🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: AI Therapist Security Scan
Branch: feature/memory_unplugging
Build: #136
Date: 2026-02-23 15:27:07

0

Critical

7

High

1

Medium

0

Low

2

Secrets

0

Misconfig

🔴 Vulnerabilities (8)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2026-2739 bn.js 4.12.3 5.2.3 bn.js: bn.js: Denial of Service via calling maskn(0)
HIGH CVE-2026-26996 minimatch 3.1.3 10.2.1 minimatch: minimatch: Denial of Service via specially crafted glob patterns
HIGH CVE-2022-0235 node-fetch 2.1.2 3.1.1, 2.6.7 node-fetch: exposure of sensitive information to an unauthorized actor
HIGH CVE-2024-4367 pdfjs-dist 3.11.174 4.2.67 Mozilla: Arbitrary JavaScript execution in PDF.js
HIGH CVE-2026-23745 tar 6.2.1 7.5.3 node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in
HIGH CVE-2026-23950 tar 6.2.1 7.5.4 node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition
HIGH CVE-2026-24842 tar 6.2.1 7.5.7 node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security chec
HIGH CVE-2026-26960 tar 6.2.1 7.5.8 tar: node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation
🔑 Secrets (2)
TypeFileLineMatch
AWS security-reports/gitleaks-report.json 72 "Match": "********************",...
AWS security-reports/gitleaks-report.json 73 "Secret": "********************",...
⚙️ Misconfigurations (0)
SeverityIDCheckFileMessage
✅ No misconfigurations found
📄 Raw JSON Report (click to expand)