VYPR

npm package

snowflake-sdk

pkg:npm/snowflake-sdk

Vulnerabilities (3)

  • CVE-2025-46328Apr 28, 2025
    affected >= 1.10.0, < 2.0.4fixed 2.0.4

    snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS the Driver reads logging configuration from

  • CVE-2025-24791Jan 29, 2025
    affected >= 1.12.0, < 2.0.2fixed 2.0.2

    snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache directo

  • CVE-2023-34232Jun 8, 2023
    affected < 1.6.21fixed 1.6.21

    snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1) e