{"record":"Snyk evidence record","url":"https://nexalign.io/vendors/snyk","vendor":{"slug":"snyk","name":"Snyk","domain":"snyk.io","category":"devsecops","categoryLabel":"DevSecOps and application security"},"lastChecked":"2026-07-18T16:17:56.535Z","coverage":{"earliest":"2022-02-04T20:05:18.000Z","latest":"2026-07-18T16:17:56.535Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":41,"kindsOfSource":4,"attributedAdvisories":24,"knownExploited":0,"registerEntriesNotAttributable":2,"practitionerThreads":4,"independentItems":6,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":26,"latest":"2026-06-05T05:00:02.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":1,"latest":"2025-06-26T05:15:23.820Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":8,"latest":"2026-06-25T20:09:58.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":6,"latest":"2026-07-18T16:17:56.535Z"}],"advisories":{"shown":6,"total":24,"truncated":true,"fullList":"https://nexalign.io/vendors/snyk/advisories","items":[{"id":"CVE-2026-10732","description":"All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the…","severity":"medium","cvss":6.1,"knownExploited":false,"date":"2026-06-05T05:00:02.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34785"]},{"id":"CVE-2026-6951","description":"Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for…","severity":"critical","cvss":9.2,"knownExploited":false,"date":"2026-04-25T05:00:05.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25639"]},{"id":"CVE-2025-3193","description":"Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype…","severity":"high","cvss":7.5,"knownExploited":false,"date":"2025-09-27T05:00:07.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-31407"]},{"id":"CVE-2025-6624","description":"Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs.","severity":"high","cvss":7.2,"knownExploited":false,"date":"2025-06-26T05:15:23.820Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-6624","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19191"]},{"id":"CVE-2025-1467","description":"Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight().","severity":"medium","cvss":5.1,"knownExploited":false,"date":"2025-02-23T15:19:46.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-4304"]},{"id":"CVE-2025-1302","description":"Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization.","severity":"critical","cvss":9.3,"knownExploited":false,"date":"2025-02-15T05:00:01.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-2104"]}]},"practitionerThreads":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Snyk Finds Prompt Injection in 36% of Payloads in a ToxicSkills Study","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48678603","date":"2026-06-25T20:09:58.000Z"},{"title":"Snyk announces layoffs, blames AI","context":"Hacker News","url":"https://news.ycombinator.com/item?id=48661446","date":"2026-06-24T15:30:28.000Z"},{"title":"Snyk Security Labs Testing Update: Cursor.com AI Code Editor","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42703232","date":"2025-01-14T20:18:01.000Z"},{"title":"Snyk security researcher deploys malicious NPM packages targeting cursor.com","context":"Hacker News","url":"https://news.ycombinator.com/item?id=42690473","date":"2025-01-13T22:38:27.000Z"}]},"independentCoverage":{"shown":5,"total":6,"truncated":true,"items":[{"title":"Snyk Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/application-security-testing/vendor/snyk","date":null},{"title":"Snyk Reviews 2026. Verified Reviews, Pros & Cons | Capterra","host":"capterra.com","url":"https://www.capterra.com/p/172252/Snyk/reviews/","date":null},{"title":"Snyk Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/snyk-reviews","date":null},{"title":"Snyk - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Snyk","date":null},{"title":"Snyk Reviews 2026: Details, Pricing, & Features | G2","host":"g2.com","url":"https://www.g2.com/products/snyk/reviews","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 2 register entries mention Snyk without naming a product of Snyk as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}