Core components for Microsoft Bot Builder. Components in this library can run either in a browser or on the server.
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10612 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. botbuilder-core is vulnerable to Path Traversal in versions 4.0.8 - 4.23.2. | 4.0.8 - 4.23.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^3.23.8 | — | — |
uuid Version ^10.0.0 | — | — |
botbuilder-stdlib Version 4.23.3-internal | — | — |
botframework-schema Version 4.23.3 | — | — |
botframework-connector Version 4.23.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant