npm
@saltcorn/server
4 known vulnerabilities · 0 critical · 0 high
GHSA-cr3w-cw5w-h3fj
Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE
Published Jan 26, 2026
GHSA-32pv-mpqg-h292
Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read
Published Apr 10, 2026
GHSA-jp74-mfrx-3qvh
Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)
Published Apr 16, 2026
GHSA-f3g8-9xv5-77gv
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)
Published Apr 16, 2026
Check your entire dependency tree at onceRun dependency scan →