pypi package report

Is node-forge safe?

1 known vulnerability.

cvss
not scored

how bad it is if exploited, out of 10

epss
not scored

chance of exploitation in the next 30 days

xyz score
2.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-5rrq-pxf6-6jx5, the advisory selected below

// advisories

GHSA-5rrq-pxf6-6jx5

UNKNOWN

The forge.debug API had a potential prototype pollution issue if called with untrusted input. The API was only used for internal debug purposes in a safe way and never documented or advertised. It is suspected that uses of this API, if any exist, would likely not have used untrusted inputs in a vulnerable way.

Affected
>=0, <1.0.0
Fixed in
not stated
Weakness
CWE-1321
Published
2022-01-08
Source
osv

OSV


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 01:38 UTC. The most recent advisory here was published 2022-01-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is node-forge safe? pypi package security report | CyberXYZ