# Security Audit Report — mcp-audiense-insights

- **Report ID:** `d94e5a42-dab2-4744-aa34-3de30a051b04`
- **Generated:** 2026-07-21T22:43:49.786496+00:00
- **Signature:** unsigned (cosign keyless signing runs in CI; Req 22.4)

## 1. Executive Summary

**Badge:** Unsafe (composite)  
**Security score:** 47.96

| Scanner | Badge |
| --- | --- |
| agent-audit-kit | Unsafe |
| agentshield | Verified |
| bearer | Verified |
| cisco-skill-scanner | Caution |
| nerlo-behavioral | Verified |
| nerlo-install-instruction | Verified |
| osv-scanner | Unsafe |
| trivy | Unsafe |

| Severity | Findings |
| --- | --- |
| critical | 0 |
| high | 20 |
| medium | 21 |
| low | 12 |

mcp-audiense-insights is NOT recommended for integration: the scan surfaced 0 critical and 20 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering.

## 2. Source Provenance

- **Repository:** https://github.com/AudienseCo/mcp-audiense-insights
- **Commit scanned:** `unknown`
- **License:** Apache-2.0
- **Maintainer:** Audiense
- **Version:** 0.2.0

## 3. Per-Scanner Detail

### agentshield (v1.4.0) — Verified / 100.0

No findings.

### cisco-skill-scanner (v2.0.11) — Caution / 67.5

- **[high] Critically low analyzability score** — Only 44% of skill content could be analyzed. 10 of 19 files are opaque to the scanner. The safety assessment has low confidence. (/repo:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/src/audienseClient.ts:24)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/src/audienseClient.ts:63)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/src/audienseClient.ts:162)

### agent-audit-kit (v0.3.26) — Unsafe / 36.0

- **[low] Dependency count exceeds threshold** — More than 200 direct + transitive dependencies in lockfile. Each dependency is a trust decision. (package-lock.json:None)
- **[low] MCP server repo missing SECURITY.md or security_contact** — A repository whose name or pyproject keywords declare it as an MCP server ships without a top-level SECURITY.md AND without a 'security_contact' entry in marketplace.json / pyproject.toml / package.json. Anthropic's April 2026 SECURITY.md guidance makes this the baseline expectation so researchers have a channel. (SECURITY.md:None)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (src/index.ts:3)
- **[medium] Bearer token used where DPoP or mTLS is required** — An MCP remote server accepts plain Bearer tokens on a flow that MCP spec 2025-11-25 flags for DPoP (Demonstrating Proof of Possession) or mTLS-bound tokens. A stolen Bearer token is fully replayable. (src/audienseClient.ts:None)
- **[medium] Repo depends on a third-party agent-platform SDK** — The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel × Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants. (package.json:39)
- **[high] MCP server built on the upstream SDK without STDIO sanitizer** — Repository declares a dependency on the upstream Anthropic / ModelContextProtocol SDK (Python 'mcp' / 'modelcontextprotocol', TS '@modelcontextprotocol/sdk', Java 'io.modelcontextprotocol:*', Rust 'mcp' / 'modelcontextprotocol') and exposes a STDIO transport ('StdioServerTransport', 'stdio_server', etc.) without a sanitizer on argv assembly. Anthropic declined to CVE this as working as designed — sanitization is the developer's responsibility. The OX Security disclosure on 2026-04-15 rolled up L (src/index.ts:None)
- **[high] Vulnerable MCP SDK version pinned (DNS-rebinding fix missing)** — A project dependency manifest (requirements.txt, pyproject.toml, package.json, pom.xml, build.gradle) pins an MCP SDK at a version below the DNS-rebinding fix. Patched versions: Python 'mcp' >= 1.23.0, TS '@modelcontextprotocol/sdk' >= 1.21.1, Java 'io.modelcontextprotocol.sdk:mcp-core' >= 0.11.0, '@apollo/mcp-server' >= 1.7.0. Even if the project never serves over StreamableHTTP itself, transitive servers built on the SDK inherit the bug. (package.json:None)
- **[high] Session token written to log sink in cleartext** — An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern — session tokens ended up in the Splunk '_internal' index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius. (src/audienseClient.ts:138)

### bearer (v2.0.2) — Verified / 100.0

No findings.

### nerlo-behavioral (v0.1.0) — Verified / 100.0

No findings.

### nerlo-install-instruction (v0.1.0) — Verified / 100.0

No findings.

### trivy (v0.71.0) — Unsafe / 24.0

- **[high] Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default** — MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPServerTransport or SSEServerTransport and has not enabled enableDnsRebindingProtection, a malicious website could exploit DNS rebinding to bypass same-origin policy rest (package-lock.json:None)
- **[high] Anthropic's MCP TypeScript SDK has a ReDoS vulnerability** — Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can trigger catastrophic backtracking on specially crafted inputs, resulting in excessive CPU consumption. An attacker can exploit this by supplying a malicious URI that causes the Node. (package-lock.json:None)
- **[low] body-parser: body-parser: Denial of Service via invalid limit option** — Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars (package-lock.json:None)
- **[high] path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions** — Impact:  A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as '{a}{b}{c}:z'. The generated regex grows exponentially with the number of groups, causing denial of service.  Patches:  Fixed in version 8.4.0.  Workarounds:  Limit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns. (package-lock.json:None)
- **[medium] path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards** — Impact:  When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.  Unsafe examples:  /*foo-*bar-:baz /*a-:b-*c-:d /x/*a-:b/*c/y  Safe examples:  /*foo-:bar /*foo-:bar-*baz  Patches:  Upgrade to version 8.4.0.  Workarounds:  If you are using multiple wildcard parameters, you can check the regex output with a too (package-lock.json:None)
- **[medium] qs: qs: Denial of Service via improper input validation in array parsing** — Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.   Summary  The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations.  Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la (package-lock.json:None)
- **[medium] \#\#\# Summary    'qs.stringify' throws 'TypeError' when called with 'arr ...** — \#\#\# Summary    'qs.stringify' throws 'TypeError' when called with 'arrayFormat: 'comma'' and 'encodeValuesOnly: true' on an array containing 'null' or 'undefined'. The throw is synchronous and not handled by any of qs's null-related options ('skipNulls', 'strictNullHandling').    \#\#\# Details    In the comma + 'encodeValuesOnly' branch, 'lib/stringify.js:145' mapped the array through the raw encoder before joining:    '''js    obj = utils.maybeMap(obj, encoder);    '''    'utils.encode' ('lib/uti (package-lock.json:None)
- **[low] qs: qs's arrayLimit bypass in comma parsing allows denial of service** — \#\#\# Summary The 'arrayLimit' option in qs does not enforce limits for comma-separated values when 'comma: true' is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).  \#\#\# Details When the 'comma' option is set to 'true' (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., '? (package-lock.json:None)
- **[medium] qs: qs: Denial of Service via improper input validation in array parsing** — Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.   Summary  The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations.  Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la (package-lock.json:None)
- **[medium] \#\#\# Summary    'qs.stringify' throws 'TypeError' when called with 'arr ...** — \#\#\# Summary    'qs.stringify' throws 'TypeError' when called with 'arrayFormat: 'comma'' and 'encodeValuesOnly: true' on an array containing 'null' or 'undefined'. The throw is synchronous and not handled by any of qs's null-related options ('skipNulls', 'strictNullHandling').    \#\#\# Details    In the comma + 'encodeValuesOnly' branch, 'lib/stringify.js:145' mapped the array through the raw encoder before joining:    '''js    obj = utils.maybeMap(obj, encoder);    '''    'utils.encode' ('lib/uti (package-lock.json:None)
- **[low] qs: qs's arrayLimit bypass in comma parsing allows denial of service** — \#\#\# Summary The 'arrayLimit' option in qs does not enforce limits for comma-separated values when 'comma: true' is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).  \#\#\# Details When the 'comma' option is set to 'true' (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., '? (package-lock.json:None)

### osv-scanner (v2.3.8) — Unsafe / 0.0

- **[low] GHSA-4x5r-pxfx-6jf8 — npm @babel/core@7.26.9** — aliases: CVE-2026-49356, GHSA-4x5r-pxfx-6jf8 \| CVSS: 3.2 (/repo/package-lock.json:None)
- **[high] GHSA-8r9q-7v3j-jr4g — npm @modelcontextprotocol/sdk@1.7.0** — aliases: CVE-2026-0621, GHSA-8r9q-7v3j-jr4g \| CVSS: 8.7 (/repo/package-lock.json:None)
- **[high] GHSA-w48q-cv73-mx4w — npm @modelcontextprotocol/sdk@1.7.0** — aliases: CVE-2025-66414, GHSA-w48q-cv73-mx4w \| CVSS: 7.6 (/repo/package-lock.json:None)
- **[low] GHSA-v422-hmwv-36x6 — npm body-parser@2.1.0** — aliases: CVE-2026-12590, GHSA-v422-hmwv-36x6 \| CVSS: 3.7 (/repo/package-lock.json:None)
- **[high] GHSA-3jxr-9vmj-r5cp — npm brace-expansion@1.1.11** — aliases: CVE-2026-13149, GHSA-3jxr-9vmj-r5cp \| CVSS: 7.7 (/repo/package-lock.json:None)
- **[medium] GHSA-f886-m6hf-6m8v — npm brace-expansion@1.1.11** — aliases: CVE-2026-33750, GHSA-f886-m6hf-6m8v \| CVSS: 6.5 (/repo/package-lock.json:None)
- **[low] GHSA-v6h2-p8h4-qcjw — npm brace-expansion@1.1.11** — aliases: CVE-2025-5889, GHSA-v6h2-p8h4-qcjw \| CVSS: 3.1 (/repo/package-lock.json:None)
- **[high] GHSA-3jxr-9vmj-r5cp — npm brace-expansion@2.0.1** — aliases: CVE-2026-13149, GHSA-3jxr-9vmj-r5cp \| CVSS: 7.7 (/repo/package-lock.json:None)
- **[medium] GHSA-f886-m6hf-6m8v — npm brace-expansion@2.0.1** — aliases: CVE-2026-33750, GHSA-f886-m6hf-6m8v \| CVSS: 6.5 (/repo/package-lock.json:None)
- **[low] GHSA-v6h2-p8h4-qcjw — npm brace-expansion@2.0.1** — aliases: CVE-2025-5889, GHSA-v6h2-p8h4-qcjw \| CVSS: 3.1 (/repo/package-lock.json:None)
- **[high] GHSA-52cp-r559-cp3m — npm js-yaml@3.14.1** — aliases: CVE-2026-59869, GHSA-52cp-r559-cp3m \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[medium] GHSA-h67p-54hq-rp68 — npm js-yaml@3.14.1** — aliases: CVE-2026-53550, GHSA-h67p-54hq-rp68 \| CVSS: 5.3 (/repo/package-lock.json:None)
- **[medium] GHSA-mh29-5h37-fv8m — npm js-yaml@3.14.1** — aliases: CVE-2025-64718, GHSA-mh29-5h37-fv8m \| CVSS: 5.3 (/repo/package-lock.json:None)
- **[high] GHSA-23c5-xmqv-rm74 — npm minimatch@3.1.2** — aliases: CVE-2026-27904, GHSA-23c5-xmqv-rm74 \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[high] GHSA-3ppc-4f35-3m26 — npm minimatch@3.1.2** — aliases: CVE-2026-26996, GHSA-3ppc-4f35-3m26 \| CVSS: 8.7 (/repo/package-lock.json:None)
- **[high] GHSA-7r86-cg39-jmmj — npm minimatch@3.1.2** — aliases: CVE-2026-27903, GHSA-7r86-cg39-jmmj \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[high] GHSA-23c5-xmqv-rm74 — npm minimatch@5.1.6** — aliases: CVE-2026-27904, GHSA-23c5-xmqv-rm74 \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[high] GHSA-3ppc-4f35-3m26 — npm minimatch@5.1.6** — aliases: CVE-2026-26996, GHSA-3ppc-4f35-3m26 \| CVSS: 8.7 (/repo/package-lock.json:None)
- **[high] GHSA-7r86-cg39-jmmj — npm minimatch@5.1.6** — aliases: CVE-2026-27903, GHSA-7r86-cg39-jmmj \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[medium] GHSA-27v5-c462-wpq7 — npm path-to-regexp@8.2.0** — aliases: CVE-2026-4923, GHSA-27v5-c462-wpq7 \| CVSS: 5.9 (/repo/package-lock.json:None)
- **[high] GHSA-j3q9-mxjg-w52f — npm path-to-regexp@8.2.0** — aliases: CVE-2026-4926, GHSA-j3q9-mxjg-w52f \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[medium] GHSA-3v7f-55p6-f55p — npm picomatch@2.3.1** — aliases: CVE-2026-33672, GHSA-3v7f-55p6-f55p \| CVSS: 5.3 (/repo/package-lock.json:None)
- **[high] GHSA-c2c7-rcm5-vvqj — npm picomatch@2.3.1** — aliases: CVE-2026-33671, GHSA-c2c7-rcm5-vvqj \| CVSS: 7.5 (/repo/package-lock.json:None)
- **[medium] GHSA-6rw7-vpxm-498p — npm qs@6.13.0** — aliases: CVE-2025-15284, GHSA-6rw7-vpxm-498p \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-q8mj-m7cp-5q26 — npm qs@6.13.0** — aliases: CVE-2026-8723, GHSA-q8mj-m7cp-5q26 \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[low] GHSA-w7fw-mjwx-w883 — npm qs@6.13.0** — aliases: CVE-2026-2391, GHSA-w7fw-mjwx-w883 \| CVSS: 3.7 (/repo/package-lock.json:None)
- **[medium] GHSA-6rw7-vpxm-498p — npm qs@6.14.0** — aliases: CVE-2025-15284, GHSA-6rw7-vpxm-498p \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[medium] GHSA-q8mj-m7cp-5q26 — npm qs@6.14.0** — aliases: CVE-2026-8723, GHSA-q8mj-m7cp-5q26 \| CVSS: 6.3 (/repo/package-lock.json:None)
- **[low] GHSA-w7fw-mjwx-w883 — npm qs@6.14.0** — aliases: CVE-2026-2391, GHSA-w7fw-mjwx-w883 \| CVSS: 3.7 (/repo/package-lock.json:None)

## 4. Threat Model

Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.

## 5. Audit Chain

- **Scan job:** `5aebbeae-a6f1-40a7-b9d0-465b5f3167e8`
- **Completed:** 2026-07-21T02:31:02.776374+00:00
- **Scanner base image:** `us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:fb6188f6b4eedc1748ddff43733dc2a67413a3288d8126eea8e575bf36d55814`
- **AI decision log entries:** 1
  - `f51f139c-b7bb-4a7f-81a9-2055a7a6ff73`

## 6. Appendix — Raw Scanner Output

```json
[
  {
    "scanner_name": "agentshield",
    "scanner_version": "1.4.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 8.931852380002965,
    "status": "complete",
    "metadata": {
      "source": "npm",
      "source_url": "https://www.npmjs.com/package/ecc-agentshield",
      "install_command": "npm install -g ecc-agentshield@1.4.0",
      "scans_performed": [
        "supply_chain"
      ]
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "cisco-skill-scanner",
    "scanner_version": "2.0.11",
    "score": 67.5,
    "scanner_badge": "Caution",
    "findings": [
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 44% of skill content could be analyzed. 10 of 19 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/src/audienseClient.ts",
        "line_number": 24,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/src/audienseClient.ts",
        "line_number": 63,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/src/audienseClient.ts",
        "line_number": 162,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      }
    ],
    "execution_duration_seconds": 46.45276872300019,
    "status": "complete",
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
      "report_type": "cisco-skill-sast",
      "analyzers_used": [
        "bytecode",
        "pipeline",
        "static_analyzer"
      ],
      "skills_scanned": [
        "repo"
      ],
      "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
      "severity_counts": {
        "low": 1,
        "high": 1,
        "medium": 3,
        "critical": 0,
        "informational": 1
      }
    },
    "display_score": 67.5,
    "display_badge": "Caution"
  },
  {
    "scanner_name": "agent-audit-kit",
    "scanner_version": "0.3.26",
    "score": 36.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "agent-audit-kit",
        "severity": "low",
        "category": "supply-chain",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "AAK-SUPPLY-005",
        "title": "Dependency count exceeds threshold",
        "description": "More than 200 direct + transitive dependencies in lockfile. Each dependency is a trust decision.",
        "remediation": "Audit and remove unused dependencies. Consider lighter alternatives."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "low",
        "category": "supply-chain",
        "file_path": "SECURITY.md",
        "line_number": null,
        "rule_identifier": "AAK-SEC-MD-001",
        "title": "MCP server repo missing SECURITY.md or security_contact",
        "description": "A repository whose name or pyproject keywords declare it as an MCP server ships without a top-level SECURITY.md AND without a `security_contact` entry in marketplace.json / pyproject.toml / package.json. Anthropic's April 2026 SECURITY.md guidance makes this the baseline expectation so researchers have a channel.",
        "remediation": "Add SECURITY.md at the repo root with a disclosure email and response SLA; OR add `security_contact` to the project manifest."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "src/index.ts",
        "line_number": 3,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "src/audienseClient.ts",
        "line_number": null,
        "rule_identifier": "AAK-OAUTH-005",
        "title": "Bearer token used where DPoP or mTLS is required",
        "description": "An MCP remote server accepts plain Bearer tokens on a flow that MCP spec 2025-11-25 flags for DPoP (Demonstrating Proof of Possession) or mTLS-bound tokens. A stolen Bearer token is fully replayable.",
        "remediation": "Require DPoP proofs or mTLS-bound tokens for high-privilege flows. Validate the token's cnf claim."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "supply-chain",
        "file_path": "package.json",
        "line_number": 39,
        "rule_identifier": "AAK-OAUTH-3P-001",
        "title": "Repo depends on a third-party agent-platform SDK",
        "description": "The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel \u00d7 Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants.",
        "remediation": "Pin the SDK to an exact version, audit the OAuth scopes it requests, and keep any deployment-level grants (Vercel, GCP, Workspace) in a secrets vault \u2014 never in a committed env file. See Vercel's bulletin for sensitive-env-var guidance: https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": "src/index.ts",
        "line_number": null,
        "rule_identifier": "AAK-ANTHROPIC-SDK-001",
        "title": "MCP server built on the upstream SDK without STDIO sanitizer",
        "description": "Repository declares a dependency on the upstream Anthropic / ModelContextProtocol SDK (Python `mcp` / `modelcontextprotocol`, TS `@modelcontextprotocol/sdk`, Java `io.modelcontextprotocol:*`, Rust `mcp` / `modelcontextprotocol`) and exposes a STDIO transport (`StdioServerTransport`, `stdio_server`, etc.) without a sanitizer on argv assembly. Anthropic declined to CVE this as working as designed \u2014 sanitization is the developer's responsibility. The OX Security disclosure on 2026-04-15 rolled up L",
        "remediation": "Wrap every argv the STDIO transport builds in an allow-list sanitizer \u2014 `shlex.quote` in Python, `execFile` with an explicit argv array in Node, equivalent in Java/Rust. OR switch the transport off STDIO (`transports=['http']` / `['sse']`). If you have deliberately accepted the risk, add `accepts_stdio_risk: true` plus a `justification:` field in `.agent-audit-kit.yml`."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": "package.json",
        "line_number": null,
        "rule_identifier": "AAK-DNS-REBIND-002",
        "title": "Vulnerable MCP SDK version pinned (DNS-rebinding fix missing)",
        "description": "A project dependency manifest (requirements.txt, pyproject.toml, package.json, pom.xml, build.gradle) pins an MCP SDK at a version below the DNS-rebinding fix. Patched versions: Python `mcp` >= 1.23.0, TS `@modelcontextprotocol/sdk` >= 1.21.1, Java `io.modelcontextprotocol.sdk:mcp-core` >= 0.11.0, `@apollo/mcp-server` >= 1.7.0. Even if the project never serves over StreamableHTTP itself, transitive servers built on the SDK inherit the bug.",
        "remediation": "Bump the SDK to the patched version listed in the rule title. If a bump is not yet possible, ensure every transport surface has its own Host-header allow-list (see AAK-DNS-REBIND-001 remediation)."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "src/audienseClient.ts",
        "line_number": 138,
        "rule_identifier": "AAK-SPLUNK-TOKLOG-001",
        "title": "Session token written to log sink in cleartext",
        "description": "An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern \u2014 session tokens ended up in the Splunk `_internal` index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius.",
        "remediation": "Redact token-shaped values before logging. Never interpolate a raw `Authorization`, `Bearer`, JWT, `splunkd_session`, or `st-` credential into a log message. Pin `splunk-mcp-server >= 1.0.3`."
      }
    ],
    "execution_duration_seconds": 20.627035309997154,
    "status": "complete",
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
      "report_type": "agent-audit-kit-sast",
      "files_scanned": 18,
      "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
      "rules_evaluated": 211,
      "severity_counts": {
        "low": 2,
        "high": 3,
        "medium": 3,
        "critical": 0,
        "informational": 0
      }
    },
    "display_score": 36.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "bearer",
    "scanner_version": "2.0.2",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 17.776923343990347,
    "status": "complete",
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/Bearer/bearer",
      "report_type": "security",
      "rules_loaded": 1,
      "install_command": "curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh -s -- -b /usr/local/bin \"v2.0.2\""
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "nerlo-behavioral",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 53.4793492089957,
    "status": "complete",
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-behavioral",
      "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
      "files_scanned": 10,
      "install_command": "pip install 'semgrep==1.97.0'"
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "nerlo-install-instruction",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 51.75237492399174,
    "status": "complete",
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-install-instruction",
      "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
      "files_scanned": 2,
      "install_command": "pip install 'semgrep==1.97.0'"
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "trivy",
    "scanner_version": "0.71.0",
    "score": 24.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2025-66414",
        "title": "Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default",
        "description": "MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPServerTransport or SSEServerTransport and has not enabled enableDnsRebindingProtection, a malicious website could exploit DNS rebinding to bypass same-origin policy rest",
        "remediation": "Upgrade @modelcontextprotocol/sdk from 1.7.0 to 1.24.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-0621",
        "title": "Anthropic's MCP TypeScript SDK has a ReDoS vulnerability",
        "description": "Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quantifiers that can trigger catastrophic backtracking on specially crafted inputs, resulting in excessive CPU consumption. An attacker can exploit this by supplying a malicious URI that causes the Node.",
        "remediation": "Upgrade @modelcontextprotocol/sdk from 1.7.0 to 1.25.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-12590",
        "title": "body-parser: body-parser: Denial of Service via invalid limit option",
        "description": "Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars",
        "remediation": "Upgrade body-parser from 2.1.0 to 1.20.6, 2.3.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-4926",
        "title": "path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions",
        "description": "Impact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.",
        "remediation": "Upgrade path-to-regexp from 8.2.0 to 8.4.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-4923",
        "title": "path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards",
        "description": "Impact:\n\nWhen using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path.\n\nUnsafe examples:\n\n/*foo-*bar-:baz\n/*a-:b-*c-:d\n/x/*a-:b/*c/y\n\nSafe examples:\n\n/*foo-:bar\n/*foo-:bar-*baz\n\nPatches:\n\nUpgrade to version 8.4.0.\n\nWorkarounds:\n\nIf you are using multiple wildcard parameters, you can check the regex output with a too",
        "remediation": "Upgrade path-to-regexp from 8.2.0 to 8.4.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2025-15284",
        "title": "qs: qs: Denial of Service via improper input validation in array parsing",
        "description": "Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummary\n\nThe arrayLimit\u00a0option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit\u00a0should apply uniformly across all array notations.\n\nNote:\u00a0The default parameterLimit\u00a0of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la",
        "remediation": "Upgrade qs from 6.13.0 to 6.14.1 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-8723",
        "title": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...",
        "description": "### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti",
        "remediation": "Upgrade qs from 6.13.0 to 6.15.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-2391",
        "title": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
        "description": "### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?",
        "remediation": "Upgrade qs from 6.13.0 to 6.14.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2025-15284",
        "title": "qs: qs: Denial of Service via improper input validation in array parsing",
        "description": "Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummary\n\nThe arrayLimit\u00a0option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit\u00a0should apply uniformly across all array notations.\n\nNote:\u00a0The default parameterLimit\u00a0of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays la",
        "remediation": "Upgrade qs from 6.14.0 to 6.14.1 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-8723",
        "title": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...",
        "description": "### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti",
        "remediation": "Upgrade qs from 6.14.0 to 6.15.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "npm",
        "file_path": "package-lock.json",
        "line_number": null,
        "rule_identifier": "CVE-2026-2391",
        "title": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
        "description": "### Summary\nThe `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).\n\n### Details\nWhen the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?",
        "remediation": "Upgrade qs from 6.14.0 to 6.14.2 or later"
      }
    ],
    "execution_duration_seconds": 1.4423403189866804,
    "status": "complete",
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
      "report_type": "filesystem-vulnerability",
      "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
      "severity_counts": {
        "low": 3,
        "high": 3,
        "medium": 5,
        "critical": 0,
        "informational": 0
      },
      "manifests_scanned": [
        "package-lock.json"
      ]
    },
    "display_score": 24.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "osv-scanner",
    "scanner_version": "2.3.8",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-4x5r-pxfx-6jf8",
        "title": "GHSA-4x5r-pxfx-6jf8 \u2014 npm @babel/core@7.26.9",
        "description": "aliases: CVE-2026-49356, GHSA-4x5r-pxfx-6jf8 | CVSS: 3.2",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-8r9q-7v3j-jr4g",
        "title": "GHSA-8r9q-7v3j-jr4g \u2014 npm @modelcontextprotocol/sdk@1.7.0",
        "description": "aliases: CVE-2026-0621, GHSA-8r9q-7v3j-jr4g | CVSS: 8.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-w48q-cv73-mx4w",
        "title": "GHSA-w48q-cv73-mx4w \u2014 npm @modelcontextprotocol/sdk@1.7.0",
        "description": "aliases: CVE-2025-66414, GHSA-w48q-cv73-mx4w | CVSS: 7.6",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-v422-hmwv-36x6",
        "title": "GHSA-v422-hmwv-36x6 \u2014 npm body-parser@2.1.0",
        "description": "aliases: CVE-2026-12590, GHSA-v422-hmwv-36x6 | CVSS: 3.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-3jxr-9vmj-r5cp",
        "title": "GHSA-3jxr-9vmj-r5cp \u2014 npm brace-expansion@1.1.11",
        "description": "aliases: CVE-2026-13149, GHSA-3jxr-9vmj-r5cp | CVSS: 7.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-f886-m6hf-6m8v",
        "title": "GHSA-f886-m6hf-6m8v \u2014 npm brace-expansion@1.1.11",
        "description": "aliases: CVE-2026-33750, GHSA-f886-m6hf-6m8v | CVSS: 6.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-v6h2-p8h4-qcjw",
        "title": "GHSA-v6h2-p8h4-qcjw \u2014 npm brace-expansion@1.1.11",
        "description": "aliases: CVE-2025-5889, GHSA-v6h2-p8h4-qcjw | CVSS: 3.1",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-3jxr-9vmj-r5cp",
        "title": "GHSA-3jxr-9vmj-r5cp \u2014 npm brace-expansion@2.0.1",
        "description": "aliases: CVE-2026-13149, GHSA-3jxr-9vmj-r5cp | CVSS: 7.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-f886-m6hf-6m8v",
        "title": "GHSA-f886-m6hf-6m8v \u2014 npm brace-expansion@2.0.1",
        "description": "aliases: CVE-2026-33750, GHSA-f886-m6hf-6m8v | CVSS: 6.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-v6h2-p8h4-qcjw",
        "title": "GHSA-v6h2-p8h4-qcjw \u2014 npm brace-expansion@2.0.1",
        "description": "aliases: CVE-2025-5889, GHSA-v6h2-p8h4-qcjw | CVSS: 3.1",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-52cp-r559-cp3m",
        "title": "GHSA-52cp-r559-cp3m \u2014 npm js-yaml@3.14.1",
        "description": "aliases: CVE-2026-59869, GHSA-52cp-r559-cp3m | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-h67p-54hq-rp68",
        "title": "GHSA-h67p-54hq-rp68 \u2014 npm js-yaml@3.14.1",
        "description": "aliases: CVE-2026-53550, GHSA-h67p-54hq-rp68 | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-mh29-5h37-fv8m",
        "title": "GHSA-mh29-5h37-fv8m \u2014 npm js-yaml@3.14.1",
        "description": "aliases: CVE-2025-64718, GHSA-mh29-5h37-fv8m | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-23c5-xmqv-rm74",
        "title": "GHSA-23c5-xmqv-rm74 \u2014 npm minimatch@3.1.2",
        "description": "aliases: CVE-2026-27904, GHSA-23c5-xmqv-rm74 | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-3ppc-4f35-3m26",
        "title": "GHSA-3ppc-4f35-3m26 \u2014 npm minimatch@3.1.2",
        "description": "aliases: CVE-2026-26996, GHSA-3ppc-4f35-3m26 | CVSS: 8.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-7r86-cg39-jmmj",
        "title": "GHSA-7r86-cg39-jmmj \u2014 npm minimatch@3.1.2",
        "description": "aliases: CVE-2026-27903, GHSA-7r86-cg39-jmmj | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-23c5-xmqv-rm74",
        "title": "GHSA-23c5-xmqv-rm74 \u2014 npm minimatch@5.1.6",
        "description": "aliases: CVE-2026-27904, GHSA-23c5-xmqv-rm74 | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-3ppc-4f35-3m26",
        "title": "GHSA-3ppc-4f35-3m26 \u2014 npm minimatch@5.1.6",
        "description": "aliases: CVE-2026-26996, GHSA-3ppc-4f35-3m26 | CVSS: 8.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-7r86-cg39-jmmj",
        "title": "GHSA-7r86-cg39-jmmj \u2014 npm minimatch@5.1.6",
        "description": "aliases: CVE-2026-27903, GHSA-7r86-cg39-jmmj | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-27v5-c462-wpq7",
        "title": "GHSA-27v5-c462-wpq7 \u2014 npm path-to-regexp@8.2.0",
        "description": "aliases: CVE-2026-4923, GHSA-27v5-c462-wpq7 | CVSS: 5.9",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-j3q9-mxjg-w52f",
        "title": "GHSA-j3q9-mxjg-w52f \u2014 npm path-to-regexp@8.2.0",
        "description": "aliases: CVE-2026-4926, GHSA-j3q9-mxjg-w52f | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-3v7f-55p6-f55p",
        "title": "GHSA-3v7f-55p6-f55p \u2014 npm picomatch@2.3.1",
        "description": "aliases: CVE-2026-33672, GHSA-3v7f-55p6-f55p | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-c2c7-rcm5-vvqj",
        "title": "GHSA-c2c7-rcm5-vvqj \u2014 npm picomatch@2.3.1",
        "description": "aliases: CVE-2026-33671, GHSA-c2c7-rcm5-vvqj | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-6rw7-vpxm-498p",
        "title": "GHSA-6rw7-vpxm-498p \u2014 npm qs@6.13.0",
        "description": "aliases: CVE-2025-15284, GHSA-6rw7-vpxm-498p | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-q8mj-m7cp-5q26",
        "title": "GHSA-q8mj-m7cp-5q26 \u2014 npm qs@6.13.0",
        "description": "aliases: CVE-2026-8723, GHSA-q8mj-m7cp-5q26 | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-w7fw-mjwx-w883",
        "title": "GHSA-w7fw-mjwx-w883 \u2014 npm qs@6.13.0",
        "description": "aliases: CVE-2026-2391, GHSA-w7fw-mjwx-w883 | CVSS: 3.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-6rw7-vpxm-498p",
        "title": "GHSA-6rw7-vpxm-498p \u2014 npm qs@6.14.0",
        "description": "aliases: CVE-2025-15284, GHSA-6rw7-vpxm-498p | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-q8mj-m7cp-5q26",
        "title": "GHSA-q8mj-m7cp-5q26 \u2014 npm qs@6.14.0",
        "description": "aliases: CVE-2026-8723, GHSA-q8mj-m7cp-5q26 | CVSS: 6.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "npm",
        "file_path": "/repo/package-lock.json",
        "line_number": null,
        "rule_identifier": "GHSA-w7fw-mjwx-w883",
        "title": "GHSA-w7fw-mjwx-w883 \u2014 npm qs@6.14.0",
        "description": "aliases: CVE-2026-2391, GHSA-w7fw-mjwx-w883 | CVSS: 3.7",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 33.63341563398717,
    "status": "complete",
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
      "report_type": "osv-vulnerability",
      "ecosystems_seen": [
        "npm"
      ],
      "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
      "severity_counts": {
        "low": 6,
        "high": 13,
        "medium": 10,
        "critical": 0,
        "informational": 0
      },
      "manifests_scanned": [
        "/repo/package-lock.json"
      ],
      "finding_id_aliases": {
        "GHSA-23c5-xmqv-rm74": [
          "CVE-2026-27904",
          "CVE-2026-27904"
        ],
        "GHSA-27v5-c462-wpq7": [
          "CVE-2026-4923"
        ],
        "GHSA-3jxr-9vmj-r5cp": [
          "CVE-2026-13149",
          "CVE-2026-13149"
        ],
        "GHSA-3ppc-4f35-3m26": [
          "CVE-2026-26996",
          "CVE-2026-26996"
        ],
        "GHSA-3v7f-55p6-f55p": [
          "CVE-2026-33672"
        ],
        "GHSA-4x5r-pxfx-6jf8": [
          "CVE-2026-49356"
        ],
        "GHSA-52cp-r559-cp3m": [
          "CVE-2026-59869"
        ],
        "GHSA-6rw7-vpxm-498p": [
          "CVE-2025-15284",
          "CVE-2025-15284"
        ],
        "GHSA-7r86-cg39-jmmj": [
          "CVE-2026-27903",
          "CVE-2026-27903"
        ],
        "GHSA-8r9q-7v3j-jr4g": [
          "CVE-2026-0621"
        ],
        "GHSA-c2c7-rcm5-vvqj": [
          "CVE-2026-33671"
        ],
        "GHSA-f886-m6hf-6m8v": [
          "CVE-2026-33750",
          "CVE-2026-33750"
        ],
        "GHSA-h67p-54hq-rp68": [
          "CVE-2026-53550"
        ],
        "GHSA-j3q9-mxjg-w52f": [
          "CVE-2026-4926"
        ],
        "GHSA-mh29-5h37-fv8m": [
          "CVE-2025-64718"
        ],
        "GHSA-q8mj-m7cp-5q26": [
          "CVE-2026-8723",
          "CVE-2026-8723"
        ],
        "GHSA-v422-hmwv-36x6": [
          "CVE-2026-12590"
        ],
        "GHSA-v6h2-p8h4-qcjw": [
          "CVE-2025-5889",
          "CVE-2025-5889"
        ],
        "GHSA-w48q-cv73-mx4w": [
          "CVE-2025-66414"
        ],
        "GHSA-w7fw-mjwx-w883": [
          "CVE-2026-2391",
          "CVE-2026-2391"
        ]
      },
      "cross_scanner_correlation": {
        "only_osv": [
          "GHSA-23c5-xmqv-rm74",
          "GHSA-3jxr-9vmj-r5cp",
          "GHSA-3ppc-4f35-3m26",
          "GHSA-3v7f-55p6-f55p",
          "GHSA-4x5r-pxfx-6jf8",
          "GHSA-52cp-r559-cp3m",
          "GHSA-7r86-cg39-jmmj",
          "GHSA-c2c7-rcm5-vvqj",
          "GHSA-f886-m6hf-6m8v",
          "GHSA-h67p-54hq-rp68",
          "GHSA-mh29-5h37-fv8m",
          "GHSA-v6h2-p8h4-qcjw"
        ],
        "only_trivy": [],
        "intersection_ids": [
          "CVE-2025-15284",
          "CVE-2025-66414",
          "CVE-2026-0621",
          "CVE-2026-12590",
          "CVE-2026-2391",
          "CVE-2026-4923",
          "CVE-2026-4926",
          "CVE-2026-8723"
        ]
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  }
]
```
