Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
cvss
0.0
medium
severity band, no base score published
epss
not scored
chance of exploitation in 30 days
xyz score
not scored
CyberXYZ composite out of 10
fig. 01 — GHSA-83rx-c8cr-6j8q, the advisory selected below
// 1 advisories
GHSA-83rx-c8cr-6j8q
MODERATE
Versions of tesseract.js prior to 1.0.19 default to using a third-party proxy. Requests may be proxied through crossorigin.me which clearly states is not suitable for production use. This may lead to instability and privacy violations.
// recommendation
Upgrade to version 1.0.19 or later.
// cvss v3.1 vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Checked 2026-10-04 at 01:13 UTC. The most recent advisory here was published 2019-06-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.