keystonejs
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 14 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 24, 2017 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →@keystone-6/core: `isFilterable` bypass via `cursor` parameter in findMany
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Conditionally missing authorization in @keystone-6/core
@keystone-6/auth Open Redirect vulnerability
NODE_ENV in Keystone defaults to development with esbuild
@keystone-6/core vulnerable to field-level access-control bypass for multiselect field
Cross-site Scripting (XSS) - Reflected in keystonejs/keystone
Private Field data leak
Monitor keystonejs in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.