npm package report

Is @tak-ps/cloudtak safe?

2 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
not scored

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-r95q-fp26-h3hc, the advisory selected below

// advisories

GHSA-r95q-fp26-h3hc

HIGHCVE-2026-55177

Every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the portal / server / layer query parameters on the GET /api/esri/ routes) and passes it into EsriBase / EsriProxyPortal / EsriProxyServer / EsriProxyLayer in api/lib/esri.ts, which fetch it with the bare fetch from @tak-ps/etl. No IP / DNS / hostname clas

Affected
>=0, <13.10.0, < 13.10.0
Fixed in
13.10.0
Weakness
CWE-918
Published
2026-07-17
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 03:30 UTC. The most recent advisory here was published 2026-07-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @tak-ps/cloudtak safe? npm package security report | CyberXYZ