Cube API Gateway
92%
Total Score
62
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10598 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @cubejs-backend/api-gateway is vulnerable to Generation of Error Message Containing Sensitive Information in versions 0.30.0 - 1.3.60. | 0.30.0 - 1.3.60 | Low |
CVE-2023-50709 @cubejs-backend/api-gateway is vulnerable to Improper Input Validation in versions 0.0.0 - 0.34.34. | 0.0.0 - 0.34.34 | Medium |
CVE-2022-23510 @cubejs-backend/api-gateway is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.31.23 - 0.31.23. | 0.31.23 - 0.31.23 | High |
| Dependency | Last Release | Score |
|---|---|---|
joi Version ^17.13.3 | — | — |
zod Version ^4.1.13 | — | — |
uuid Version ^8.3.2 | — | — |
nexus Version ^1.1.0 | — | — |
ramda Version ^0.27.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant