forked from snyk-labs/nodejs-goof
-
Notifications
You must be signed in to change notification settings - Fork 3
Pull requests: COG-GTM/nodejs-goof
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
bug: remove hardcoded API token from app.js
#240
opened Aug 28, 2026 by
devin-ai-integration
Bot
Loading…
bug: fix lodash prototype pollution in PUT /chat (CWE-1321)
#239
opened Aug 28, 2026 by
devin-ai-integration
Bot
Loading…
Fix NoSQL operator injection in login handler
#238
opened Aug 28, 2026 by
devin-ai-integration
Bot
Loading…
Fix OS command injection in POST /create (package install feature finding)
#237
opened Aug 28, 2026 by
devin-ai-integration
Bot
Loading…
bug: prevent Zip Slip path traversal in /import zip extraction
#236
opened Aug 28, 2026 by
devin-ai-integration
Bot
Loading…
bug: fix prototype pollution in chat message handler
#235
opened Aug 25, 2026 by
devin-ai-integration
Bot
Loading…
bug: prevent Zip Slip path traversal in archive import
#234
opened Aug 25, 2026 by
devin-ai-integration
Bot
Loading…
Remove hardcoded API token from app.js
#233
opened Aug 25, 2026 by
devin-ai-integration
Bot
Loading…
fix: command injection in todo image identify (CWE-78)
#232
opened Aug 25, 2026 by
devin-ai-integration
Bot
Loading…
bug: fix NoSQL operator injection in admin loginHandler
#231
opened Aug 25, 2026 by
devin-ai-integration
Bot
Loading…
fix: stored XSS in todo content rendering (CWE-79)
#230
opened Aug 25, 2026 by
devin-ai-integration
Bot
Loading…
fix(jssecurity:S5147): NoSQL injection in routes/index.js
#229
opened Aug 25, 2026 by
devin-ai-integration
Bot
Loading…
fix(security): prevent open redirect from user-controlled data (SonarQube jssecurity:S5146)
#228
opened Aug 24, 2026 by
devin-ai-integration
Bot
Loading…
fix: [elliptic] Upgrade elliptic from 6.4.1 to 6.6.1 to resolve CVE-2024-48948
#227
opened Aug 24, 2026 by
hannahhuh-cog
Loading…
fix: [parse-url] Upgrade parse-url from 5.0.1 to 6.0.1 to resolve CVE-2022-2216
#226
opened Aug 24, 2026 by
hannahhuh-cog
Loading…
fix: [form-data] Upgrade form-data from 2.3.3 to 4.0.4 to resolve CVE-2025-7783
#225
opened Aug 24, 2026 by
hannahhuh-cog
Loading…
fix: [handlebars] Upgrade handlebars from 4.0.14 to 4.7.9 to resolve SNYK-JS-HANDLEBARS-534988 (Prototype Pollution)
#224
opened Aug 24, 2026 by
hannahhuh-cog
Loading…
fix: [adm-zip] Upgrade adm-zip from 0.4.7 to 0.5.18 to resolve CVE-2018-1002204
#223
opened Aug 24, 2026 by
hannahhuh-cog
Loading…
fix(security): prevent open redirect from user-controlled data (SonarQube jssecurity:S5146)
#222
opened Aug 23, 2026 by
devin-ai-integration
Bot
Loading…
fix(security): prevent NoSQL injection from user-controlled query data (SonarQube jssecurity:S5147)
#221
opened Aug 23, 2026 by
devin-ai-integration
Bot
Loading…
bug: remove hardcoded API token and session secret from app.js
#220
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
bug: prevent prototype pollution in chat.add message merge
#219
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
bug: prevent NoSQL operator injection in loginHandler
#218
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
bug: fix Zip Slip in POST /import archive extraction
#217
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
bug: fix OS command injection in POST /create identify call
#216
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
Previous Next
ProTip!
Exclude everything labeled
bug with -label:bug.