@paperclipai/shared is vulnerable to Denial of Service (DoS)
50
Medium Risk
Issue-related validators accept a request-depth style parameter used while traversing linked issue graphs. Before the fix extremely large values could force disproportionate work during validation or downstream fan-out. The patch clamps the parameter to a fixed maximum and extends tests so pathological depth inputs cannot be used to exhaust CPU or stall request handling.
You are affected if you are using a version that falls within the vulnerable range.
@paperclipai/shared is vulnerable to Denial of Service (DoS) in versions 2026.318.0 - 2026.416.0.
Upgrade the @paperclipai/shared library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant