corvus is vulnerable to Incorrect Default Permissions
28
Low Risk
Affected versions of this package did not consistently enforce restrictive permissions on configuration files, allowing them to be created or saved with overly permissive access rights. On multi-user Unix systems, this could expose sensitive data stored in configuration files—such as API keys, tokens, or credentials—to other local users. An attacker with local access could read these improperly protected files and extract secrets to gain unauthorized access to services or escalate privileges within the environment.
You are affected if you are using a version that falls within the vulnerable range.
corvus is vulnerable to Incorrect Default Permissions in versions 0.1.0 - 0.1.3.
Upgrade the corvus library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant