check, then decodeURIComponent converts %2e to '.', resulting in '..' which enables directory traversal outside the mount path.","position":{"begin":{"line":192,"column":1},"end":{"line":192,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The single detected issue describes a path traversal vulnerability, not the CVE's specific open redirect vulnerability. Different impacts and vectors; in fixed code, this appears to be a distinct or remaining issue, not the original CVE."}
{"cve_id":"CVE-2017-16003","variant":"unfixed","cve_explanation":"windows-build-tools is a module for installing C++ Build Tools for Windows using npm. windows-build-tools versions below 1.0.0 download resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.","cve_explanation_source":"osv","original_explanations":["Download of sensitive file through insecure connection"],"detected_issues":[{"file":"src/download.js","explanation":"SSL certificate verification is explicitly disabled (strictSSL: false) when downloading executable installers. This allows Man-in-the-Middle attackers to intercept the HTTPS connection and serve malicious executables instead of legitimate Visual Studio Build Tools and Python installers.","position":{"begin":{"line":34,"column":1},"end":{"line":34,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely identifies the vulnerability in src/download.js where SSL verification is disabled during downloads, allowing MITM interception identical to the CVE's described risk of resource tampering over insecure connections leading to RCE. Terminology differs (HTTPS with strictSSL:false vs. HTTP), but security outcome, attack vector, and instance (downloading Visual Studio/Python installers) match exactly."}
{"cve_id":"CVE-2018-1000096","variant":"unfixed","cve_explanation":"brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.","cve_explanation_source":"osv","original_explanations":["Disabling certificate validation"],"detected_issues":[{"file":"_read.js","explanation":"SSL/TLS certificate validation is explicitly disabled by setting rejectUnauthorized to false. This makes all HTTPS requests vulnerable to man-in-the-middle (MITM) attacks because the client will accept any certificate, including self-signed, expired, or malicious certificates presented by an attacker.","position":{"begin":{"line":35,"column":1},"end":{"line":35,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely matches the CVE vulnerability. It identifies the explicit disabling of SSL/TLS certificate validation via rejectUnauthorized: false in the library's HTTPS handling (_read.js), resulting in MITM exposure, which is the core issue described in CVE-2018-1000096. No other issues detected, but this one is an exact match on security impact (MITM), attack pattern (missing cert validation), and vulnerability instance (library core functionality)."}
{"cve_id":"CVE-2017-16029","variant":"unfixed","cve_explanation":"Affected versions of `hostr` are vulnerable to directory traversal which allows attackers to read files outside the current directory by sending `../` in the url path for GET requests.\n\n\n## Recommendation\n\nUpgrade to version 2.3.6 or later.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[{"file":"lib/routes/statics.js","explanation":"The code constructs a file path by directly concatenating user-controlled input (resource.pathname from req.url) with process.cwd() without any sanitization. An attacker can use URL-encoded path traversal sequences like '../' or '..%2f' to escape the current working directory and read arbitrary files from the filesystem, including sensitive files like /etc/passwd, configuration files, or application secrets.","position":{"begin":{"line":26,"column":1},"end":{"line":26,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely matches the CVE-2017-16029 vulnerability: directory traversal in the statics route by using user-controlled URL path (resource.pathname) concatenated to process.cwd() without sanitization, allowing '../' sequences to read arbitrary files. Same impact (arbitrary file disclosure) and exact attack vector as described."}
{"cve_id":"CVE-2017-16014","variant":"fixed","cve_explanation":"Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service.","cve_explanation_source":"osv","original_explanations":["Server crash"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16224","variant":"unfixed","cve_explanation":"st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. (\"%2e%2e\", \"%2e.\", \".%2e\").","cve_explanation_source":"osv","original_explanations":["Server-side URL redirect"],"detected_issues":[{"file":"st.js","explanation":"The path traversal check at line 183 only matches `..` when surrounded by slashes (`/[/\\]\\.\\.[/\\]/`), but fails to catch `..` at the end of a path (e.g., `/foo/..`). An attacker can use URLs ending in `..` to bypass the traversal check and access files outside the mounted directory. The `path.normalize()` on line 189 will resolve `..` components, allowing directory escape.","position":{"begin":{"line":183,"column":1},"end":{"line":183,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"The sole detected issue describes a path traversal vulnerability allowing directory escape and arbitrary file access, which has a different security impact (information disclosure) and attack pattern compared to the CVE's open external redirect vulnerability (phishing/SSRF-like redirect to arbitrary domains). Although both involve malformed paths with '..', they target different behaviors in the st module: file serving traversal vs. redirect handling. No match for the exact CVE vulnerability."}
{"cve_id":"CVE-2017-18077","variant":"fixed","cve_explanation":"index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.","cve_explanation_source":"osv","original_explanations":["Inefficient regular expression"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16014","variant":"unfixed","cve_explanation":"Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service.","cve_explanation_source":"osv","original_explanations":["Server crash"],"detected_issues":[{"file":"lib/node-http-proxy.js","explanation":"Missing validation of req.headers.upgrade before calling toLowerCase(). If the 'upgrade' header is missing or undefined, calling toLowerCase() will throw a TypeError, but more critically, if a malicious actor can craft a request without a proper upgrade header that passes the truthy check but fails the websocket comparison, the socket won't be destroyed and may lead to unauthorized WebSocket connections being proxied.","position":{"begin":{"line":418,"column":1},"end":{"line":418,"column":1}}},{"file":"lib/node-http-proxy.js","explanation":"The buffer function's destroy() method sets variables to null (line 183) but the resume() function can still be called with stale references due to race conditions. While destroy() overwrites resume(), the events array and obj reference could be accessed by code still executing from a previous asynchronous callback, leading to data from one request being emitted to another request's stream.","position":{"begin":{"line":177,"column":1},"end":{"line":177,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The first detected issue matches the CVE exactly: it identifies the unhandled TypeError from invalid/missing 'upgrade' header (attacker-forced error), leading to server crash/DoS, same as CVE description. The second issue is unrelated (race-based data leak). Thus, at least one match confirms detection of the specific CVE vulnerability."}
{"cve_id":"CVE-2017-18077","variant":"unfixed","cve_explanation":"index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.","cve_explanation_source":"osv","original_explanations":["Inefficient regular expression"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16023","variant":"fixed","cve_explanation":"Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.","cve_explanation_source":"osv","original_explanations":["Regular expression injection"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16137","variant":"unfixed","cve_explanation":"The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16023","variant":"unfixed","cve_explanation":"Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.","cve_explanation_source":"osv","original_explanations":["Regular expression injection"],"detected_issues":[{"file":"index.js","explanation":"The `sep` parameter is directly interpolated into a regular expression without escaping special regex characters. This allows an attacker to inject arbitrary regex patterns by providing malicious separator values containing regex metacharacters (e.g., `.*`, `|`, `(`, `)`). While the primary impact is ReDoS (denial of service), the regex injection could also be exploited to alter the matching behavior in unexpected ways, potentially leading to logic bugs in downstream code that relies on predictable output from this function.","position":{"begin":{"line":8,"column":1},"end":{"line":8,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely identifies the CVE vulnerability: regex injection via unescaped separator parameter leading to ReDoS/DoS. Same impact (DoS), same attack pattern (unescaped input in regex), and same instance (decamelize function's sep handling)."}
{"cve_id":"CVE-2018-1002204","variant":"unfixed","cve_explanation":"adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16490","variant":"fixed","cve_explanation":"Versions of `mpath` before 0.5.1 are vulnerable to prototype pollution. Provided certain input `mpath` can add or modify properties of the `Object` prototype. These properties will be present on all objects.\n\n\n## Recommendation\n\nUpdate to version `0.5.1` or later.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"lib/index.js","explanation":"The set() function only blocks '__proto__' paths but does not block 'constructor.prototype' paths. An attacker can pollute Object.prototype by setting paths like 'constructor.prototype.polluted' to inject arbitrary properties into all JavaScript objects. This is a classic prototype pollution vulnerability that can lead to denial of service, property injection, or in some cases remote code execution depending on how the polluted properties are used downstream.","position":{"begin":{"line":186,"column":1},"end":{"line":186,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"In the fixed version (0.5.1+), the original prototype pollution vulnerability via the specific input paths described in CVE-2018-16490 has been resolved. The security agent detected a related but distinct issue: pollution via 'constructor.prototype' paths, which bypasses the fix implemented for '__proto__'. This flags an incomplete or improper fix rather than the original vulnerability, so it does not match the exact CVE. Same category (prototype pollution) but different attack vector/gadget, and explicitly comments on the fix's limitations."}
{"cve_id":"CVE-2017-18353","variant":"fixed","cve_explanation":"Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.","cve_explanation_source":"osv","original_explanations":["Reflected cross-site scripting"],"detected_issues":[{"file":"src/main.js","explanation":"Chrome headless browser is launched with --remote-debugging-address=0.0.0.0, which binds the Chrome DevTools Protocol (CDP) to all network interfaces. This allows any machine on the network (or internet if exposed) to connect to the debugging port and execute arbitrary JavaScript, read/write files, and take full control of the browser instance. The DevTools protocol has no authentication mechanism.","position":{"begin":{"line":145,"column":1},"end":{"line":145,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The single detected issue describes a misconfiguration exposing Chrome's debugging interface (--remote-debugging-address=0.0.0.0), enabling remote arbitrary JS execution and browser control. This differs from the CVE's _ah/stop route, which allowed any remote attacker to shut down the service via GET request. Distinct locations (Chrome flags vs app route), vectors (port access vs HTTP endpoint), and outcomes (RCE vs DoS shutdown). No match for the exact CVE vulnerability in fixed code."}
{"cve_id":"CVE-2017-16043","variant":"unfixed","cve_explanation":"Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.","cve_explanation_source":"osv","original_explanations":["Client-side cross-site scripting"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16490","variant":"unfixed","cve_explanation":"Versions of `mpath` before 0.5.1 are vulnerable to prototype pollution. Provided certain input `mpath` can add or modify properties of the `Object` prototype. These properties will be present on all objects.\n\n\n## Recommendation\n\nUpdate to version `0.5.1` or later.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"lib/index.js","explanation":"The mpath.set() function is vulnerable to Prototype Pollution (CVE-2018-16490). When setting values using object paths, the function does not sanitize dangerous path segments like '__proto__', 'constructor', or 'prototype'. An attacker can inject malicious properties into Object.prototype, which will affect all JavaScript objects in the application. This can lead to arbitrary code execution, denial of service, or security bypass depending on how the polluted properties are used by the application.","position":{"begin":{"line":272,"column":1},"end":{"line":272,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely describes the CVE vulnerability: prototype pollution in mpath.set() by failing to sanitize paths like '__proto__', enabling Object.prototype pollution with the same consequences."}
{"cve_id":"CVE-2018-13797","variant":"fixed","cve_explanation":"The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"lib/linux.js","explanation":"The `iface` parameter is directly concatenated into a file path without validation, allowing path traversal attacks. An attacker can provide a malicious interface name like `../../etc/passwd` or `../../../etc/shadow` to read arbitrary files from the system via the `cat` command. The execFile function prevents command injection but does not prevent path traversal in the file argument.","position":{"begin":{"line":4,"column":1},"end":{"line":4,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The sole detected issue identifies path traversal vulnerability in the fixed code's execFile usage, which is a distinct issue from the original CVE's command injection via exec. The fix addressed the CVE (command injection prevented), but introduced/did not address path traversal separately. Not the exact same vulnerability instance or attack vector."}
{"cve_id":"CVE-2017-18353","variant":"unfixed","cve_explanation":"Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.","cve_explanation_source":"osv","original_explanations":["Reflected cross-site scripting"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16026","variant":"fixed","cve_explanation":"Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.","cve_explanation_source":"osv","original_explanations":["Resource exhaustion"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-13797","variant":"unfixed","cve_explanation":"The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"lib/linux.js","explanation":"The `iface` parameter is directly concatenated into a shell command executed via child_process.exec() without any sanitization or validation. An attacker who can control the `iface` parameter can inject arbitrary shell commands.","position":{"begin":{"line":4,"column":1},"end":{"line":4,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue describes the precise vulnerability documented in CVE-2018-13797: command injection via unsanitized `iface` parameter in lib/linux.js using child_process.exec(). The security impact (arbitrary command execution) and attack pattern (direct concatenation into shell command) are identical, confirming it is the exact same vulnerability instance."}
{"cve_id":"CVE-2017-16087","variant":"fixed","cve_explanation":"Affected versions of `fs-git` do not sanitize strings passed into the `buildCommand` method, resulting in arbitrary code execution.\n\n\n## Recommendation\n\nUpdate to version 1.0.2 or later. ","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-18354","variant":"fixed","cve_explanation":"Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in network request"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16087","variant":"unfixed","cve_explanation":"Affected versions of `fs-git` do not sanitize strings passed into the `buildCommand` method, resulting in arbitrary code execution.\n\n\n## Recommendation\n\nUpdate to version 1.0.2 or later. ","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"lib/index.ts","explanation":"The _buildCommand method concatenates user-controlled input (this.path and args) directly into a shell command string without sanitization. This command is then executed via child_process.exec() which spawns a shell, allowing an attacker to inject arbitrary shell commands through the 'path', 'ref', or file path parameters.","position":{"begin":{"line":125,"column":1},"end":{"line":125,"column":1}}},{"file":"lib/index.ts","explanation":"The readFile method passes user-controlled 'path' parameter directly to _buildCommand and ultimately to child_process.exec() without sanitization. The path is concatenated with ref using ':' separator and can contain shell metacharacters.","position":{"begin":{"line":62,"column":1},"end":{"line":62,"column":1}}},{"file":"lib/index.ts","explanation":"The revParse method accepts a 'ref' parameter that is passed directly to _buildCommand without sanitization. This allows command injection through the ref parameter.","position":{"begin":{"line":83,"column":1},"end":{"line":83,"column":1}}},{"file":"lib/index.ts","explanation":"The _lsTree method passes the 'path' parameter directly to _buildCommand and exec() without sanitization, allowing command injection through file path arguments.","position":{"begin":{"line":100,"column":1},"end":{"line":100,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"All detected issues describe the exact same vulnerability as CVE-2017-16087: lack of sanitization of user-controlled strings (path, ref, args) passed into _buildCommand, leading to command injection/arbitrary code execution via child_process.exec(). They target the same method and security flaw in the unfixed variant, with identical impact (arbitrary code execution) and attack pattern (shell command injection). No partial fixes or unrelated issues present."}
{"cve_id":"CVE-2017-16026","variant":"unfixed","cve_explanation":"Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.","cve_explanation_source":"osv","original_explanations":["Resource exhaustion"],"detected_issues":[{"file":"lib/multipart.js","explanation":"The multipart.js build function directly concatenates user-controlled part keys and values into HTTP headers without any sanitization or validation. An attacker who controls the keys in a multipart part object can inject arbitrary HTTP headers by including CRLF sequences (\\r\\n). This is CVE-2017-16026. The vulnerable code constructs headers by directly concatenating: `preamble += key + ': ' + part[key] + '\\r\\n'` where both `key` and `part[key]` can contain CRLF characters, allowing injection of additional headers or even response splitting attacks.","position":{"begin":{"line":82,"column":1},"end":{"line":82,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"The single detected issue does not match the CVE's resource exhaustion vulnerability. It describes a distinct CRLF-based header injection issue in the same file, with different exploitation method and impact. Agent's claim of it being the CVE is incorrect based on provided descriptions."}
{"cve_id":"CVE-2018-16491","variant":"fixed","cve_explanation":"A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"lib/extend.js","explanation":"While this code protects against __proto__ prototype pollution (CVE-2018-16491 fix), it remains vulnerable to prototype pollution via the 'constructor.prototype' path. An attacker can pass a malicious object like {constructor: {prototype: {isAdmin: true}}} which will pollute Object.prototype when deep=true is used. The for-in loop at line 75 iterates over all properties including 'constructor', and since the code only checks for '__proto__' (lines 20, 34), the 'constructor' property is allowed through and merged recursively into the target's constructor.prototype, polluting the global Object prototype.","position":{"begin":{"line":75,"column":1},"end":{"line":75,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No detected issue matches the exact CVE-2018-16491 vulnerability. The security agent flagged a related but distinct prototype pollution issue via 'constructor.prototype', which is a bypass of the fix rather than the original '__proto__' pollution path addressed by the CVE fix. Per guidelines for fixed code, this does not count as detecting the specific original CVE vulnerability."}
{"cve_id":"CVE-2017-18354","variant":"unfixed","cve_explanation":"Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in network request"],"detected_issues":[{"file":"src/renderer.js","explanation":"The url parameter is directly interpolated into a JavaScript string passed to Runtime.evaluate() without any sanitization or escaping. An attacker can craft a URL containing single quotes and JavaScript code to break out of the string context and execute arbitrary JavaScript in the Chrome browser instance. For example, a URL like \"http://example.com'); alert('xss'); //\" would escape the string and execute attacker-controlled code. This is Server-Side Request Forgery (SSRF) combined with JavaScript injection in the headless browser context, which could be used to access internal network resources or perform other malicious actions.","position":{"begin":{"line":188,"column":1},"end":{"line":188,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"The sole detected issue focuses on JS injection and SSRF, not the CVE's specific LFI vulnerability via file:// protocol. No exact match for the CVE vulnerability instance."}
{"cve_id":"CVE-2017-16107","variant":"fixed","cve_explanation":"Affected versions of `pooledwebsocket` resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside of the intended directory root, which may result in the disclosure of private files on the vulnerable system.\n\n**Example request:**\n```http\nGET /../../../../../../../../../../etc/passwd HTTP/1.1\nhost:foo\n```\n\n\n## Recommendation\n\nUpdate to version 0.0.19 or later.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[{"file":"server.js","explanation":"Path traversal vulnerability in file serving. The regex `.replace(/^(\\.\\.[\\/\\\\])+/, '')` only removes leading '../' sequences but fails to prevent path traversal via URL-encoded characters (e.g., %2e%2e%2f), nested sequences after normalization, or absolute paths. An attacker can read arbitrary files from the filesystem.","position":{"begin":{"line":10,"column":1},"end":{"line":10,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The security agent detected a path traversal issue in the fixed code, but it focuses on limitations in the fix implementation (e.g., fails against URL-encoded '../', nested sequences, absolute paths). The original CVE-2017-16107 specifically involved directory traversal via plain relative paths (e.g., /../../../../etc/passwd). Since this is fixed code and the detection targets bypasses of the fix rather than the original plain '../' attack vector, it does not match the exact CVE vulnerability. The original vulnerability is no longer present in its described form."}
{"cve_id":"CVE-2017-16028","variant":"fixed","cve_explanation":"Affected versions of `randomatic` generate random values using a cryptographically weak psuedo-random number generator. This may result in predictable values instead of random values as intended.\n\n\n\n\n## Recommendation\n\nUpdate to version 3.0.0 or later.","cve_explanation_source":"osv","original_explanations":["Insecure randomness"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16107","variant":"unfixed","cve_explanation":"Affected versions of `pooledwebsocket` resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside of the intended directory root, which may result in the disclosure of private files on the vulnerable system.\n\n**Example request:**\n```http\nGET /../../../../../../../../../../etc/passwd HTTP/1.1\nhost:foo\n```\n\n\n## Recommendation\n\nUpdate to version 0.0.19 or later.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[{"file":"server.js","explanation":"The HTTP server directly concatenates user-controlled req.url with __dirname to create a file path for fs.createReadStream without any sanitization. This allows an attacker to traverse directories and read arbitrary files on the system using path traversal sequences like '../'.","position":{"begin":{"line":9,"column":1},"end":{"line":9,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue in server.js matches the CVE vulnerability precisely: both involve path traversal through user-controlled relative paths (e.g., '../' or '/../../../../etc/passwd') leading to arbitrary file disclosure outside the intended directory, using unsanitized input in file path resolution with fs.createReadStream."}
{"cve_id":"CVE-2018-16491","variant":"unfixed","cve_explanation":"A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16028","variant":"unfixed","cve_explanation":"Affected versions of `randomatic` generate random values using a cryptographically weak psuedo-random number generator. This may result in predictable values instead of random values as intended.\n\n\n\n\n## Recommendation\n\nUpdate to version 3.0.0 or later.","cve_explanation_source":"osv","original_explanations":["Insecure randomness"],"detected_issues":[{"file":"index.js","explanation":"Math.random() is used to generate random characters for what appears to be a security-sensitive random string generator. Math.random() is not cryptographically secure and produces predictable values. This is a known vulnerability (CVE-2017-16028) in the randomatic package.","position":{"begin":{"line":81,"column":1},"end":{"line":81,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The security agent correctly identified the exact vulnerability in CVE-2017-16028: the use of insecure Math.random() in the randomatic package leading to predictable random values. The detection directly references the CVE and matches the description, security impact (predictable randomness), and attack pattern (weak PRNG in random string generation)."}
{"cve_id":"CVE-2017-18355","variant":"fixed","cve_explanation":"Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the \"_where\" attribute of package.json files.","cve_explanation_source":"osv","original_explanations":["Exposure of private files"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16117","variant":"fixed","cve_explanation":"slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16117","variant":"unfixed","cve_explanation":"slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16034","variant":"fixed","cve_explanation":"Affected versions of `pidusage` pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method.\n \nThis package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.\n\nWindows and Linux are not vulnerable. \n\n## Proof of Concept\n```\nvar pid = require('pidusage');\npid.stat('1 && /usr/local/bin/python');\n```\n\n\n## Recommendation\n\nUpdate to version 1.1.5 or later.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-18355","variant":"unfixed","cve_explanation":"Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the \"_where\" attribute of package.json files.","cve_explanation_source":"osv","original_explanations":["Exposure of private files"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16136","variant":"fixed","cve_explanation":"method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-14042","variant":"fixed","cve_explanation":"In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.","cve_explanation_source":"osv","original_explanations":["Unsafe jQuery plugin"],"detected_issues":[{"file":"js/tooltip.js","explanation":"The template option from data attributes is passed directly to jQuery's $() function without sanitization. When the options are merged at line 87 via this.$element.data(), any data-template attribute value is included. At line 432, this.$tip = $(this.options.template) parses this as HTML, allowing execution of arbitrary JavaScript through event handlers like onerror. This is related to CVE-2019-8331 where sanitization was later added to Bootstrap tooltip/popover components.","position":{"begin":{"line":432,"column":1},"end":{"line":432,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The sole detected issue flags XSS in the tooltip template option (data-template), not the data-container property specified in CVE-2018-14042. This is a different vulnerability instance in the same file/component, so it does not match the exact CVE. In fixed code, the original data-container vuln should be resolved, and this appears to be an unrelated or later issue (per agent's CVE-2019-8331 reference).\""}
{"cve_id":"CVE-2018-1002203","variant":"fixed","cve_explanation":"unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[{"file":"lib/extract.js","explanation":"The Zip Slip mitigation is incomplete. The check on line 24-26 uses path.join() followed by indexOf() to validate paths, but this can be bypassed because: 1) opts.path is not resolved to an absolute path before joining, so relative path attacks may succeed depending on the working directory, 2) The indexOf check is vulnerable to directory prefix collision attacks - if opts.path is '/tmp/out', an attacker could write to '/tmp/outbound/malicious' since '/tmp/outbound'.indexOf('/tmp/out') === 0. The fix should use path.resolve() on opts.path first and compare using either string concatenation with a trailing separator or by checking that the resolved extractPath starts with the resolved destination followed by path.sep.","position":{"begin":{"line":24,"column":1},"end":{"line":24,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The single detected issue identifies bypasses in the implemented Zip-Slip mitigation (path.join + indexOf check), explicitly calling it 'incomplete.' Per guidelines for fixed code, this is a critique of fix quality (improper/partial mitigation), not detection of the original unmitigated directory traversal CVE vulnerability. No issue matches the exact original CVE (arbitrary file write via mishandled ../ in extraction without proper safeguards)."}
{"cve_id":"CVE-2017-16136","variant":"unfixed","cve_explanation":"method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16462","variant":"fixed","cve_explanation":"A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"index.js","explanation":"User-controlled input is passed directly to spawnSync without proper sanitization. The opts.sqlclPath parameter is used as the command to execute, and multiple user-controlled parameters (opts.connectString, opts.appID, opts.destination, opts.pluginName) are passed as arguments. An attacker who can control these options could inject malicious values to execute arbitrary commands.","position":{"begin":{"line":74,"column":1},"end":{"line":74,"column":1}}}],"TP":0,"FP":1,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely identifies the original CVE-2018-16462 vulnerability: command injection via unsanitized user input (opts.sqlclPath and arguments) to spawnSync in index.js, allowing arbitrary shell command execution. Despite being fixed code, the agent's detection targets the exact same vulnerability instance, location, and exploitation pattern as described in the CVE."}
{"cve_id":"CVE-2017-16034","variant":"unfixed","cve_explanation":"Affected versions of `pidusage` pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method.\n \nThis package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.\n\nWindows and Linux are not vulnerable. \n\n## Proof of Concept\n```\nvar pid = require('pidusage');\npid.stat('1 && /usr/local/bin/python');\n```\n\n\n## Recommendation\n\nUpdate to version 1.1.5 or later.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16462","variant":"unfixed","cve_explanation":"A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"index.js","explanation":"Multiple user-controlled parameters (opts.sqlclPath, opts.connectString, opts.appID, opts.destination, opts.pluginName) are concatenated directly into a shell command executed via execSync() without any sanitization. An attacker can inject arbitrary shell commands through any of these parameters.","position":{"begin":{"line":54,"column":1},"end":{"line":54,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The detected issue precisely describes the command injection vulnerability in apex-publish-static-files via user-controlled opts parameters in shell commands, matching CVE-2018-16462 exactly (same impact: arbitrary shell execution; same pattern: unsafe concatenation into execSync)."}
{"cve_id":"CVE-2018-1002203","variant":"unfixed","cve_explanation":"unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[{"file":"lib/extract.js","explanation":"The Extract function uses path.join() with an untrusted entry.path from the ZIP archive without validating that the resulting path stays within the intended extraction directory. A malicious ZIP file can contain entries with paths like '../../../etc/passwd' or absolute paths that escape the target directory, allowing arbitrary file write anywhere on the filesystem (Zip Slip vulnerability). This is CVE-2018-1002203.","position":{"begin":{"line":21,"column":1},"end":{"line":21,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely describes the Zip Slip vulnerability (directory traversal allowing arbitrary file writes during ZIP extraction) in lib/extract.js, matching the CVE's security impact, attack pattern, and instance, with explicit reference to CVE-2018-1002203."}
{"cve_id":"CVE-2017-16137","variant":"fixed","cve_explanation":"The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16042","variant":"fixed","cve_explanation":"Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"lib/growl.js","explanation":"The `options.exec` parameter is passed directly to `spawn()` without any validation or sanitization. An attacker who can control the `options.exec` value can execute arbitrary commands on the system. The user-supplied `options.exec` value is assigned directly to `cmd.pkg` (line 172), which becomes `args[0]`, then `cmd_to_exec` (line 286), and is finally passed to `spawn()` (line 288).","position":{"begin":{"line":169,"column":1},"end":{"line":169,"column":1}}},{"file":"lib/growl.js","explanation":"In the 'Custom' case block, user-controlled `options.title` and `msg` values are concatenated and inserted into the command string via string replacement using `$1' + message`. The message is inserted into the command template without proper escaping, which can lead to command injection if the original command contains shell metacharacters or if the message itself contains special characters that could alter command execution.","position":{"begin":{"line":276,"column":1},"end":{"line":276,"column":1}}}],"TP":0,"FP":1,"TN":0,"FN":0,"judge_reasoning":"The first detected issue exactly matches the CVE vulnerability: unsanitized library input (`options.exec`) passed directly to a process execution function (`spawn()`), allowing arbitrary command execution. The second issue is a distinct, related command injection in a different code path involving message insertion, not the precise CVE instance. Since at least one issue matches exactly (same impact, attack pattern, and vulnerability instance in fixed code context), cve_matches_any_issue is true. No indications of improper fix criticism; detections describe persistent original vulnerability patterns."}
{"cve_id":"CVE-2018-20834","variant":"fixed","cve_explanation":"A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16472","variant":"fixed","cve_explanation":"A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.","cve_explanation_source":"osv","original_explanations":["Remote property injection"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2017-16042","variant":"unfixed","cve_explanation":"Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16472","variant":"unfixed","cve_explanation":"A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.","cve_explanation_source":"osv","original_explanations":["Remote property injection"],"detected_issues":[{"file":"lib/index.js","explanation":"The cachedPathRelative function uses user-controlled input ('from' and 'to' parameters) directly as object keys without validation. When 'from' is set to '__proto__', 'constructor', or 'prototype', and the cache lookup or assignment happens, it can pollute the Object prototype. Specifically, at line 38-39, `cache[from] = cache[from] || {}` followed by `cache[from][to] = result` allows an attacker to set arbitrary properties on Object.prototype when from='__proto__'.","position":{"begin":{"line":34,"column":1},"end":{"line":34,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The detected issue precisely identifies the prototype pollution vulnerability in cached-path-relative's cachedPathRelative function, where user-controlled 'from' and 'to' parameters are used as cache object keys without validation, enabling property injection on Object.prototype as described in CVE-2018-16472."}
{"cve_id":"CVE-2018-1002204","variant":"fixed","cve_explanation":"adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16478","variant":"fixed","cve_explanation":"All versions of `simplehttpserver` are vulnerable to Path Traversal. \n\nThis vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.\n\n\n## Recommendation\n\nNo fix is currently available. Do not use `simplehttpserver` in production or consider using an alternative module until a fix is made available.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-20834","variant":"unfixed","cve_explanation":"A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-16478","variant":"unfixed","cve_explanation":"All versions of `simplehttpserver` are vulnerable to Path Traversal. \n\nThis vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.\n\n\n## Recommendation\n\nNo fix is currently available. Do not use `simplehttpserver` in production or consider using an alternative module until a fix is made available.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[{"file":"simplehttpserver/simplehttpserver.js","explanation":"Path traversal vulnerability allows attackers to read files outside the web root directory. The pathname from user-controlled URL is joined with the base directory using path.join(), but this does not prevent traversal sequences. An attacker can use URL-encoded path traversal sequences (e.g., %2e%2e%2f or ..%2f) to escape the web root and access arbitrary files on the filesystem.","position":{"begin":{"line":58,"column":1},"end":{"line":58,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The detected issue exactly matches the CVE-2018-16478 vulnerability: path traversal in simplehttpserver allowing attackers to read files outside the webroot using traversal sequences in URLs, aligning with the CVE's description of path traversal and symlink navigation."}
{"cve_id":"CVE-2017-16043","variant":"fixed","cve_explanation":"Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.","cve_explanation_source":"osv","original_explanations":["Client-side cross-site scripting"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-20835","variant":"fixed","cve_explanation":"A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[{"file":"index.js","explanation":"Symlink target (header.linkname) is not validated before creating the symlink. While the destination path 'name' is sanitized using path.join('/', header.name), the symlink target 'header.linkname' is passed directly from the tar archive without any validation. This allows a malicious tar archive to create symlinks pointing to arbitrary locations outside the extraction directory. An attacker can craft a tar archive with: 1) A symlink entry pointing to a sensitive file like '/etc/passwd' or '../../../sensitive', 2) A subsequent file entry that uses the symlink path. When extracted, the symlink gets created pointing outside the target directory, and any subsequent file operations through that symlink would affect files outside the extraction directory.","position":{"begin":{"line":257,"column":1},"end":{"line":257,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The single detected issue concerns symlink path traversal/overwrites, not the hardlink-based overwrite specified in the CVE. Symlinks and hardlinks are distinct mechanisms. In fixed code, the hardlink vulnerability should be resolved, and detecting a different (symlink) issue does not count as matching the original CVE vulnerability."}
{"cve_id":"CVE-2018-20835","variant":"unfixed","cve_explanation":"A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[{"file":"index.js","explanation":"Arbitrary file overwrite via symlink extraction vulnerability. The header.linkname from a tar archive is used directly in xfs.symlink() without any validation. A malicious tar archive can contain a symlink entry with linkname pointing to an absolute path (e.g., /etc/passwd) or a relative path traversing outside the extraction directory (e.g., ../../etc/passwd). When extracting such an archive, the symlink is created pointing to the attacker-controlled destination. A subsequent file entry with the same name as the symlink will overwrite the target file through the symlink, allowing arbitrary file write.","position":{"begin":{"line":257,"column":1},"end":{"line":257,"column":1}}},{"file":"index.js","explanation":"Hard link extraction allows linking to files outside the extraction directory. The header.linkname is resolved relative to cwd using path.resolve(), but there's no validation that the resolved path stays within the extraction boundary. An attacker can create a hard link pointing to sensitive files outside the extraction directory, then read or modify those files through the hard link.","position":{"begin":{"line":264,"column":1},"end":{"line":264,"column":1}}},{"file":"index.js","explanation":"Directory type entries bypass the validate() function for path traversal checks. When header.type is 'directory', the code immediately calls mkdirfix() and stat() without running the validate() function that checks for path traversal on file/link entries. While line 238 attempts to normalize the path using path.join(cwd, path.join('/', header.name)), symlink race conditions and other edge cases could potentially be exploited since directories don't go through the same validation as other entry types.","position":{"begin":{"line":291,"column":1},"end":{"line":291,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The second detected issue precisely captures the CVE vulnerability: lack of validation on hardlink targets (header.linkname) allows creating hardlinks to arbitrary existing files outside the extraction directory, enabling their overwrite/modification (e.g., via a subsequent plain file extraction to the same name), matching the exact security impact (arbitrary file overwrite) and attack pattern described in CVE-2018-20835."}
{"cve_id":"CVE-2018-3713","variant":"fixed","cve_explanation":"Affected versions of `angular-http-server` are vulnerable to path traversal allowing a remote attacker to read files from the server that uses `angular-http-server`.\n\n## Recommendation\n\nUpdate to version 1.6.0 or later.\n\n:exclamation: Note: This was originally thought to be fixed in version 1.4.3, though according to [this issue](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark/issues/117#issuecomment-803872454) the vulnerability was not completely fixed until version 1.6.0.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3726","variant":"fixed","cve_explanation":"crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.","cve_explanation_source":"osv","original_explanations":["Stored cross-site scripting"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3726","variant":"unfixed","cve_explanation":"crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.","cve_explanation_source":"osv","original_explanations":["Stored cross-site scripting"],"detected_issues":[{"file":"crud-file-server.js","explanation":"The cleanUrl function has a flawed path traversal protection. The condition `url.indexOf('..').length > 0` is incorrect - indexOf returns -1 if not found or the index position (a number), and numbers don't have a `.length` property (returns undefined). This means the condition is always falsy, making the while loop never execute. The protection against directory traversal using '..' sequences is completely broken, allowing attackers to read, write, or delete arbitrary files outside the intended directory.","position":{"begin":{"line":6,"column":1},"end":{"line":6,"column":1}}},{"file":"crud-file-server.js","explanation":"When rendering directory listings as HTML, file names are inserted directly into the HTML response without sanitization. The `name` variable (from `results[f].name`) is written directly to the response in both the href attribute and the anchor text without escaping HTML special characters.","position":{"begin":{"line":143,"column":1},"end":{"line":143,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The second detected issue exactly describes the CVE vulnerability (XSS via unsanitized file names in HTML directory listings), sharing the same security impact (XSS) and attack pattern (unvalidated file names in HTML). The first issue is a distinct path traversal vulnerability and does not match."}
{"cve_id":"CVE-2018-3752","variant":"unfixed","cve_explanation":"The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10750","variant":"fixed","cve_explanation":"Versions of `deeply` prior to 1.0.1 are vulnerable to Prototype Pollution. The package fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects.\n\n\n\n\n## Recommendation\n\nUpgrade to version 3.1.0 or later.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"lib/reduce_object.js","explanation":"The isUnsafeKey function only blocks '__proto__' but fails to block 'constructor' which can also be used for prototype pollution attacks. An attacker can pollute Object.prototype via obj.constructor.prototype when merging untrusted input. This allows arbitrary property injection on all JavaScript objects in the application.","position":{"begin":{"line":43,"column":1},"end":{"line":43,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The CVE describes prototype pollution due to failure to validate Object properties updated (prior to 1.0.1). In fixed code, the agent detects an incomplete mitigation where '__proto__' is blocked but 'constructor' is not, allowing pollution via obj.constructor.prototype. This is the same category (prototype pollution) and impact (arbitrary property injection), but a different vector/instance resulting from an improper/partial fix, not the original unmitigated vulnerability. Per guidelines for fixed variants and partial fix detection, this does not match the exact CVE vulnerability."}
{"cve_id":"CVE-2019-10777","variant":"unfixed","cve_explanation":"In aws-lambda versions prior to version 1.0.5, the \"config.FunctioName\" is used to construct the argument used within the \"exec\" function without any sanitization. It is possible for a user to inject arbitrary commands to the \"zipCmd\" used within \"config.FunctionName\".","cve_explanation_source":"osv","original_explanations":["Uncontrolled command line"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-7651","variant":"unfixed","cve_explanation":"index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10061","variant":"fixed","cve_explanation":"utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.","cve_explanation_source":"osv","original_explanations":["Indirect uncontrolled command line"],"detected_issues":[{"file":"utils/find-opencv.js","explanation":"Environment variable PKG_CONFIG_OPENCV3 is not validated before being used in exec() command construction. While the current code only checks for strict equality with '1', the alternative branch uses a hardcoded string. However, any future modification or if an attacker can control PKG_CONFIG_OPENCV3 in certain build environments, arbitrary commands could be injected via shell metacharacters in the environment variable value if the conditional logic changes.","position":{"begin":{"line":15,"column":1},"end":{"line":15,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The sole detected issue in the fixed code acknowledges the CVE fix (validation via === '1' check) but speculates on potential injection risks under unlikely scenarios like future modifications or attacker-controlled build env vars. This does not match the original CVE vulnerability (unvalidated user input in exec() causing command injection), as it addresses a new, hypothetical concern about fix quality, not the resolved original attack vector. Same file, but different vulnerability instance focused on post-fix risks."}
{"cve_id":"CVE-2018-3736","variant":"fixed","cve_explanation":"Resource exhaustion","cve_explanation_source":"original","original_explanations":["Resource exhaustion"],"detected_issues":[{"file":"index.js","explanation":"HTTP header injection (CRLF injection) vulnerability. The hostname and port values from opts are directly concatenated into the CONNECT request without sanitization. If an attacker can control these values, they can inject CRLF characters (\\r\\n) to manipulate HTTP headers or inject additional HTTP requests, potentially leading to request smuggling or response splitting attacks.","position":{"begin":{"line":201,"column":1},"end":{"line":201,"column":1}}},{"file":"index.js","explanation":"HTTP header injection vulnerability in custom proxy headers. The proxy.headers object values are directly concatenated into the HTTP request without sanitization. If an attacker can control header values (via the headers option passed to HttpsProxyAgent), they can inject CRLF characters to manipulate headers or inject additional requests.","position":{"begin":{"line":219,"column":1},"end":{"line":219,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"Detected issues describe HTTP header/CRLF injection vulnerabilities leading to smuggling/splitting, not resource exhaustion (e.g., DoS via CPU/memory). These are distinct vulnerabilities with different impacts and attack vectors. In fixed code, original resource exhaustion CVE is resolved; detected issues are unrelated/new."}
{"cve_id":"CVE-2019-10750","variant":"unfixed","cve_explanation":"Versions of `deeply` prior to 1.0.1 are vulnerable to Prototype Pollution. The package fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects.\n\n\n\n\n## Recommendation\n\nUpgrade to version 3.1.0 or later.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"lib/reduce_object.js","explanation":"The reduceObject function iterates over all keys of the source object using Object.keys() and directly assigns them to the target object without filtering dangerous property names. An attacker can provide a malicious source object with '__proto__' or 'constructor.prototype' keys to pollute the Object prototype, affecting all objects in the application. This is CVE-2019-10750.","position":{"begin":{"line":17,"column":1},"end":{"line":17,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue accurately identifies the exact prototype pollution vulnerability in lib/reduce_object.js as described in CVE-2019-10750, including the attack vector with '__proto__' and impact on Object prototype."}
{"cve_id":"CVE-2018-3757","variant":"fixed","cve_explanation":"Versions of `pdf-image` before 2.0.0 are vulnerable to command injection. This vulnerability is exploitable if the attacker has control over the `pdfFilePath` variable passed into `pdf-image`.\n\n\n## Recommendation\n\nUpdate to version 2.0.0 or later.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"index.js","explanation":"The command string 'gm convert' or 'convert' contains a space in the cmd parameter passed to spawn(). The child-process-promise spawn() function will execute this as a shell command when the cmd contains spaces, potentially allowing command injection through the pdfFilePath, convertOptions, or outputDirectory parameters. An attacker controlling the pdfFilePath could inject shell metacharacters to execute arbitrary commands.","position":{"begin":{"line":85,"column":1},"end":{"line":85,"column":1}}},{"file":"index.js","explanation":"Same command injection vulnerability in constructCombineCommandForFile(). The 'gm convert' command string with a space in cmd parameter combined with user-controlled imagePaths array allows command injection.","position":{"begin":{"line":94,"column":1},"end":{"line":94,"column":1}}},{"file":"index.js","explanation":"The constructConvertOptions() function directly uses keys and values from user-controlled convertOptions object without validation. These are passed as arguments to the convert/gm command, allowing arbitrary command-line argument injection.","position":{"begin":{"line":98,"column":1},"end":{"line":98,"column":1}}},{"file":"index.js","explanation":"The getOutputImagePathForPage() function constructs output paths using user-controlled pdfFileBaseName and outputDirectory without proper validation. An attacker could use path traversal sequences to write files outside the intended directory.","position":{"begin":{"line":54,"column":1},"end":{"line":54,"column":1}}}],"TP":0,"FP":1,"TN":0,"FN":0,"judge_reasoning":"The first detected issue precisely describes the CVE-2018-3757 vulnerability: command injection exploitable via control of pdfFilePath in a shell command constructed with spawn() on a spaced cmd ('gm convert'/'convert'). This matches the exact instance, attack vector (pdfFilePath), and security impact (arbitrary command execution). Even in fixed code, this detection aligns with the specific CVE description. Other issues are related command/arg injections or path traversal in different code paths/parameters, not the exact CVE vulnerability."}
{"cve_id":"CVE-2018-3736","variant":"unfixed","cve_explanation":"Resource exhaustion","cve_explanation_source":"original","original_explanations":["Resource exhaustion"],"detected_issues":[{"file":"index.js","explanation":"HTTP Header Injection / Request Smuggling vulnerability via unsanitized proxy.headers values. The code directly concatenates header names and values into the HTTP CONNECT request without sanitizing for CRLF characters. If an attacker can control proxy.headers values (e.g., through user-supplied proxy configuration), they can inject arbitrary HTTP headers or even additional HTTP requests by including \\r\\n sequences in header values.","position":{"begin":{"line":219,"column":1},"end":{"line":219,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"The CVE vulnerability is resource exhaustion, a DoS condition from depleting system resources. The sole detected issue is HTTP Header Injection/Request Smuggling, a distinct vulnerability involving CRLF injection for header/request manipulation. While smuggling could indirectly enable DoS, it does not match the exact security impact, attack pattern, or CVE-described instance of resource exhaustion."}
{"cve_id":"CVE-2019-10061","variant":"unfixed","cve_explanation":"utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.","cve_explanation_source":"osv","original_explanations":["Indirect uncontrolled command line"],"detected_issues":[{"file":"utils/find-opencv.js","explanation":"The 'flag' variable sourced from process.argv[2] is directly concatenated into a shell command executed via child_process.exec() without any sanitization. An attacker who can control command-line arguments can inject arbitrary shell commands. For example, passing '--exists; rm -rf /' or '$(malicious_command)' as the argument would execute arbitrary commands on the system.","position":{"begin":{"line":15,"column":1},"end":{"line":15,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely describes the CVE-2019-10061 vulnerability: command injection in utils/find-opencv.js from uncontrolled command-line argument (process.argv[2]) directly used in shell execution without validation. Matches security impact (arbitrary command execution), attack pattern (command injection via argv), and exact vulnerability instance (specific file and code path)."}
{"cve_id":"CVE-2019-10785","variant":"fixed","cve_explanation":"dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.","cve_explanation_source":"osv","original_explanations":["Incomplete string escaping or encoding"],"detected_issues":[{"file":"xmpp/util.js","explanation":"The createElement function builds XML strings by directly concatenating attribute values without any encoding. Although xmlEncode() is defined in the same file, it is NOT used to sanitize the attribute values before insertion. If user-controlled data flows into the attributes object (e.g., via xmppSession.js search() function at line 633-634 where 'service' and 'jid' are used), an attacker could inject malicious XML/HTML content by including characters like quotes, angle brackets, or ampersands. This is the core vulnerability addressed by CVE-2019-10785.","position":{"begin":{"line":92,"column":1},"end":{"line":92,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No detected issue matches the exact CVE vulnerability. The sole issue flags unsafe string concatenation in createElement without using xmlEncode, whereas the CVE is precisely about the xmlEncode function itself being incomplete (first occurrence only). These are related XML/XSS issues in the same module but differ in specifics: missing encoding vs. partial encoding. For fixed code, the agent does not describe the original CVE flaw persisting but a different concern, so no match."}
{"cve_id":"CVE-2019-10757","variant":"unfixed","cve_explanation":"knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.","cve_explanation_source":"osv","original_explanations":["Replacement of a substring with itself"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3757","variant":"unfixed","cve_explanation":"Versions of `pdf-image` before 2.0.0 are vulnerable to command injection. This vulnerability is exploitable if the attacker has control over the `pdfFilePath` variable passed into `pdf-image`.\n\n\n## Recommendation\n\nUpdate to version 2.0.0 or later.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"index.js","explanation":"The pdfFilePath is passed directly to pdfinfo command via util.format without proper sanitization. While the path is enclosed in double quotes, an attacker can escape these quotes using specially crafted filenames containing shell metacharacters like backticks, $(), or escaped quotes to execute arbitrary commands.","position":{"begin":{"line":27,"column":1},"end":{"line":27,"column":1}}},{"file":"index.js","explanation":"The constructConvertCommandForPage function passes pdfFilePath and outputImagePath to the convert/gm command via util.format. Additionally, convertOptionsString (line 91) is built from user-controlled convertOptions object keys and values without sanitization, allowing injection of arbitrary shell commands.","position":{"begin":{"line":88,"column":1},"end":{"line":88,"column":1}}},{"file":"index.js","explanation":"The constructCombineCommandForFile function joins imagePaths array with spaces and passes them directly to the shell command. While these paths are generated internally, they derive from user-controlled pdfFileBaseName and outputDirectory options, allowing command injection.","position":{"begin":{"line":96,"column":1},"end":{"line":96,"column":1}}},{"file":"index.js","explanation":"The cleanup code executes 'rm ' + imagePaths.join(' ') directly in a shell. The imagePaths are derived from user-controlled options (pdfFileBaseName, outputDirectory, convertExtension), enabling command injection through crafted option values.","position":{"begin":{"line":125,"column":1},"end":{"line":125,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"Multiple detected issues (1 and 2) precisely match the CVE by describing command injection through attacker-controlled pdfFilePath passed unsanitized into shell commands (pdfinfo and convert/gm), enabling arbitrary command execution via crafted filenames. Other issues describe related but distinct injection points via different options."}
{"cve_id":"CVE-2019-10759","variant":"fixed","cve_explanation":"safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.","cve_explanation_source":"osv","original_explanations":["sandbox escape / arbitrary code execution"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10785","variant":"unfixed","cve_explanation":"dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.","cve_explanation_source":"osv","original_explanations":["Incomplete string escaping or encoding"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3770","variant":"fixed","cve_explanation":"Versions of `markdown-pdf` prior to 9.0.0 are vulnerable to Remote Code Execution. The package fails to sanitize HTML code in markdown files. If markdown files with malicious HTML are converted to PDF, the resulting PDF file will execute any JavaScript code in the original markdown file. This may allow attackers to execute Remote Code.\n\n\n## Recommendation\n\nUpgrade to version 9.0.0 or later.","cve_explanation_source":"osv","original_explanations":["Insecure default value: HTML supported by default"],"detected_issues":[{"file":"index.js","explanation":"The cssPath, highlightCssPath, and runningsPath options accept user-controlled file paths which are resolved with path.resolve() but not validated to be within a safe directory. These paths are passed as arguments to PhantomJS where they are used to load local files. An attacker can provide paths like '/etc/passwd' or use path traversal sequences to read arbitrary files from the filesystem. This is CVE-2018-3770.","position":{"begin":{"line":18,"column":1},"end":{"line":18,"column":1}}},{"file":"index.js","explanation":"User-controlled opts.phantomPath is passed directly to childProcess.execFile() as the executable path. While execFile() is safer than exec(), an attacker who controls opts.phantomPath can execute arbitrary binaries on the system. The path is not validated to point to the actual PhantomJS binary.","position":{"begin":{"line":117,"column":1},"end":{"line":117,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No detected issues match the exact CVE-2018-3770 vulnerability, which involves failure to sanitize HTML in markdown files leading to JS execution RCE in generated PDFs. Detected issues are unrelated: path traversal for file reads and arbitrary exec via phantomPath, with different vectors and (partially) impacts from the CVE. These are distinct vulnerabilities, not the original CVE instance, even in fixed code context."}
{"cve_id":"CVE-2019-10759","variant":"unfixed","cve_explanation":"safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.","cve_explanation_source":"osv","original_explanations":["sandbox escape / arbitrary code execution"],"detected_issues":[{"file":"src/browser.js","explanation":"The browser version of safer-eval is vulnerable to sandbox escape via prototype chain exploitation. The mitigation attempt at line 42 (`this.constructor.constructor = function () {}`) only assigns a no-op function to one reference of the Function constructor, but the sandbox can be escaped via alternative prototype chain access paths such as `(function(){}).constructor.constructor('return this')()` to access the global scope and execute arbitrary code. This is CVE-2019-10759.","position":{"begin":{"line":49,"column":1},"end":{"line":49,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The detected issue precisely describes the CVE-2019-10759 vulnerability in safer-eval: arbitrary code execution via sandbox escape using alternative prototype chain access to the Function constructor, matching the same security impact (arbitrary code execution) and attack pattern (constructor properties bypassing sandbox mitigation)."}
{"cve_id":"CVE-2019-10090","variant":"unfixed","cve_explanation":"On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.","cve_explanation_source":"osv","original_explanations":["Client-side cross-site scripting"],"detected_issues":[{"file":"jspwiki-war/src/main/scripts/moo-extend/Element.Extend.js","explanation":"The mapTextNodes function uses innerHTML to render HTML content returned by arbitrary callback functions. When combined with HighlightQuery.js (line 64), user-supplied template parameter can inject malicious HTML/JavaScript. The stripScripts() sanitization is insufficient as it only removes <script> tags but allows other XSS vectors like event handlers (onerror, onmouseover, etc.) and other executable contexts.","position":{"begin":{"line":530,"column":1},"end":{"line":530,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely captures the CVE-2019-10090 vulnerability: a client-side XSS exploitable via user-controlled input (plugin links providing templates) processed by vulnerable JS functions using innerHTML with inadequate sanitization. Same impact (JS execution for sensitive info theft), same attack pattern (malicious HTML/JS injection), and same instance (specific MooTools extensions and HighlightQuery used in JSPWiki's plain editor context)."}
{"cve_id":"CVE-2018-3737","variant":"fixed","cve_explanation":"sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3770","variant":"unfixed","cve_explanation":"Versions of `markdown-pdf` prior to 9.0.0 are vulnerable to Remote Code Execution. The package fails to sanitize HTML code in markdown files. If markdown files with malicious HTML are converted to PDF, the resulting PDF file will execute any JavaScript code in the original markdown file. This may allow attackers to execute Remote Code.\n\n\n## Recommendation\n\nUpgrade to version 9.0.0 or later.","cve_explanation_source":"osv","original_explanations":["Insecure default value: HTML supported by default"],"detected_issues":[{"file":"index.js","explanation":"The cssPath option is resolved using path.resolve() without any validation or sanitization, then passed to PhantomJS which loads it as a stylesheet. An attacker who can control the opts.cssPath parameter can read arbitrary files from the filesystem by supplying path traversal sequences like '../../etc/passwd' or absolute paths to sensitive files. The file content would be included in the PDF output or cause errors that leak file existence information.","position":{"begin":{"line":19,"column":1},"end":{"line":19,"column":1}}},{"file":"index.js","explanation":"The highlightCssPath option has the same vulnerability as cssPath. It is resolved using path.resolve() without validation and passed to PhantomJS, allowing arbitrary file reads through path traversal.","position":{"begin":{"line":20,"column":1},"end":{"line":20,"column":1}}},{"file":"index.js","explanation":"The runningsPath option is resolved using path.resolve() without validation, then passed to PhantomJS where it is loaded via require() (phantom/render.js line 61). An attacker who controls this option can execute arbitrary JavaScript code by pointing to a malicious JS file on the filesystem.","position":{"begin":{"line":18,"column":1},"end":{"line":18,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"None of the detected issues match the exact CVE vulnerability. The CVE describes RCE due to lack of HTML sanitization in markdown input files, allowing JS in HTML to execute during PDF generation. Detected issues are path traversal vulnerabilities in specific options (cssPath, highlightCssPath for file reads; runningsPath for JS execution), which are different attack vectors (options control vs markdown content) and not the same instance as the CVE's HTML sanitization failure. File reads are info disclosure, not RCE; runningsPath RCE uses different exploitation method."}
{"cve_id":"CVE-2019-12043","variant":"fixed","cve_explanation":"In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \\x0ejavascript: URL.","cve_explanation_source":"osv","original_explanations":["Incomplete sanitization of control characters"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-1010091","variant":"fixed","cve_explanation":"tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.","cve_explanation_source":"osv","original_explanations":["Incomplete multi-character sanitization"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3737","variant":"unfixed","cve_explanation":"sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3746","variant":"fixed","cve_explanation":"Versions of `pdfinfojs` before 0.4.1 are vulnerable to command injection. This is exploitable if an attacker can control the filename parameter that is passed into the `pdfinfojs` constructor.\n\n\n## Recommendation\n\nUpdate to version 0.4.1 or later.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-12043","variant":"unfixed","cve_explanation":"In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \\x0ejavascript: URL.","cve_explanation_source":"osv","original_explanations":["Incomplete sanitization of control characters"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10761","variant":"fixed","cve_explanation":"This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the \"sandboxed\" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.","cve_explanation_source":"osv","original_explanations":["sandbox escape / arbitrary code execution"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3746","variant":"unfixed","cve_explanation":"Versions of `pdfinfojs` before 0.4.1 are vulnerable to command injection. This is exploitable if an attacker can control the filename parameter that is passed into the `pdfinfojs` constructor.\n\n\n## Recommendation\n\nUpdate to version 0.4.1 or later.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"lib/pdfinfo.js","explanation":"Command injection vulnerability via unsanitized filename parameter passed directly to execSync. The filename is wrapped in double quotes (line 6) but this is insufficient protection as an attacker can escape the quotes and inject arbitrary shell commands.","position":{"begin":{"line":26,"column":1},"end":{"line":26,"column":1}}},{"file":"lib/pdfinfo.js","explanation":"Command injection vulnerability via unsanitized filename parameter passed directly to exec. Same vulnerability as line 26 but in the async version. The double-quote wrapping on line 6 does not prevent command injection.","position":{"begin":{"line":36,"column":1},"end":{"line":36,"column":1}}},{"file":"lib/pdfinfo.js","explanation":"The add_options method allows arbitrary options to be added to the command line without sanitization. These options are then joined and passed to exec/execSync, enabling command injection through the options parameter.","position":{"begin":{"line":8,"column":1},"end":{"line":8,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"Multiple issues detected, with the first two precisely matching the CVE's command injection vulnerability via the controllable filename parameter in the pdfinfojs constructor. The third issue describes a related but distinct injection vector via options, which does not match the specific CVE vulnerability instance. Since at least one issue matches exactly (same impact: command injection; same pattern and instance: filename param to shell), overall match is TRUE."}
{"cve_id":"CVE-2019-1010091","variant":"unfixed","cve_explanation":"tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.","cve_explanation_source":"osv","original_explanations":["Incomplete multi-character sanitization"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10746","variant":"fixed","cve_explanation":"mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3783","variant":"fixed","cve_explanation":"A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.","cve_explanation_source":"osv","original_explanations":["Database query built from user-controlled sources"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10761","variant":"unfixed","cve_explanation":"This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the \"sandboxed\" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.","cve_explanation_source":"osv","original_explanations":["sandbox escape / arbitrary code execution"],"detected_issues":[{"file":"lib/contextify.js","explanation":"The Decontextify.object's defineProperty trap uses 'target' instead of 'object' when defining properties. This inconsistency with Contextify.object (line 570 which uses 'object') can allow sandbox code to define properties directly on the proxy target object rather than the intended sandboxed object, potentially enabling sandbox escape by manipulating the proxy target's prototype chain.","position":{"begin":{"line":276,"column":1},"end":{"line":276,"column":1}}},{"file":"lib/contextify.js","explanation":"The fakeDefineGetter, fakeDefineSetter, fakeLookupGetter, and fakeLookupSetter functions (lines 44-68) allow sandboxed code to define getters/setters on the proxy receiver. The 'value' parameter passed to defineProperty in these functions comes directly from sandbox code without validation. An attacker can pass a malicious getter/setter function that, when invoked by host code, could leak host context references.","position":{"begin":{"line":44,"column":1},"end":{"line":44,"column":1}}},{"file":"lib/contextify.js","explanation":"The Decontextify.value function has a catch-all exception handler (lines 376-379) that silently returns null when any exception occurs during value conversion. This includes exceptions from the instanceOf checks that could contain host object references. An attacker can craft objects that throw controlled exceptions during the type checking process, and the silent null return masks what could be exploitable error conditions.","position":{"begin":{"line":376,"column":1},"end":{"line":376,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"None of the detected issues describe the CVE's specific vulnerability of infinite recursion causing a host RangeError exception, which exposes the mainModule property for arbitrary code execution via child_process. All detected issues identify different potential sandbox escape vectors in contextify.js (proxy traps, getters/setters, exception masking), but they do not match the exact recursion-based attack pattern, mechanism, or exploitation steps of the CVE."}
{"cve_id":"CVE-2019-13506","variant":"fixed","cve_explanation":"@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.","cve_explanation_source":"osv","original_explanations":["Improper code sanitization"],"detected_issues":[{"file":"src/index.ts","explanation":"RegExp.toString() output is not sanitized before being included in serialized output. When the devalue output is embedded in HTML script tags (the primary use case per README), a malicious RegExp containing patterns like '</script>' can break out of the script context and execute arbitrary JavaScript. The escaped map includes characters like '<', '>' and '/' but these are not applied to RegExp stringification.","position":{"begin":{"line":104,"column":1},"end":{"line":104,"column":1}}},{"file":"src/index.ts","explanation":"Same XSS vulnerability as line 104 - RegExp.toString() is used without sanitization in the named values section (used for handling repeated/cyclical RegExp references). This is a separate code path that also needs fixing.","position":{"begin":{"line":156,"column":1},"end":{"line":156,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No detected issues match the exact CVE vulnerability (mishandling object keys leading to XSS). Both detections focus on RegExp.toString() unsanitization in serialization output, likely in values or named references sections, not object keys. They acknowledge partial escaping (escaped map) exists but not applied, and note separate code paths, indicating detection of incomplete/partial fix or related but distinct issues in fixed code, not the original CVE instance. Same XSS impact and category (improper sanitization), but not the same vulnerability instance per criteria for fixed variants."}
{"cve_id":"CVE-2018-3750","variant":"fixed","cve_explanation":"The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10746","variant":"unfixed","cve_explanation":"mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"index.js","explanation":"Incomplete prototype pollution protection. While '__proto__' is blocked on line 7, the code remains vulnerable to prototype pollution via 'constructor.prototype' path. An attacker can modify Object.prototype by passing a payload like {constructor: {prototype: {isAdmin: true}}} which bypasses the __proto__ check.","position":{"begin":{"line":6,"column":1},"end":{"line":6,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely matches the CVE-2019-10746 vulnerability, identifying the prototype pollution via constructor.prototype bypass in the unfixed mixin-deep code, with the same attack payload and security impact (modifying Object.prototype)."}
{"cve_id":"CVE-2019-10747","variant":"fixed","cve_explanation":"set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-13506","variant":"unfixed","cve_explanation":"@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.","cve_explanation_source":"osv","original_explanations":["Improper code sanitization"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10776","variant":"fixed","cve_explanation":"In \"index.js\" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3750","variant":"unfixed","cve_explanation":"The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3783","variant":"unfixed","cve_explanation":"A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.","cve_explanation_source":"osv","original_explanations":["Database query built from user-controlled sources"],"detected_issues":[{"file":"server/apps/routes/auth.js","explanation":"The /verify endpoint takes a user-controlled token from the query string (req.query.t) and directly interpolates it into a redirect URL without any validation. An attacker can craft a malicious URL like /verify?t=../../../evil.com which could redirect users to an attacker-controlled domain. This is CVE-2018-3783.","position":{"begin":{"line":112,"column":1},"end":{"line":112,"column":1}}},{"file":"server/apps/routes/auth.js","explanation":"The /setpassword endpoint takes the token directly from req.body and uses it in a MongoDB query without type validation. If an attacker sends a JSON body with token as an object like {\"$ne\": null}, they could potentially match any user with a token set, allowing unauthorized password reset for arbitrary users.","position":{"begin":{"line":58,"column":1},"end":{"line":58,"column":1}}},{"file":"server/apps/routes/auth.js","explanation":"The /forgotpassword endpoint takes email directly from req.body and uses it in a MongoDB query without type validation. An attacker can send an object with MongoDB operators instead of a string to manipulate the query logic.","position":{"begin":{"line":80,"column":1},"end":{"line":80,"column":1}}},{"file":"server/apps/routes/auth.js","explanation":"The /verify endpoint takes token from req.query.t and uses it directly in a MongoDB findOne query. Query parameters can be passed as arrays or objects in Express, enabling NoSQL injection attacks.","position":{"begin":{"line":105,"column":1},"end":{"line":105,"column":1}}},{"file":"server/apps/routes/auth.js","explanation":"The /firstuser endpoint creates a new User directly from req.body without filtering allowed fields. An attacker could inject additional fields like 'usergroup' or 'token' to escalate privileges or manipulate the user object. While usergroup is explicitly set afterward, other fields in the User schema could be manipulated.","position":{"begin":{"line":27,"column":1},"end":{"line":27,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The second detected issue precisely describes the CVE vulnerability: blind MongoDB injection in the password reset (/setpassword) using unvalidated token input, allowing unauthorized password changes and account takeover. Other issues are related NoSQL injections or different vulnerabilities but do not match the exact CVE instance and impact."}
{"cve_id":"CVE-2019-10747","variant":"unfixed","cve_explanation":"set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-10776","variant":"unfixed","cve_explanation":"In \"index.js\" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"src/run.js","explanation":"The run() function executes shell commands using child_process.exec() without any input sanitization. This function is exported and called throughout the codebase with user-controlled input including remoteUrl, startTag, endTag, ignoredFiles, startCommand, and endCommand parameters that come directly from CLI arguments. An attacker can inject arbitrary shell commands via these parameters.","position":{"begin":{"line":10,"column":1},"end":{"line":10,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The security agent's detected issue precisely identifies the command injection vulnerability via the remoteUrl parameter in the run() function, aligning exactly with the CVE description. No other issues detected, but this single match suffices."}
{"cve_id":"CVE-2019-15482","variant":"fixed","cve_explanation":"Versions of `selectize-plugin-a11y ` prior to 1.1.0 are vulnerable to Cross-Site Scripting. The `accessibility.liveRegion.speak` function does not sanitize the `msg` variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.1.0 or later.","cve_explanation_source":"osv","original_explanations":["DOM text reinterpreted as HTML"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-3752","variant":"fixed","cve_explanation":"The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-15482","variant":"unfixed","cve_explanation":"Versions of `selectize-plugin-a11y ` prior to 1.1.0 are vulnerable to Cross-Site Scripting. The `accessibility.liveRegion.speak` function does not sanitize the `msg` variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.1.0 or later.","cve_explanation_source":"osv","original_explanations":["DOM text reinterpreted as HTML"],"detected_issues":[{"file":"selectize-plugin-a11y.js","explanation":"DOM-based XSS vulnerability in the speak() function. The msg parameter is directly concatenated into HTML without any sanitization or encoding. When speak() is called on line 52 with $target.text(), if an attacker can control the text content of dropdown options (e.g., through user-generated content or malicious data injection), they can inject arbitrary HTML/JavaScript that will be executed when the option becomes active.","position":{"begin":{"line":28,"column":1},"end":{"line":28,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely identifies the same DOM-based XSS vulnerability in the speak() function of selectize-plugin-a11y.js as described in the CVE, involving unsanitized user-controlled input (msg) rendered as HTML, leading to arbitrary JavaScript execution. Same security impact (XSS), attack pattern (direct HTML insertion without sanitization), and exact vulnerability instance (speak function).\""}
{"cve_id":"CVE-2019-10777","variant":"fixed","cve_explanation":"In aws-lambda versions prior to version 1.0.5, the \"config.FunctioName\" is used to construct the argument used within the \"exec\" function without any sanitization. It is possible for a user to inject arbitrary commands to the \"zipCmd\" used within \"config.FunctionName\".","cve_explanation_source":"osv","original_explanations":["Uncontrolled command line"],"detected_issues":[{"file":"lib/main.js","explanation":"Command injection vulnerability via package.json 'files' array. The code reads package.json, extracts the 'files' array, joins them with spaces, and passes them directly to a shell command via exec(). A malicious package.json with crafted file entries like '; rm -rf /' or '$(malicious_command)' would result in arbitrary command execution.","position":{"begin":{"line":185,"column":1},"end":{"line":185,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"The single detected issue describes command injection via package.json 'files' array passed to exec(), which shares the same security impact (arbitrary command execution) and pattern (unsanitized input to shell exec) as the CVE. However, the CVE targets the exact instance of 'config.FunctionName' in 'zipCmd', a different code path/input. In fixed code, this detects a similar but unrelated vulnerability, not the original CVE. Thus, no exact match."}
{"cve_id":"CVE-2018-6333","variant":"fixed","cve_explanation":"The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.","cve_explanation_source":"osv","original_explanations":["Server-side URL redirect"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-15532","variant":"fixed","cve_explanation":"CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.","cve_explanation_source":"osv","original_explanations":["Client-side cross-site scripting"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-6333","variant":"unfixed","cve_explanation":"The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.","cve_explanation_source":"osv","original_explanations":["Server-side URL redirect"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2018-7651","variant":"fixed","cve_explanation":"index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.","cve_explanation_source":"osv","original_explanations":["Polynomial regular expression used on uncontrolled data"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-20149","variant":"unfixed","cve_explanation":"ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.","cve_explanation_source":"osv","original_explanations":["improper input validation"],"detected_issues":[{"file":"index.js","explanation":"The ctorName function accesses val.constructor.name without proper validation. An attacker can craft an object with a malicious constructor property that pollutes the prototype chain or causes type confusion. Specifically, an object like {constructor: {name: 'Map'}} will be incorrectly identified as a 'map' type, bypassing type checks that depend on this library. This is CVE-2019-20149.","position":{"begin":{"line":68,"column":1},"end":{"line":68,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely matches the CVE-2019-20149 vulnerability: improper validation of user-controlled input to val.constructor.name in ctorName function, enabling type manipulation via crafted objects like {'constructor': {'name': 'Symbol'}} or similar. Explicit CVE reference and identical security outcome (type detection bypass) confirm exact match for the same vulnerability instance in index.js."}
{"cve_id":"CVE-2020-15156","variant":"fixed","cve_explanation":"In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.","cve_explanation_source":"osv","original_explanations":["Missing CSRF middleware"],"detected_issues":[{"file":"library.js","explanation":"User-controlled URL parameter used directly in redirect without validation. The 'url' parameter from req.body.url is used in res.redirect() without any sanitization or validation against a whitelist of allowed domains.","position":{"begin":{"line":131,"column":1},"end":{"line":131,"column":1}}},{"file":"library.js","explanation":"User-controlled URL parameter used directly in redirect without validation in the success path of replyToComment function.","position":{"begin":{"line":134,"column":1},"end":{"line":134,"column":1}}},{"file":"library.js","explanation":"The Referer header is used directly in res.redirect() without validation. An attacker can manipulate the Referer header to redirect users to arbitrary URLs.","position":{"begin":{"line":193,"column":1},"end":{"line":193,"column":1}}},{"file":"library.js","explanation":"The 'url' variable from the database is directly concatenated into an HTML string without proper escaping, creating a stored XSS vulnerability. The URL is stored via the 'blog-comments:url' field from user-controlled input (req.body.url in publishArticle) and later rendered as HTML.","position":{"begin":{"line":219,"column":1},"end":{"line":219,"column":1}}}],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"None of the detected issues describe the exact CVE vulnerability: missing CSRF validation enabling XSS for third-party posting on behalf of logged-in users. Detected issues are open redirects (unrelated impact) and a stored XSS on URL rendering (different pattern and cause, not linked to CSRF or the specific posting exploit). In fixed code, original CSRF vuln is resolved; these are separate issues, not the CVE instance or improper fix critiques."}
{"cve_id":"CVE-2019-15532","variant":"unfixed","cve_explanation":"CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.","cve_explanation_source":"osv","original_explanations":["Client-side cross-site scripting"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-15156","variant":"unfixed","cve_explanation":"In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.","cve_explanation_source":"osv","original_explanations":["Missing CSRF middleware"],"detected_issues":[{"file":"library.js","explanation":"User-controlled URL parameter from req.body.url is used directly in res.redirect() without validation. An attacker can craft a malicious URL that redirects users to phishing sites or other malicious destinations.","position":{"begin":{"line":131,"column":1},"end":{"line":131,"column":1}}},{"file":"library.js","explanation":"User-controlled URL parameter from req.body.url is used directly in res.redirect() on success path without validation.","position":{"begin":{"line":134,"column":1},"end":{"line":134,"column":1}}},{"file":"library.js","explanation":"The URL from the database is inserted into HTML content without proper escaping. While the URL is originally user-provided (from req.body.url in publishArticle), it is stored in the database and later rendered as HTML in an anchor tag href attribute. If the URL contains malicious content like 'javascript:' scheme or quotes to break out of the attribute, it could lead to XSS.","position":{"begin":{"line":219,"column":1},"end":{"line":219,"column":1}}},{"file":"library.js","explanation":"The POST endpoint /comments/reply lacks CSRF protection. While the GET endpoint /comments/get uses middleware.applyCSRF, the POST route for replying to comments has no CSRF middleware applied, making it vulnerable to cross-site request forgery attacks.","position":{"begin":{"line":251,"column":1},"end":{"line":251,"column":1}}},{"file":"library.js","explanation":"The POST endpoint /comments/publish lacks CSRF protection. This endpoint allows publishing articles and has no CSRF middleware applied, making it vulnerable to cross-site request forgery attacks.","position":{"begin":{"line":252,"column":1},"end":{"line":252,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"Detected issues include open redirects and stored XSS, which do not match. However, two issues precisely identify missing CSRF protection on POST endpoints (/comments/reply and /comments/publish), directly corresponding to the CVE's described vulnerability of lack of CSRF validation allowing third-party posting on behalf of logged-in users. Same impact (forged posting), attack pattern (CSRF absence), and instance (missing middleware)."}
{"cve_id":"CVE-2019-20174","variant":"fixed","cve_explanation":"Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.","cve_explanation_source":"osv","original_explanations":["Client-side cross-site scripting"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-7763","variant":"fixed","cve_explanation":"This affects the package phantom-html-to-pdf before 0.6.1.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[{"file":"lib/conversion.js","explanation":"The tmpId parameter from user input is used directly in file path construction without sanitization. An attacker can supply a tmpId containing path traversal sequences like '../' to write HTML files to arbitrary locations on the filesystem. This is used on lines 12 and 64 where the id is concatenated into file paths.","position":{"begin":{"line":56,"column":1},"end":{"line":56,"column":1}}}],"TP":0,"FP":1,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely matches the CVE-2020-7763 vulnerability description of uncontrolled data (tmpId) in path expressions leading to path traversal and arbitrary file access/write. Same input source, exploitation method, impact, file, and line numbers confirm it is the exact same vulnerability instance, even in the fixed variant."}
{"cve_id":"CVE-2020-6836","variant":"fixed","cve_explanation":"grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow attackers to run arbitrary commands on the server.","cve_explanation_source":"osv","original_explanations":["Code injection"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-7763","variant":"unfixed","cve_explanation":"This affects the package phantom-html-to-pdf before 0.6.1.","cve_explanation_source":"osv","original_explanations":["Uncontrolled data used in path expression"],"detected_issues":[{"file":"lib/conversion.js","explanation":"User-controlled tmpId parameter is used directly in file path construction without validation, allowing path traversal attacks. The id variable is concatenated into file paths at lines 12 and 64 using path.join(options.tmpDir, id + ...). An attacker can supply a malicious tmpId like '../../../etc/cron.d/malicious' to write files outside the intended tmp directory.","position":{"begin":{"line":56,"column":1},"end":{"line":56,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely identifies the CVE-2020-7763 vulnerability: uncontrolled tmpId used in path expressions leading to path traversal for arbitrary file writes, with matching impact, pattern, and specific code details (lib/conversion.js lines 12/64)."}
{"cve_id":"CVE-2019-20174","variant":"unfixed","cve_explanation":"Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.","cve_explanation_source":"osv","original_explanations":["Client-side cross-site scripting"],"detected_issues":[{"file":"src/ui/input/checkbox_input.jsx","explanation":"The CheckboxInput component uses dangerouslySetInnerHTML to render the placeholder prop directly as HTML without any sanitization. This placeholder value originates from the additionalSignUpFields configuration option provided by application developers, which accepts arbitrary HTML. If an attacker can influence this configuration (e.g., via stored XSS in an admin panel, or if the configuration is fetched from an untrusted source), they can inject malicious JavaScript that executes in users' browsers during the authentication flow. This is CVE-2019-20174.","position":{"begin":{"line":18,"column":1},"end":{"line":18,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue exactly matches the CVE vulnerability in description, attack vector (additionalSignUpFields placeholder), location (CheckboxInput), and impact (XSS). It is the precise vulnerability instance documented in CVE-2019-20174."}
{"cve_id":"CVE-2019-15657","variant":"fixed","cve_explanation":"In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.","cve_explanation_source":"osv","original_explanations":["Arbitrary Code Execution"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-26226","variant":"fixed","cve_explanation":"In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.","cve_explanation_source":"osv","original_explanations":["Incomplete sanitization of of sensitive values in the presence of url-encoding."],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-6836","variant":"unfixed","cve_explanation":"grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow attackers to run arbitrary commands on the server.","cve_explanation_source":"osv","original_explanations":["Code injection"],"detected_issues":[{"file":"src/grammar-parser/grammar-parser.js","explanation":"Critical Remote Code Execution (RCE) vulnerability via eval() injection. The parser uses eval() to parse array literals from user input on line 226. The variable 'yytext' contains the raw matched text from user-supplied formula expressions, which is directly concatenated into an eval() call without any sanitization. An attacker can inject arbitrary JavaScript code through specially crafted formula inputs containing array syntax.","position":{"begin":{"line":226,"column":1},"end":{"line":226,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue matches the CVE exactly: both describe RCE through eval injection using unsanitized user-supplied formula inputs in the grammar-parser component of hot-formula-parser. Same security impact (arbitrary code execution), attack pattern (eval with raw user data), and vulnerability instance (parser's handling of formulas)."}
{"cve_id":"CVE-2020-8116","variant":"fixed","cve_explanation":"Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-8116","variant":"unfixed","cve_explanation":"Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"index.js","explanation":"The set() function allows modification of object properties via user-controlled paths without checking for dangerous property names like '__proto__', 'constructor', or 'prototype'. An attacker can pollute the Object prototype by calling set({}, '__proto__.polluted', 'yes'), which adds the 'polluted' property to all JavaScript objects in the application.","position":{"begin":{"line":63,"column":1},"end":{"line":63,"column":1}}},{"file":"index.js","explanation":"The delete() function allows deletion of properties via user-controlled paths without checking for dangerous property names. An attacker could potentially delete critical properties from Object.prototype or constructor functions by passing paths like '__proto__.toString'.","position":{"begin":{"line":89,"column":1},"end":{"line":89,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The first issue directly identifies the prototype pollution vulnerability in the set() function, matching the CVE's description of adding arbitrary properties to JavaScript objects/prototypes. The second issue is a related but distinct deletion vulnerability, not covered by this CVE."}
{"cve_id":"CVE-2019-15657","variant":"unfixed","cve_explanation":"In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.","cve_explanation_source":"osv","original_explanations":["Arbitrary Code Execution"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-26226","variant":"unfixed","cve_explanation":"In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.","cve_explanation_source":"osv","original_explanations":["Incomplete sanitization of of sensitive values in the presence of url-encoding."],"detected_issues":[{"file":"lib/hide-sensitive.js","explanation":"The hide-sensitive function calls .trim() on environment variable values without first verifying they are strings. If an environment variable value is not a string (e.g., undefined, null, number, or object), this will throw a TypeError, causing the secret-hiding function to fail. When this function crashes, any subsequent error handling or logging that relies on this function for sanitization will receive unsanitized output, potentially leaking sensitive credentials in logs or error messages.","position":{"begin":{"line":11,"column":1},"end":{"line":11,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"The single detected issue does not match the CVE. The CVE vulnerability is about secrets with URL-encodable characters not being properly masked in URL contexts due to incomplete sanitization handling of those characters. The detected issue is a separate problem: lack of type checking before trim(), causing a crash and failure to mask any secrets under non-string conditions. Both can lead to secret disclosure but via different mechanisms and conditions, so it is not the exact same CVE vulnerability."}
{"cve_id":"CVE-2019-5483","variant":"fixed","cve_explanation":"Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.","cve_explanation_source":"osv","original_explanations":["Clear-text logging of sensitive information"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-7656","variant":"fixed","cve_explanation":"jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove \"<script>\" HTML tags that contain a whitespace character, i.e: \"</script >\", which results in the enclosed script logic to be executed.","cve_explanation_source":"osv","original_explanations":["Incomplete multi-character sanitization"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-16769","variant":"fixed","cve_explanation":"The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.","cve_explanation_source":"osv","original_explanations":["cross-site scripting due to unsafe characters in serialized regular expressions"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-26256","variant":"fixed","cve_explanation":"Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a possible ReDoS vulnerability (Regular Expression Denial of Service) when using ignoreEmpty option when parsing. This has been patched in `v4.3.6` You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6` This vulnerability was found using a CodeQL query which identified `EMPTY_ROW_REGEXP` regular expression as vulnerable.","cve_explanation_source":"osv","original_explanations":["Inefficient regular expression for strings containing many repetitions of ' ,'."],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-7656","variant":"unfixed","cve_explanation":"jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove \"<script>\" HTML tags that contain a whitespace character, i.e: \"</script >\", which results in the enclosed script logic to be executed.","cve_explanation_source":"osv","original_explanations":["Incomplete multi-character sanitization"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-5483","variant":"unfixed","cve_explanation":"Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.","cve_explanation_source":"osv","original_explanations":["Clear-text logging of sensitive information"],"detected_issues":[{"file":"lib/print.js","explanation":"The minimist library is used to parse command-line arguments without any sanitization or protection against prototype pollution. Malicious command-line arguments such as '--__proto__.polluted=true' or '--constructor.prototype.polluted=true' can inject properties into the Object prototype, affecting all objects in the application. This is the documented CVE-2019-5483 vulnerability in seneca.","position":{"begin":{"line":14,"column":1},"end":{"line":14,"column":1}}}],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"The single detected issue claims to be CVE-2019-5483 but describes prototype pollution, not the CVE's clear-text logging leading to unauthorized exposure of environment variables. Prototype pollution enables prototype manipulation potentially leading to other impacts, but does not match the specific CVE description of env var exposure via logging. No matching issue found."}
{"cve_id":"CVE-2020-8192","variant":"fixed","cve_explanation":"A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.","cve_explanation_source":"osv","original_explanations":["Resource exhaustion"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-16769","variant":"unfixed","cve_explanation":"The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.","cve_explanation_source":"osv","original_explanations":["cross-site scripting due to unsafe characters in serialized regular expressions"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-26256","variant":"unfixed","cve_explanation":"Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a possible ReDoS vulnerability (Regular Expression Denial of Service) when using ignoreEmpty option when parsing. This has been patched in `v4.3.6` You will only be affected by this if you use the `ignoreEmpty` parsing option. If you do use this option it is recommended that you upgrade to the latest version `v4.3.6` This vulnerability was found using a CodeQL query which identified `EMPTY_ROW_REGEXP` regular expression as vulnerable.","cve_explanation_source":"osv","original_explanations":["Inefficient regular expression for strings containing many repetitions of ' ,'."],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-7660","variant":"fixed","cve_explanation":"serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function \"deleteFunctions\" within \"index.js\".","cve_explanation_source":"osv","original_explanations":["Remote code execution"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-4066","variant":"fixed","cve_explanation":"### Impact\nThe `trainBatch` function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.\n\n### Patches\nPatched in version 0.9.5.\n\n### Workarounds\nDo not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost\n\n### References\nNo","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"classifiers/svm/SvmLinear.js","explanation":"The train_command option allows specifying an arbitrary executable that is passed directly to child_process.execFileSync(). If an attacker can control the opts.train_command value passed to the SvmLinear constructor, they can execute arbitrary binaries on the system. The command is executed at line 97 with user-controllable arguments from learn_args. While execFileSync prevents shell injection through arguments, the command itself can be any executable path.","position":{"begin":{"line":97,"column":1},"end":{"line":97,"column":1}}},{"file":"classifiers/svm/SvmLinear.js","explanation":"The test_command option allows specifying an arbitrary executable that is passed directly to child_process.execFileSync() in the classifyBatch method. Similar to train_command, if an attacker can control opts.test_command, they can execute arbitrary binaries on the system.","position":{"begin":{"line":143,"column":1},"end":{"line":143,"column":1}}}],"TP":0,"FP":1,"TN":0,"FN":0,"judge_reasoning":"The first detected issue precisely matches the CVE-2020-4066 vulnerability: command injection/arbitrary execution in the SVM Linear classifier's train_command, used during trainBatch as referenced in the CVE. Same security impact (RCE), attack pattern (user-controlled command/executable), and exact instance (SVM Linear training path). The second issue is a related but distinct vulnerability in test/classifyBatch, not covered by the CVE. Even in fixed code, this detection identifies the specific CVE issue, not a new/improper fix concern."}
{"cve_id":"CVE-2020-7660","variant":"unfixed","cve_explanation":"serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function \"deleteFunctions\" within \"index.js\".","cve_explanation_source":"osv","original_explanations":["Remote code execution"],"detected_issues":[{"file":"index.js","explanation":"The RegExp serialization at line 196 does not properly escape the RegExp flags property before inserting it into the serialized output string. An attacker can craft a RegExp object with malicious content in the flags property that breaks out of the string context and injects arbitrary JavaScript code. When this serialized output is later evaluated (via eval() or script insertion as documented in the README), the injected code will execute. This is CVE-2020-7660.","position":{"begin":{"line":196,"column":1},"end":{"line":196,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely matches the CVE-2020-7660 vulnerability: same file (index.js), same security impact (arbitrary code injection/RCE), same attack pattern (malicious input leading to code injection during serialization), and explicitly labeled as the CVE. It describes the exact vulnerability instance."}
{"cve_id":"CVE-2020-8192","variant":"unfixed","cve_explanation":"A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.","cve_explanation_source":"osv","original_explanations":["Resource exhaustion"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-5484","variant":"fixed","cve_explanation":"Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-4066","variant":"unfixed","cve_explanation":"### Impact\nThe `trainBatch` function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.\n\n### Patches\nPatched in version 0.9.5.\n\n### Workarounds\nDo not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost\n\n### References\nNo","cve_explanation_source":"osv","original_explanations":["Unsafe shell command constructed from library input"],"detected_issues":[{"file":"classifiers/svm/SvmLinear.js","explanation":"Command injection vulnerability in trainBatch function. User-controlled values from opts.train_command, opts.learn_args, and opts.model_file_prefix are concatenated into a shell command without sanitization and executed via child_process.execSync(). An attacker who can control the SvmLinear constructor options can inject arbitrary shell commands.","position":{"begin":{"line":100,"column":1},"end":{"line":100,"column":1}}},{"file":"classifiers/svm/SvmLinear.js","explanation":"Command injection vulnerability in classifyBatch function. User-controlled opts.test_command and this.modelFileString are concatenated into a shell command without sanitization and executed via child_process.execSync(). The modelFileString derives from user-controlled model_file_prefix.","position":{"begin":{"line":146,"column":1},"end":{"line":146,"column":1}}},{"file":"classifiers/svm/SvmLinear.js","explanation":"The train_command and test_command options accept arbitrary strings that are later used directly in shell command execution without validation. These options are set from user-provided configuration in the constructor and used in trainBatch (line 100) and classifyBatch (line 146).","position":{"begin":{"line":35,"column":1},"end":{"line":35,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The first and third detected issues precisely describe the CVE-2020-4066 vulnerability: command injection in the trainBatch function of SvmLinear.js via unsanitized user-controlled options (e.g., train_command, learn_args, model_file_prefix) concatenated into shell commands executed with child_process.execSync. This matches the CVE's focus on trainBatch in shell-executing classifiers like SVM Linear. The classifyBatch issues are related but distinct instances not covered by this CVE. Since at least one issue matches exactly (same impact: arbitrary command execution; same pattern and instance: trainBatch in SvmLinear), detection is accurate."}
{"cve_id":"CVE-2020-7662","variant":"fixed","cve_explanation":"websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.","cve_explanation_source":"osv","original_explanations":["Inefficient regular expression"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-8244","variant":"fixed","cve_explanation":"A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.","cve_explanation_source":"osv","original_explanations":["Buffer over-read vulnerability resulting in exposure of uninitialized memory"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-7662","variant":"unfixed","cve_explanation":"websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.","cve_explanation_source":"osv","original_explanations":["Inefficient regular expression"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-5258","variant":"fixed","cve_explanation":"In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-5484","variant":"unfixed","cve_explanation":"Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is extracted.","cve_explanation_source":"osv","original_explanations":["Arbitrary file write during zip extraction (\"Zip Slip\")"],"detected_issues":[{"file":"lib/util/extract.js","explanation":"The extractTar function uses tar-fs to extract tar archives without validating that extracted file paths stay within the destination directory. A malicious tar archive can contain entries with path traversal sequences (e.g., '../../../etc/passwd') that would write files outside the intended extraction directory. This is known as CVE-2019-5484 / Zip Slip vulnerability. The tar-fs library version ^1.4.1 used here does not prevent path traversal by default.","position":{"begin":{"line":65,"column":1},"end":{"line":65,"column":1}}},{"file":"lib/util/extract.js","explanation":"The extractTarGz function uses tar-fs to extract gzipped tar archives without validating that extracted file paths stay within the destination directory. This suffers from the same CVE-2019-5484 vulnerability as extractTar. A malicious .tar.gz or .tgz archive can contain entries with path traversal sequences that escape the extraction directory.","position":{"begin":{"line":95,"column":1},"end":{"line":95,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"Both detected issues explicitly identify and describe the path traversal vulnerability (Zip Slip) in Bower's archive extraction utilities during package installation, directly matching CVE-2019-5484's description of arbitrary file writes via malicious packages. The issues target the exact functions and outcomes documented in the CVE, confirming accurate detection of the specific vulnerability."}
{"cve_id":"CVE-2020-8244","variant":"unfixed","cve_explanation":"A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.","cve_explanation_source":"osv","original_explanations":["Buffer over-read vulnerability resulting in exposure of uninitialized memory"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-8331","variant":"fixed","cve_explanation":"In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.","cve_explanation_source":"osv","original_explanations":["DOM text reinterpreted as HTML"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-5258","variant":"unfixed","cve_explanation":"In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"request/util.js","explanation":"The deepCopy function iterates over all properties in the source object using 'for (var name in source)' and copies them to the target object without checking if the property name is '__proto__', 'constructor', or 'prototype'. An attacker who controls the source object can pollute Object.prototype by including a '__proto__' property, which would be copied to the target and could modify the prototype chain of all JavaScript objects in the application.","position":{"begin":{"line":44,"column":1},"end":{"line":44,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely identifies the prototype pollution vulnerability in the dojo deepCopy function (in request/util.js), including the exact mechanism (for...in loop without prototype property checks) and impact (polluting Object.prototype via controlled '__proto__' input), directly matching CVE-2020-5258."}
{"cve_id":"CVE-2020-7699","variant":"fixed","cve_explanation":"This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2021-31712","variant":"fixed","cve_explanation":"react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS.","cve_explanation_source":"osv","original_explanations":["react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS."],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-7699","variant":"unfixed","cve_explanation":"This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.","cve_explanation_source":"osv","original_explanations":["Prototype-polluting function"],"detected_issues":[{"file":"lib/processNested.js","explanation":"The processNested function is vulnerable to prototype pollution. When parsing nested keys from user-controlled input (form field names), the function dynamically assigns values to object properties without checking if the key is '__proto__', 'constructor', or 'prototype'. An attacker can send a form field with a name like '__proto__.polluted' or 'constructor.prototype.polluted' which will pollute the Object prototype, affecting all objects in the application. Since this processes req.body and req.files from multipart form data (line 132-133 in processMultipart.js), an attacker can exploit this via crafted HTTP requests.","position":{"begin":{"line":19,"column":1},"end":{"line":19,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue exactly matches the CVE vulnerability: prototype pollution in the processNested function via user-controlled nested form field names in multipart requests, enabling DoS or RCE when parseNested is enabled. Same impact, attack pattern, and specific instance in express-fileupload before 1.1.8."}
{"cve_id":"CVE-2021-31712","variant":"unfixed","cve_explanation":"react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS.","cve_explanation_source":"osv","original_explanations":["react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS."],"detected_issues":[{"file":"src/decorators/Link/index.js","explanation":"The URL from entity data is directly rendered in an anchor tag's href attribute without sanitization. An attacker can inject a 'javascript:' URL scheme which will execute arbitrary JavaScript when a user clicks the link. The url value comes from contentState.getEntity(entityKey).getData() which can contain user-controlled content from the editor state.","position":{"begin":{"line":59,"column":1},"end":{"line":59,"column":1}}},{"file":"src/decorators/Link/index.js","explanation":"The URL from entity data is passed directly to window.open() without validation. This allows execution of javascript: URLs when the user clicks the open link icon. The url comes from contentState.getEntity(entityKey).getData() which can be controlled through editor content.","position":{"begin":{"line":35,"column":1},"end":{"line":35,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"Both detected issues describe vulnerabilities in the exact file (decorators/Link/index.js) involving unsanitized user-controlled URLs (from entity data in shared drafts/editor content) enabling javascript: URI execution leading to XSS, directly matching the CVE's description of the Link Target flaw. The first issue precisely captures the anchor href vector, and the second the window.open vector, both part of the same vulnerability instance."}
{"cve_id":"CVE-2019-18350","variant":"fixed","cve_explanation":"In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.","cve_explanation_source":"osv","original_explanations":["Client-side URL redirect"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-18350","variant":"unfixed","cve_explanation":"In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.","cve_explanation_source":"osv","original_explanations":["Client-side URL redirect"],"detected_issues":[{"file":"src/models/login.ts","explanation":"Open Redirect vulnerability in login redirect logic. When the redirect URL's origin differs from the current page's origin, the code directly redirects to the attacker-controlled URL via window.location.href = redirect. An attacker can craft a malicious login link with a redirect parameter pointing to a phishing site (e.g., ?redirect=https://evil.com), and after successful login, the user will be redirected to the attacker's site.","position":{"begin":{"line":56,"column":1},"end":{"line":56,"column":1}}}],"TP":1,"FP":0,"TN":0,"FN":0,"judge_reasoning":"The single detected issue precisely matches the CVE-2019-18350 vulnerability: reflected XSS via unvalidated 'redirect' parameter in user/login (login.ts), leading to arbitrary JS execution post-login. Terminology differs (Open Redirect vs. XSS), but core vuln (direct redirect to controlled URL post-auth) is identical, enabling same exploitation including JS via javascript: URLs. No other issues; exact instance confirmed."}
{"cve_id":"CVE-2019-19507","variant":"fixed","cve_explanation":"In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.","cve_explanation_source":"osv","original_explanations":["User-controlled bypass of security check"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-19507","variant":"unfixed","cve_explanation":"In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.","cve_explanation_source":"osv","original_explanations":["User-controlled bypass of security check"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2019-20149","variant":"fixed","cve_explanation":"ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.","cve_explanation_source":"osv","original_explanations":["improper input validation"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-11021","variant":"fixed","cve_explanation":"Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if consumers of the http-client: 1. make an http request with an authorization header 2. that request leads to a redirect (302) and 3. the redirect url redirects to another domain or hostname Then the authorization header will get passed to the other domain. The problem is fixed in version 1.0.8.","cve_explanation_source":"osv","original_explanations":["Authorization headers are sent to untrusted host"],"detected_issues":[],"TP":0,"FP":0,"TN":1,"FN":0,"judge_reasoning":"No issues were detected by the security agent."}
{"cve_id":"CVE-2020-11021","variant":"unfixed","cve_explanation":"Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if consumers of the http-client: 1. make an http request with an authorization header 2. that request leads to a redirect (302) and 3. the redirect url redirects to another domain or hostname Then the authorization header will get passed to the other domain. The problem is fixed in version 1.0.8.","cve_explanation_source":"osv","original_explanations":["Authorization headers are sent to untrusted host"],"detected_issues":[],"TP":0,"FP":0,"TN":0,"FN":1,"judge_reasoning":"No issues were detected by the security agent."}