Uppy
by Transloadit
Source repositories
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-70023 | Cri | 0.64 | 9.8 | 0.00 | Apr 14, 2026 | An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. | ||
| CVE-2020-8135 | Cri | 0.64 | 9.8 | 0.01 | Mar 20, 2020 | The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems. | ||
| CVE-2022-0086 | Cri | 0.57 | 9.8 | 0.01 | Jan 4, 2022 | uppy is vulnerable to Server-Side Request Forgery (SSRF) | ||
| CVE-2022-0528 | Med | 0.35 | 6.5 | 0.01 | Mar 3, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1. | ||
| CVE-2020-8205 | Hig | 0.00 | 7.5 | 0.01 | Jul 20, 2020 | The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems. |
- risk 0.64cvss 9.8epss 0.00
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
- risk 0.64cvss 9.8epss 0.01
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
- risk 0.57cvss 9.8epss 0.01
uppy is vulnerable to Server-Side Request Forgery (SSRF)
- risk 0.35cvss 6.5epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
- risk 0.00cvss 7.5epss 0.01
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.