A modern, headless ecommerce framework
90%
Total Score
100
31
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-83521 @vendure/core is vulnerable to Insecure Direct Object Reference (IDOR) in versions 1.0.0 - 3.7.1. | 1.0.0 - 3.7.1 | Medium |
AIKIDO-2026-765852 @vendure/core is vulnerable to Insecure Direct Object Reference (IDOR) in versions 0.0.1 - 3.7.1. | 0.0.1 - 3.7.1 | Medium |
AIKIDO-2026-893927 @vendure/core is vulnerable to Privilege Escalation in versions 0.0.1 - 3.7.1. | 0.0.1 - 3.7.1 | Critical |
AIKIDO-2026-723703 @vendure/core is vulnerable to Broken Access Control in versions 1.8.0 - 3.7.1. | 1.8.0 - 3.7.1 | High |
AIKIDO-2026-11013 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @vendure/core is vulnerable to Server-side Request Forgery (SSRF) in versions 1.0.0 - 3.6.3. | 1.0.0 - 3.6.3 | High |
| Dependency | Last Release | Score |
|---|---|---|
ms Version ^2.1.3 | — | — |
rxjs Version ^7.8.1 | — | — |
bcrypt Version ^6.0.0 | — | — |
croner Version ^10.0.1 | — | — |
nanoid Version ^3.3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant