The `AssetServerPlugin` serves assets (images and other files) from the local file system. It can also perform on-the-fly image transformations and caches the results for subsequent calls.
89%
Total Score
68
100
100
90
88
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10365 @vendure/asset-server-plugin is vulnerable to Directory Traversal in versions 0.0.1 - 2.3.2 and 3.0.0 - 3.0.4. | 0.0.1 - 2.3.23.0.0 - 3.0.4 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
sharp Version ~0.34.5 | — | — |
fs-extra Version ^11.2.0 | — | — |
file-type Version ^19.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant