🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: agent_ui
Branch: feature/generaling-ui
Build: #174
Date: 2026-03-12 21:03:03

0

Critical

9

High

0

Medium

0

Low

59

Secrets

1

Misconfig

🔴 Vulnerabilities (8)
SeverityCVE IDPackageInstalledFixed InDescription
HIGH CVE-2022-0235 node-fetch 2.1.2 3.1.1, 2.6.7 node-fetch: exposure of sensitive information to an unauthorized actor
HIGH CVE-2024-4367 pdfjs-dist 3.11.174 4.2.67 Mozilla: Arbitrary JavaScript execution in PDF.js
HIGH CVE-2026-23745 tar 6.2.1 7.5.3 node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in
HIGH CVE-2026-23950 tar 6.2.1 7.5.4 node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition
HIGH CVE-2026-24842 tar 6.2.1 7.5.7 node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security chec
HIGH CVE-2026-26960 tar 6.2.1 7.5.8 tar: node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation
HIGH CVE-2026-29786 tar 6.2.1 7.5.10 node-tar: hardlink path traversal via drive-relative linkpath
HIGH CVE-2026-31802 tar 6.2.1 7.5.11 tar: tar: File overwrite via drive-relative symlink traversal
🔑 Secrets (59)
TypeFileLineMatch
AWS security-reports/gitleaks-report.json 156 "Match": "********************",...
AWS security-reports/gitleaks-report.json 157 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 219 "Match": "********************",...
AWS security-reports/gitleaks-report.json 220 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 534 "Match": "********************",...
AWS security-reports/gitleaks-report.json 535 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 576 "Match": "********************",...
AWS security-reports/gitleaks-report.json 577 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 681 "Match": "********************",...
AWS security-reports/gitleaks-report.json 682 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 723 "Match": "********************",...
AWS security-reports/gitleaks-report.json 724 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 954 "Match": "********************",...
AWS security-reports/gitleaks-report.json 955 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1227 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1228 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1290 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1291 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1353 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1354 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1416 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1417 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1479 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1480 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1542 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1543 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1605 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1606 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1668 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1669 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1731 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1732 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1794 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1795 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1857 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1858 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 1920 "Match": "********************",...
AWS security-reports/gitleaks-report.json 1921 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2004 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2005 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2046 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2047 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2109 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2110 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2172 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2173 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2235 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2236 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2298 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2299 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2361 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2362 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2445 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2446 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2487 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2488 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 2550 "Match": "********************",...
AWS security-reports/gitleaks-report.json 2551 "Secret": "********************",...
AWS src/services/AwsService.ts 6 accessKeyId: "********************",...
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)