Automated semver compliant package publishing
91%
Total Score
100
43
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-54614 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. semantic-release is vulnerable to Code Injection in versions 13.1.0 - 25.0.7. | 13.1.0 - 25.0.7 | Medium |
AIKIDO-2026-773803 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. semantic-release is vulnerable to Argument Injection in versions 13.0.0 - 25.0.6. | 13.0.0 - 25.0.6 | Medium |
AIKIDO-2026-305929 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. semantic-release is vulnerable to Exposure of Sensitive Information in versions 19.0.3 - 25.0.5. | 19.0.3 - 25.0.5 | Medium |
CVE-2022-31051 semantic-release is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 17.0.4 - 19.0.3. | 17.0.4 - 19.0.3 | Medium |
CVE-2020-26226 semantic-release is vulnerable to Improper Encoding or Escaping of Output in versions 0.0.0 - 17.2.2. | 0.0.0 - 17.2.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
debug Version ^4.0.0 | — | — |
execa Version ^9.0.0 | — | — |
yargs Version ^18.0.0 | — | — |
env-ci Version ^11.0.0 | — | — |
marked Version ^15.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant