A client to interact with Keycloak's Administration API
94%
Total Score
100
78
100
100
0
| Title | Versions | Severity |
|---|---|---|
CVE-2026-2366 @keycloak/keycloak-admin-client is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.0 - 26.5.5. | 0.0.0 - 26.5.5 | Low |
AIKIDO-2025-10335 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @keycloak/keycloak-admin-client is vulnerable to Improper Authentication in versions 12.0.0 - 26.2.4. | 12.0.0 - 26.2.4 | Low |
| Dependency | Last Release | Score |
|---|---|---|
camelize-ts Version ^3.0.0 | — | — |
url-template Version ^3.1.1 | — | — |
@microsoft/kiota-abstractions Version 1.0.0-preview.103 | — | — |
@microsoft/kiota-http-fetchlibrary Version 1.0.0-preview.103 | — | — |
@microsoft/kiota-serialization-form Version 1.0.0-preview.103 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.