Extensible JavaScript file upload widget with support for drag&drop, resumable uploads, previews, restrictions, file processing/encoding, remote providers like Instagram, Dropbox, Google Drive, S3 and more :dog:
82%
Total Score
60
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10443 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. uppy is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.27.0 - 4.6.0. | 0.27.0 - 4.6.0 | Low |
AIKIDO-2024-10409 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. uppy is vulnerable to Overly Permissive Cross-domain Whitelist in versions 3.5.0 - 4.5.0. | 3.5.0 - 4.5.0 | Low |
CVE-2022-0086 uppy is vulnerable to Server-Side Request Forgery (SSRF). | — | High |
| Dependency | Last Release | Score |
|---|---|---|
@uppy/box Version 4.1.0 | — | — |
@uppy/tus Version 5.1.1 | — | — |
@uppy/url Version 5.1.0 | — | — |
@uppy/core Version 5.2.0 | — | — |
@uppy/form Version 5.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant