8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether @keystone-6/core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-63421
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
MEDIUM 4.3
CVE-2026-10802
Keystone: GraphQL API Endpoint Lacks Query Depth Limits
MEDIUM 4.3
CVE-2026-33326
@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany (CVE-2025-46720 incomplete fix)
LOW 3.1
CVE-2025-46720
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
MEDIUM 5.3
CVE-2023-40027
When `ui.isAccessAllowed` is `undefined`, the `adminMeta` GraphQL query is publicly accessible
CRITICAL 9.8
CVE-2022-39382
@keystone-6/core's NODE_ENV defaults to development with esbuild
CRITICAL 9.1
CVE-2022-39322
Field-level access-control bypass for multiselect field
UNKNOWN
GHSA-5fp6-4xw3-xqq3
@keystone-6/core's bundled cuid package known to be insecure
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes