DevSecOps and application security

Snyk advisories: every record the registers tie to its products

In one line

24 advisories are attributed to Snyk products in this record, covering February 2022 to June 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 2 register entries mention Snyk without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

24

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

2

by the register

Last checked

Jul 18, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Snyk, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

2 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

24 of the 24 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2026-10732mediumCVSS 6.1Jun 05, 2026

    All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the…

  • CVE-2026-6951criticalCVSS 9.2Apr 25, 2026

    Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for…

  • CVE-2025-3193highCVSS 7.5Sep 27, 2025

    Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype…

  • CVE-2025-6624highCVSS 7.2Jun 26, 2025

    Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs.

  • CVE-2025-1467mediumCVSS 5.1Feb 23, 2025

    Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight().

  • CVE-2025-1302criticalCVSS 9.3Feb 15, 2025

    Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization.

  • CVE-2025-1026highCVSS 7.7Feb 05, 2025

    Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File…

  • CVE-2024-21549highCVSS 7.7Dec 20, 2024

    Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method.

  • CVE-2024-21571highCVSS 8.1Dec 06, 2024

    Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent.

  • CVE-2024-48963highCVSS 7.5Oct 23, 2024

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project.

  • CVE-2024-48964highCVSS 7.5Oct 23, 2024

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project.

  • CVE-2023-26130highCVSS 7.5May 30, 2023

    Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put…

  • CVE-2023-1767mediumCVSS 4.3Apr 20, 2023

    The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023.

  • CVE-2023-1065mediumCVSS 6.5Feb 28, 2023

    This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues.

  • CVE-2022-25937mediumCVSS 6.5Feb 13, 2023

    Versions of the package glance before 3.0.9 are vulnerable to Directory Traversal that allows users to read files outside the public root directory.

  • CVE-2022-25860highCVSS 8.1Jan 24, 2023

    Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization.

  • CVE-2022-25912highCVSS 8.1Dec 12, 2022

    The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method.

  • CVE-2022-24441mediumCVSS 5.8Nov 30, 2022

    The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project.

  • CVE-2022-22984mediumCVSS 5.0Nov 30, 2022

    The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package…

  • CVE-2022-21231highCVSS 7.5Jun 24, 2022

    All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function.

  • CVE-2022-21190highCVSS 7.5May 13, 2022

    This affects the package convict before 6.2.3.

  • CVE-2022-22143highCVSS 7.5May 01, 2022

    The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey.

  • CVE-2022-25352highCVSS 7.5Mar 17, 2022

    The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js.

  • CVE-2021-23507highCVSS 7.5Feb 04, 2022

    The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it.

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union26Jun 05, 2026
National Vulnerability DatabaseNIST, United States Department of Commerce1Jun 26, 2025

The entry counts here are the raw register totals for Snyk, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Snyk have?

24 advisories in this record are tied by a register to a product of Snyk. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Snyk vulnerabilities being actively exploited?

None of the 24 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Snyk than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 2 register entries name Snyk without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Snyk advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); National Vulnerability Database (NIST, United States Department of Commerce). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Snyk is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Snyk record, including sources and open questions

Snyk vulnerabilities: all 24 advisories on record, with sources | DecisionOS by nexalign