Project Risk Score Project Risk Score: weighted blend of vulnerability (40%), trust (30%), and pipeline (30%) subscores. Useful for at-a-glance triage. Click for more →
79 /100
Critical

43 findings across 13 packages · 1142 packages clean

Candidates: 4 auto-merge · 7 review · 0 decline · 2 no fix

Scanned eslint/eslint @ main Scan · Completed 215 hrs ago Download SBOM
Total Findings
43
All detected issues
KEV Findings
0
Known exploited
High EPSS
3
Likely to be exploited
Auto-merge ready
4
Remediation candidates
Affected pkgs
13
with remediation paths
KEV catalog CISA's Known Exploited Vulnerabilities catalog. Documented active exploitation in the wild; the strongest 'this is happening now' signal. Click for more →
0
actively exploited CVEs
Highest EPSS Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
22.4%
CVE-2021-23337
Active vetos
7
lens blocks on candidates

Findings

lodash @ 4.17.23
root → metascraper-logo → lodash
6 findings high–medium
Trust 0/100 EPSS 22.4% ↑
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-r5fr-rjxr-66jc high CVSS 8.1 EPSS 22.4%
lodash vulnerable to Code Injection via `_.template` imports key names

Affects 3 install paths

GHSA-f23m-r3pf-42rh medium CVSS 6.5 EPSS 1.5%
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

Affects 3 install paths

4.17.23 → 4.18.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 8.1 · 6 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 22.4% · 97th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-r5fr-rjxr-66jc: lodash vulnerable to Code Injection via `_.template` imports key names

Upgrade lodash from 4.17.23 to 4.18.0 or later

View advisory
root → metascraper-logo → lodash

Blast radius

Paths from project root to lodash - which dependencies pulled this package in?

underscore @ 1.4.4
root → npm-license → underscore
2 findings critical–medium
Trust 30/100 EPSS 4.1% ⚠ new maintainer
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-qpx9-hpmf-5gmw medium CVSS 5.9 EPSS 0.6%
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
1.4.4 → 1.13.8 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 9.8 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 4.1% · 89th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.new_maintainer Veto: a new publishing identity was added between your current version and the upgrade target. A well-documented supply chain attack vector. Click for more →
  • trust veto: new maintainer added
GHSA-cf4h-3jhx-xvhq: Arbitrary Code Execution in underscore

Upgrade underscore from 1.4.4 to 1.12.1 or later

View advisory
root → npm-license → underscore

Blast radius

Paths from project root to underscore - which dependencies pulled this package in?

axios @ 0.21.4 An upgrade Arguss blocked despite the newer version being available, because trust signals like ownership transfer or new maintainer fired during the upgrade window. Click for more →
root → eslint-release → github-api → axios
23 findings high–low
Trust 0/100 EPSS 2.5% ⚠ ownership transferred
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-pjwm-pj3p-43mv high CVSS 8.6 EPSS 0.9%
axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
GHSA-43fc-jf86-j433 high CVSS 7.5 EPSS 2.5%
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
GHSA-62hf-57xw-28j9 high CVSS 7.5 EPSS 0.7%
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
GHSA-hfxv-24rg-xrqf high CVSS 7.5 EPSS 0.6%
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
GHSA-j5f8-grm9-p9fc high CVSS 7.5 EPSS 0.5%
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
GHSA-jr5f-v2jv-69x6 high CVSS 7.5 EPSS 0.8%
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
GHSA-p92q-9vqr-4j8v high CVSS 7.5 EPSS 0.7%
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
GHSA-pf86-5x62-jrwf high CVSS 7.4 EPSS 0.8%
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
GHSA-pmwg-cvhr-8vh7 high CVSS 7.2 EPSS 0.7%
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
GHSA-3g43-6gmg-66jw high CVSS 7.0 EPSS 0.5%
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
GHSA-m7pr-hjqh-92cm medium CVSS 6.8 EPSS 0.3%
Axios: no_proxy bypass via IP alias allows SSRF
GHSA-xx6v-rp6x-q39c medium CVSS 5.4 EPSS 0.2%
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
GHSA-5c9x-8gcm-mpgx medium CVSS 5.3 EPSS 0.3%
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
GHSA-vf2m-468p-8v99 medium CVSS 5.3 EPSS 0.4%
Axios: HTTP adapter streamed responses bypass maxContentLength
GHSA-7q8q-rj6j-mhjq medium CVSS 5.0 EPSS n/a
Axios: Nested axios option objects can consume polluted prototype values
GHSA-mmx7-hfxf-jppx medium CVSS 5.0 EPSS n/a
Axios: Prototype pollution gadgets can alter axios request construction
GHSA-3p68-rc4w-qgx5 medium CVSS 4.8 EPSS 1.2%
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
GHSA-898c-q2cr-xwhg medium CVSS 4.8 EPSS 0.3%
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
GHSA-fvcv-3m26-pcqx medium CVSS 4.8 EPSS 1.8%
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
GHSA-w9j2-pvgh-6h63 medium CVSS 4.8 EPSS 0.6%
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
GHSA-xhjh-pmcv-23jw low CVSS 3.7 EPSS 0.2%
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
0.21.4 → 0.33.0 minor
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 85
Max CVSS 8.6 · 23 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.5% · 82nd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
trust.ownership_transferred Veto: the package's primary maintainer changed during the upgrade window. Combined with new-maintainer, this is the highest-risk trust combination. Click for more →
  • trust veto: package ownership transferred between versions
GHSA-pjwm-pj3p-43mv: axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

Upgrade axios from 0.21.4 to 0.32.0 or later

View advisory
root → eslint-release → github-api → axios

Blast radius

Paths from project root to axios - which dependencies pulled this package in?

nth-check @ 1.0.2
root → cheerio → css-select → nth-check
1 finding high
Trust 30/100 EPSS 2.2%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-rp65-9cf3-cjxr high CVSS 7.5 EPSS 2.2%
Inefficient Regular Expression Complexity in nth-check
1.0.2 → 2.0.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 2.2% · 80th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-rp65-9cf3-cjxr: Inefficient Regular Expression Complexity in nth-check

Upgrade nth-check from 1.0.2 to 2.0.1 or later

View advisory
root → cheerio → css-select → nth-check

Blast radius

Paths from project root to nth-check - which dependencies pulled this package in?

cross-spawn @ 5.1.0
root → cypress → execa → cross-spawn
1 finding high
Trust 30/100 EPSS 0.9%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-3xgq-45jj-v275 high CVSS 7.5 EPSS 0.9%
Regular Expression Denial of Service (ReDoS) in cross-spawn
5.1.0 → 6.0.6 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.9% · 54th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-3xgq-45jj-v275: Regular Expression Denial of Service (ReDoS) in cross-spawn

Upgrade cross-spawn from 5.1.0 to 6.0.6 or later

View advisory
root → cypress → execa → cross-spawn

Blast radius

Paths from project root to cross-spawn - which dependencies pulled this package in?

diff @ 7.0.0
root → mocha → diff
1 finding low
Trust 0/100 EPSS 0.6%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-73rr-hh4g-fpgx low CVSS 2.5 EPSS 0.6%
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
7.0.0 → 8.0.3 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 2.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.6% · 43rd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-73rr-hh4g-fpgx: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Upgrade diff from 7.0.0 to 8.0.3 or later

View advisory
root → mocha → diff

Blast radius

Paths from project root to diff - which dependencies pulled this package in?

serialize-javascript @ 6.0.2
root → mocha → serialize-javascript
2 findings high–medium
Trust 0/100 EPSS 0.5%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-5c6j-r48x-rmvq high CVSS 8.1 EPSS n/a
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
GHSA-qj8w-gfj5-8c6v medium CVSS 5.9 EPSS 0.5%
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
6.0.2 → 7.0.5 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 8.1 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.5% · 37th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-5c6j-r48x-rmvq: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Upgrade serialize-javascript from 6.0.2 to 7.0.3 or later

View advisory
root → mocha → serialize-javascript

Blast radius

Paths from project root to serialize-javascript - which dependencies pulled this package in?

js-yaml @ 4.1.1
root → markdownlint-cli2 → js-yaml
2 findings high–medium
Trust 30/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-52cp-r559-cp3m high CVSS 7.5 EPSS 0.4%
js-yaml: YAML merge-key chains can force quadratic CPU consumption
GHSA-h67p-54hq-rp68 medium CVSS 5.3 EPSS 0.3%
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
4.1.1 → 4.3.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 7.5 · 2 findings Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 29th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-52cp-r559-cp3m: js-yaml: YAML merge-key chains can force quadratic CPU consumption

Upgrade js-yaml from 4.1.1 to 4.3.0 or later

View advisory
root → markdownlint-cli2 → js-yaml

Blast radius

Paths from project root to js-yaml - which dependencies pulled this package in?

qs @ 6.14.2
root → cypress → @cypress/request → qs
1 finding medium
Trust 0/100 EPSS 0.4%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-q8mj-m7cp-5q26 medium CVSS 5.3 EPSS 0.4%
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
6.14.2 → 6.15.2 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.4% · 27th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-q8mj-m7cp-5q26: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Upgrade qs from 6.14.2 to 6.15.2 or later

View advisory
root → cypress → @cypress/request → qs

Blast radius

Paths from project root to qs - which dependencies pulled this package in?

uuid @ 8.3.2
root → cypress → @cypress/request → uuid
1 finding high
Trust 0/100 EPSS 0.3%
REVIEW Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more →
GHSA-w5hq-g745-h8pq high CVSS 7.5 EPSS 0.3%
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
8.3.2 → 11.1.1 major
review-required Verdict tier: at least one veto fired. A human needs to decide whether to merge despite the flagged risk. Click for more → Score 50
Max CVSS 7.5 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 25th percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
fix_kind.major Veto: the available fix requires a major version bump (1.x → 2.x), which implies potential breaking changes outside the auto-merge envelope. Click for more →
  • major version bump requires human review (never auto-merge)
GHSA-w5hq-g745-h8pq: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Upgrade uuid from 8.3.2 to 11.1.1 or later

View advisory
root → cypress → @cypress/request → uuid

Blast radius

Paths from project root to uuid - which dependencies pulled this package in?

markdown-it @ 14.1.1
root → markdownlint-cli2 → markdown-it
1 finding medium
Trust 30/100 EPSS 0.3%
AUTO-MERGE Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more →
GHSA-6v5v-wf23-fmfq medium CVSS 5.3 EPSS 0.3%
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
14.1.1 → 14.2.0 minor
auto-merge Verdict tier: the fix passes all three lenses cleanly. In Mode C, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. Click for more → Score 100
Max CVSS 5.3 · 1 finding Common Vulnerability Scoring System. A 0–10 score for how damaging exploitation could be. Severity, not urgency. Click for more → Max EPSS 0.3% · 22nd percentile Exploit Prediction Scoring System. Daily-updated probability that a CVE will be exploited in the next 30 days. Probability, not severity. Click for more →
  • minor-level upgrade; trust signals unchanged; CI verifies tests
GHSA-6v5v-wf23-fmfq: markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

Upgrade markdown-it from 14.1.1 to 14.2.0 or later

View advisory
root → markdownlint-cli2 → markdown-it

Blast radius

Paths from project root to markdown-it - which dependencies pulled this package in?

Package status

1155 packages scanned.

  • 7 Review-required candidates Arguss flagged these for a human decision - nothing merges until you review them.
  • 2 Packages with no automated fix
  • 4 Auto-merge candidates

Review auto-merge candidates and open PRs in a guided flow.

Glossary

What the labels and signals mean.

Trust Save
A package upgrade Arguss would have blocked despite the new version being available, because trust signals, like ownership transfer or a new maintainer, fired during the upgrade window. The name reflects what the agent did for the user: saved them from a potentially malicious update that a version-only auto-PR tool would have merged.
AUTO-MERGE
Verdict tier indicating the fix passes all three lenses cleanly. After you confirm action from a Scan assessment, Arguss opens a pull request for the upgrade; it does not merge PRs on GitHub. The envelope is conservative on purpose: patch or minor version bump, trust signals unchanged, blast radius bounded, real tests pass.
REVIEW
Verdict tier requiring a human decision. At least one veto fired during fix-confidence evaluation, trust signals shifted, the pipeline can't verify post-upgrade behavior, or the upgrade is a major version bump. The agent surfaces the reasons; the developer decides.
DECLINE
Verdict tier indicating no remediation is recommended. Typically applies when no fix version exists for the finding, or when multiple critical vetoes make even human review unproductive.
fix_kind.major
Veto signal that fires when the available fix requires a major version bump (1.x → 2.x). Major bumps imply potential breaking changes and fall outside the auto-merge envelope by default, even when the upgrade is the only available fix.
trust.new_maintainer
Veto signal that fires when a package added a new maintainer during the upgrade window, meaning between the user's current version and the proposed upgrade. New publishing identities are a well-documented attack vector for typosquats and supply chain takeovers.
trust.ownership_transferred
Veto signal that fires when a package's primary maintainer changed during the upgrade window. Combined with trust.new_maintainer, this is the highest-risk trust combination, typical of the xz-utils style attacks and historical npm credential theft incidents.
pipeline.test_reality
Veto signal that fires when Arguss can't verify tests will run on the upgraded code. Four conditions must hold: a test script exists in package.json, it isn't a no-op, real test files exist, and a workflow actually invokes them. If any fail, the fix cannot qualify for AUTO_MERGE because there's no way to verify the upgrade didn't break the user's project.
CVSS
Common Vulnerability Scoring System. A numeric score (0.0–10.0) representing how damaging a vulnerability could be if exploited. Sourced from NIST's National Vulnerability Database via OSV.dev. Severity, not urgency.
EPSS
Exploit Prediction Scoring System. A daily-updated probability (0.0–1.0, displayed as percent) that a CVE will be exploited in the next 30 days. Sourced from FIRST.org. Probability, not severity.
KEV
CISA's Known Exploited Vulnerabilities catalog. A federal list of CVEs with documented active exploitation in the wild. Federal agencies have a binding patching deadline; for everyone else, presence on KEV is the strongest "this is being used right now" signal available. Sourced directly from CISA.
Project Risk Score (PRS)
A weighted blend of the three lens subscores (40% vulnerability, 30% trust, 30% pipeline) producing an overall 0–100 indicator of the project's dependency health. Useful for at-a-glance triage; the per-finding fix-confidence verdicts are what drive automated decisions.

Dependency graph

Full-project map of transitive dependencies. Severity colors reflect vulnerabilities; trust rings apply only to direct dependencies analyzed by OpenSSF Scorecard (higher = riskier).