snyk
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting snykpage 1 of 1
- CVE-2022-22984MEDIUMCVSS 5.0EG 5.0✓ Fixed in 1.1064.02022-11-30
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-py…
- CVE-2022-24441MEDIUMCVSS 5.8EG 5.8✓ Fixed in 1.1064.02022-11-30
The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, wh…
- CVE-2022-40764HIGHCVSS 7.8EG 7.8✓ Fixed in 1.996.02022-10-03
Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. T…
- CVE-2025-6624HIGHCVSS 7.2EG 7.2✓ Fixed in 1.1297.32025-06-26
Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments …
Check whether snyk is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for snyk CVEs against the assets you own.
Start Free Scan →