Creates CycloneDX Software Bill of Materials (SBOM) from source or container image
93%
Total Score
63
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10556 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @cyclonedx/cdxgen is vulnerable to OS command execution in versions 11.4.2 - 12.2.0. | 11.4.2 - 12.2.0 | High |
CVE-2024-50611 @cyclonedx/cdxgen is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 11.1.7. | 0.0.0 - 11.1.7 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ajv Version 8.20.0 | — | — |
got Version 14.6.6 | — | — |
tar Version 7.5.15 | — | — |
glob Version 13.0.6 | — | — |
keyv Version 5.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant