Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 13 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 13 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
13 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
466 of 7695 files scanned (6%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Read 466 of 500 selected files — this repository's archive was too large to finish in one scan.
Two scanners read 466 of 7695 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 0 committed credentials on production paths and 13 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
15.5.15 — GHSA-267c-6grr-h53f, GHSA-26hh-7cqf-hhc6, GHSA-36qx-fr4f-26g5
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes — HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up — HIGH
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n — HIGH
16.2.3 — GHSA-267c-6grr-h53f, GHSA-26hh-7cqf-hhc6, GHSA-36qx-fr4f-26g5
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes — HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up — HIGH
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n — HIGH
1.15.0 — GHSA-35jp-ww65-95wh, GHSA-3g43-6gmg-66jw
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` — HIGH
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge — HIGH
4.24.13 — GHSA-7rqj-j65f-68wh, GHSA-xmf8-cvqr-rfgj
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass — CRITICAL
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers — HIGH
.env.example:67
:67 — CRON_API_KE…8d0' — non-production path
agents/skills/calcom-api/references/authentication.md:182
:182 — export CAL_API_KE…..." — non-production path
apps/api/v2/.env.example:14, :18
:14 — NEXTAUTH_SECRET…f0=" — non-production path
:18 — JWT_SECRET…JDU" — non-production path
apps/api/v2/src/modules/auth/oauth2/controllers/oauth2.controller.e2e-spec.ts:89, :302, :395, :412, :468
:89 — const testClient…123"; — non-production path
:302 — client…ret", — non-production path
:395 — refresh_token:…ken", — non-production path
:412 — client…ret", — non-production path
:468 — const testClient…456"; — non-production path
2.5.5 — GHSA-3qcw-2rhx-2726, GHSA-hcf7-66rw-9f5r
Turbo: Unexpected local code execution during Yarn Berry detection — devDependency
Turbo: Login callback CSRF/session fixation — devDependency
2.7.1 — GHSA-3qcw-2rhx-2726, GHSA-hcf7-66rw-9f5r
Turbo: Unexpected local code execution during Yarn Berry detection — devDependency
Turbo: Login callback CSRF/session fixation — devDependency
3.3.2 — GHSA-39q2-94rc-95cp, GHSA-55q2-fjhq-7xh7, GHSA-76mc-f452-cxcm
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation — MODERATE
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS — MODERATE
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR` — MODERATE
15.1.0 — GHSA-36qx-fr4f-26g5, GHSA-3g8h-86w9-wvmq, GHSA-3h52-269p-cp9r
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n — devDependency
Next.js's Middleware / Proxy redirects can be cache-poisoned — devDependency
Information exposure in Next.js dev server due to lack of origin verification — devDependency
8.5.6 — GHSA-6g55-p6wh-862q, GHSA-fxqj-rqcc-2cmp, GHSA-qx2v-qp2m-jg93
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments — devDependency
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset — devDependency
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output — devDependency
7.0.12 — GHSA-268h-hp4c-crq3, GHSA-c7w3-x93f-qmm8
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection — MODERATE
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter — LOW
6.4.2 — GHSA-fx2h-pf6j-xcff, GHSA-v6wh-96g9-6wx3
vite: `server.fs.deny` bypass on Windows alternate paths — devDependency
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows — devDependency
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 466 of 7695 files (highest-priority subset) · calcom/cal.diy
Dependency manifests: 107 package roots found, 36 scanned.
[](https://nittim.com)