OsVault/npm/@saltcorn/server
npm

@saltcorn/server

4 known vulnerabilities · 0 critical · 0 high

GHSA-cr3w-cw5w-h3fj

Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE

Published Jan 26, 2026
GHSA-32pv-mpqg-h292

Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read

Published Apr 10, 2026
GHSA-jp74-mfrx-3qvh

Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)

Published Apr 16, 2026
GHSA-f3g8-9xv5-77gv

Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)

Published Apr 16, 2026
Check your entire dependency tree at onceRun dependency scan →