3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether esbuild is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.1
GHSA-gv7w-rqvm-qjhr
Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
LOW 2.5
GHSA-g7r4-m6w7-qqqr
esbuild allows arbitrary file read when running the development server on Windows
MEDIUM 5.3
GHSA-67mh-4wv8-2f99
esbuild enables any website to send any requests to the development server and read the response
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes