Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 19 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 19 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
19 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
138 of 15580 files scanned (<1%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Read 138 of 274 selected files — this repository's archive was too large to finish in one scan.
Two scanners read 138 of 15580 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 19 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
5.1.6 — GHSA-23c5-xmqv-rm74, GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions — HIGH
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern — HIGH
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments — HIGH
2.0.1 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — HIGH
4.0.0 — GHSA-fjxv-7rqg-78g4, GHSA-hmw2-7cc7-3qxx
form-data uses unsafe random function in form-data for choosing boundary — CRITICAL
form-data: CRLF injection in form-data via unescaped multipart field names and filenames — HIGH
4.7.8 — GHSA-2w6w-674q-4c4q, GHSA-3mfm-83xf-c92r
Handlebars.js has JavaScript Injection via AST Type Confusion — CRITICAL
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block — HIGH
3.14.1 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj
js-yaml: YAML merge-key chains can force quadratic CPU consumption — HIGH
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — HIGH
3.3.7 — GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8
nanoid: non-secure generators can loop indefinitely with negative size — HIGH
nanoid: custom generators can loop indefinitely when size is zero — HIGH
8.17.0 — GHSA-3h5v-q93c-6h6q, GHSA-96hv-2xvq-fx4p
ws affected by a DoS when handling a request with many HTTP headers — HIGH
ws: Memory exhaustion DoS from tiny fragments and data chunks — HIGH
3.14.1 — GHSA-h67p-54hq-rp68
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases — MODERATE
4.1.1 — GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68
js-yaml: YAML merge-key chains can force quadratic CPU consumption — devDependency
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — devDependency
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases — devDependency
3.1.4 — GHSA-39q2-94rc-95cp, GHSA-55q2-fjhq-7xh7, GHSA-76mc-f452-cxcm
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation — MODERATE
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS — MODERATE
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` — MODERATE
10.2.0 — GHSA-22jq-vg5j-6vgg, GHSA-4xrf-jv44-h6hh, GHSA-mwp4-54f8-5fhr
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — devDependency
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — devDependency
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — devDependency
8.17.0 — GHSA-58qx-3vcg-4xpx
ws: Uninitialized memory disclosure — MODERATE
8.20.0 — GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p
ws: Uninitialized memory disclosure — devDependency
ws: Memory exhaustion DoS from tiny fragments and data chunks — devDependency
0.36.0 — GO-2026-6179, GO-2026-6180
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog — UNKNOWN
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb — UNKNOWN
8.4.38 — GHSA-fxqj-rqcc-2cmp, GHSA-qx2v-qp2m-jg93
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — MODERATE
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output — MODERATE
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 138 of 15580 files (highest-priority subset) · mattermost/mattermost
Dependency manifests: 4 package roots found, 4 scanned; 4 Go manifests read — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)