Sandbox for Postman Scripts to run in Node.js or browser
88%
Total Score
88
100
100
67
50
No build attestation or trusted-publisher provenance is provided, leaving publication origin less transparent despite the package's otherwise strong maintenance evidence.
Three pull requests were opened in the last month, but none were merged and there were no new or closed issues; this is a minor activity concern, offset by recent commits and releases.
No repository security policy is present, leaving disclosure and response expectations undocumented.
Both workflows were analyzed without high-confidence findings or untrusted checkouts, but all 10 action references are unpinned; the absence of a top-level permissions block is acceptable here and no broad write access is reported.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10136 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. postman-sandbox is vulnerable to Sandbox Escape in versions 0.0.0 - 4.1.5. | 0.0.0 - 4.1.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
uvm Version 4.0.2 | — | — |
lodash Version 4.18.1 | — | — |
postman-collection Version 5.3.1 | — | — |
teleport-javascript Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.