7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether @sync-in/server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.5
CVE-2026-58270
Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
MEDIUM 5.3
CVE-2026-58272
Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
HIGH 8.1
CVE-2026-58269
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
MEDIUM 6.8
CVE-2026-58271
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
HIGH 7.7
CVE-2026-47684
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP
UNKNOWN
CVE-2026-41161
Sync-in Server has Username Enumeration via Timing Attack
UNKNOWN
CVE-2025-67438
Sync-in Server has a stored cross-site scripting (XSS) vulnerability
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes