A zero-dependency alternative to cosmiconfig
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2024-21537 lilconfig is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 3.1.0 - 3.1.1. | 3.1.0 - 3.1.1 | High |
AIKIDO-2024-10001 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. lilconfig is vulnerable to Code Injection in versions 3.1.0 - 3.1.0. | 3.1.0 - 3.1.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant