Skip to content

fix: security vulnerabilities (Trust scan 994c86b8) - #441

Open
Jaden-JJH wants to merge 15 commits into
OWASP:masterfrom
Jaden-JJH:trust-security/fix-994c86b8
Open

fix: security vulnerabilities (Trust scan 994c86b8)#441
Jaden-JJH wants to merge 15 commits into
OWASP:masterfrom
Jaden-JJH:trust-security/fix-994c86b8

Conversation

@Jaden-JJH

Copy link
Copy Markdown

Security Fixes by Trust Security

Scan ID: 994c86b8-99d2-4490-89c4-4ba69092c469
Score: 1/100 (Grade F)

Fixed Vulnerabilities (30)

  • [CRITICAL] Arbitrary Code Execution in underscore (package.json)
  • [HIGH] Arbitrary Code Execution in grunt (package.json)
  • [HIGH] body-parser vulnerable to denial of service when url encoding is enabled (package.json)
  • [HIGH] Inefficient Regular Expression Complexity in marked (package.json)
  • [HIGH] Inefficient Regular Expression Complexity in marked (package.json)
  • [HIGH] Regular Expression Denial of Service in marked (package.json)
  • [HIGH] Arbitrary local file read vulnerability during template rendering (package.json)
  • [HIGH] Denial of Service in mongodb (package.json)
  • [HIGH] Race Condition in Grunt (package.json)
  • [HIGH] Code String Concat (CWE-95) (app/routes/contributions.js)
  • [HIGH] Detected a Generic API Key, potentially exposing access to various services and sensitive operations. (config/env/development.js)
  • [LOW] express vulnerable to XSS via response.redirect() (package.json)
  • [LOW] Express Check Csurf Middleware Usage (CWE-352) (server.js)
  • [MEDIUM] Sanitization bypass using HTML Entities in marked (package.json)
  • [MEDIUM] Writable Filesystem Service (CWE-732) (docker-compose.yml)
  • [MEDIUM] Django No Csrf Token (CWE-352) (app/views/benefits.html)
  • [MEDIUM] Express Cookie Session No Path (CWE-522) (server.js)
  • [MEDIUM] Marked allows Regular Expression Denial of Service (ReDoS) attacks (package.json)
  • [MEDIUM] Express Cookie Session No Domain (CWE-522) (server.js)
  • [MEDIUM] Express.js Open Redirect in malformed URLs (package.json)
  • [MEDIUM] Express Open Redirect (CWE-601) (app/routes/index.js)
  • [MEDIUM] No New Privileges (CWE-732) (docker-compose.yml)
  • [MEDIUM] Express Cookie Session No Expires (CWE-522) (server.js)
  • [MEDIUM] Path Traversal in Grunt (package.json)
  • [MEDIUM] Express Cookie Session Default Name (CWE-522) (server.js)
  • [MEDIUM] Marked vulnerable to XSS from data URIs (package.json)
  • [MEDIUM] Express Cookie Session No Secure (CWE-522) (server.js)
  • [MEDIUM] Express Cookie Session No Httponly (CWE-522) (server.js)
  • [MEDIUM] Using Http Server (CWE-319) (server.js)
  • [MEDIUM] Eval Detected (CWE-95) (app/routes/contributions.js)

Generated by Trust Security

Jaden-JJH added 15 commits March 4, 2026 18:14
…ession Complexity in marked, Race Condition in Grunt, body-parser vulnerable to denial of service when url encodin, Arbitrary local file read vulnerability during template rend, Denial of Service in mongodb, Express.js Open Redirect in malformed URLs
…ession Default Name (CWE-522), Express Cookie Session No Expires (CWE-522), Express Cookie Session No Secure (CWE-522), Express Cookie Session No Domain (CWE-522), Using Http Server (CWE-319), Express Cookie Session No Httponly (CWE-522), Express Cookie Session No Path (CWE-522)
…ession No Path (CWE-522), Express Cookie Session No Domain (CWE-522), Express Cookie Session No Expires (CWE-522), Express Cookie Session Default Name (CWE-522), Express Cookie Session No Secure (CWE-522), Express Cookie Session No Httponly (CWE-522), Using Http Server (CWE-319)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant