diff
28 known vulnerabilities · 2 critical · 2 high
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Regular Expression Denial of Service (ReDoS)
Malicious code in argocd-diff-action (npm)
OpenClaw: system.run approval identity mismatch could execute a different binary than displayed
Malicious code in simple-date-diff-utils (npm)
Malicious code in @antv/xflow-diff (npm)
Malicious code in updated-object-diff (npm)
Malicious code in diff-dom-2 (npm)
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry
fast-jwt: Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
Malicious code in @t-in-one/only_difference_payload (npm)
Duplicate Advisory: OpenClaw: system.run approval identity mismatch could execute a different binary than displayed
Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames
Malicious code in dom-diff-exporter (npm)
Malicious code in @amber-team/report-bundle-diff (npm)
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
Malicious code in numdifftools (npm)
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
Malicious code in rediff (npm)
Malicious code in @asyncapi/diff (npm)
CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS
Malicious code in rediff-viewer (npm)