Core libraries to interact with SFDX projects, orgs, and APIs.
91%
Total Score
100
60
100
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-55673 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @salesforce/core is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.16.10 - 8.32.2. | 0.16.10 - 8.32.2 | Medium |
AIKIDO-2026-10220 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @salesforce/core is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 8.25.1. | 0.0.1 - 8.25.1 | Low |
| Dependency | Last Release | Score |
|---|---|---|
ajv Version ^8.18.0 | — | — |
zod Version ^4.1.12 | — | — |
faye Version ^1.4.1 | — | — |
pino Version ^9.7.0 | — | — |
jszip Version 3.10.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant