github.com/arduino/arduino-create-agent
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/arduino/arduino-create-agentpage 1 of 1
- CVE-2023-43800HIGHCVSS 7.3EG 7.3✓ Fixed in 1.3.32023-10-18
Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass t…
- CVE-2023-43801MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.3.32023-10-18
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP…
- CVE-2023-43802HIGHCVSS 7.1EG 7.1✓ Fixed in 1.3.32023-10-18
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user who has the ability to perform HTTP requests to the localho…
- CVE-2023-43803MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.3.32023-10-18
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP…
Check whether github.com/arduino/arduino-create-agent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/arduino/arduino-create-agent CVEs against the assets you own.
Start Free Scan →