OAuth helper and remote fetcher for Uppy's (https://uppy.io) extensible file upload widget with support for drag&drop, resumable uploads, previews, restrictions, file processing/encoding, remote providers like Dropbox and Google Drive, S3 and more :dog:
72%
Total Score
10
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10315 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @uppy/companion is vulnerable to AES Key Wear-out in versions 0.0.1 - 5.6.0. | 0.0.1 - 5.6.0 | Low |
CVE-2022-0528 @uppy/companion is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 3.3.1. | 0.0.0 - 3.3.1 | High |
CVE-2020-8135 @uppy/companion is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 1.9.3. | 0.0.0 - 1.9.3 | Critical |
CVE-2020-8205 @uppy/companion is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 1.13.2 and 2.0.0-alpha.0 - 2.0.0-alpha.4. | 0.0.0 - 1.13.22.0.0-alpha.0 - 2.0.0-alpha.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
ms Version 2.1.3 | — | — |
ws Version 8.17.1 | — | — |
got Version ^13.0.0 | — | — |
cors Version ^2.8.5 | — | — |
grant Version ^5.4.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant