aikido intel logoPowered by AI + Aikido Research Team

Aikido Threat Intelligence

Your earliest warning for supply chain threats. We expose malware and vulnerabilities in open-source ecosystems, within minutes.

Most Recent

Medium
21 hours ago

@cap-js/hana is vulnerable to Denial of Service (DoS)

Upgrade the @cap-js/hana library to the patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10172
High
21 hours ago

strapi-plugin-comments is vulnerable to Cross-site Scripting (XSS)

Upgrade the strapi-plugin-comments library to the patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10171
Low
21 hours ago

github.com/external-secrets/external-secrets is vulnerable to Generation of Error Message Containing Sensitive Information

Upgrade the github.com/external-secrets/external-secrets library to a patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10170
Low
21 hours ago

taskiq-redis is vulnerable to Denial of Service (DoS)

Upgrade the taskiq-redis library to the patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10169
Medium
21 hours ago

openhands-sdk is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Upgrade the openhands-sdk library to the patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10168
High
21 hours ago

directorytree/imapengine is vulnerable to Command injection

Upgrade the directorytree/imapengine library to the patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10167
High
21 hours ago

eclipse-threadx.threadx is vulnerable to Incorrect Check of Function Return Value

Upgrade the eclipse-threadx.threadx library to the patch version.

CVE-2026-0648AIKIDO-2026-10166
Critical
21 hours ago

@enspirit/elo is vulnerable to Code Injection

Upgrade the @enspirit/elo library to the patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10165
High
21 hours ago

sigs.k8s.io/azurefile-csi-driver is vulnerable to Dependency on Vulnerable Third-Party Component

Upgrade the sigs.k8s.io/azurefile-csi-driver library to a patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10164
High
21 hours ago

@nx/workspace is vulnerable to Command Injection

Upgrade the @nx/workspace library to the patch version.

Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
AIKIDO-2026-10163

Protect yourself from malware upon install with Aikido Safe Chain (open source)

Install Safe Chain

Search and Compare Health
of Open-Source Packages.

Make confident, secure choices for your next build.

Go to Package Health
Packagist
NPM
PyPi

Our Intel, Your Security

Open source

Open Source

Aikido Intel is available under AGPL license, developers may freely use, modify, and distribute the vulnerability & malware feed.

Contribute to Intel
License the intel database

License the Intel Database

Want to integrate our threat intelligence into your product? Get access through our commercial API.

Get Access

Get Secure Now

Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.

Get Secure