VYPR

npm package

snyk

pkg:npm/snyk

Vulnerabilities (4)

  • CVE-2025-6624HigJun 26, 2025
    affected < 1.1297.3fixed 1.1297.3

    Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI in

  • CVE-2022-24441Nov 30, 2022
    affected < 1.1064.0fixed 1.1064.0

    The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges

  • CVE-2022-22984Nov 30, 2022
    affected < 1.1064.0fixed 1.1064.0

    The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package sn

  • CVE-2022-40764Oct 3, 2022
    affected < 1.996.0fixed 1.996.0

    Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell