🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: platfrom_ui
Branch: feature/vulnerabilities-scan
Build: #80
Date: 2026-02-13 16:02:43

0

Critical

7

High

7

Medium

0

Low

0

Secrets

5

Misconfig

🔴 Vulnerabilities (9)
SeverityCVE IDPackageInstalledFixed InDescription
HIGH CVE-2020-8203 lodash 4.17.14 4.17.19 nodejs-lodash: prototype pollution in zipObjectDeep function
HIGH CVE-2021-23337 lodash 4.17.14 4.17.21 nodejs-lodash: command injection via template
MEDIUM CVE-2020-28500 lodash 4.17.14 4.17.21 nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions
MEDIUM CVE-2025-13465 lodash 4.17.14 4.17.23 lodash: prototype pollution in _.unset and _.omit functions
HIGH CVE-2021-3803 nth-check 1.0.2 2.0.1 nodejs-nth-check: inefficient regular expression complexity
MEDIUM CVE-2023-44270 postcss 7.0.39 8.4.31 PostCSS: Improper input validation in PostCSS
MEDIUM CVE-2021-3163 quill 1.3.7 No fix Cross-site Scripting in quill
MEDIUM CVE-2025-30359 webpack-dev-server 4.15.2 5.2.1 webpack-dev-server: webpack-dev-server information exposure
MEDIUM CVE-2025-30360 webpack-dev-server 4.15.2 5.2.1 webpack-dev-server: webpack-dev-server information exposure
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (5)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
MEDIUM DS-0001 ':latest' tag used node_modules/@surma/rollup-plugin-off-main-thread/Dockerfile Specify a tag in the 'FROM' statement for image 'selenium/node-chrome'
HIGH DS-0002 Image user should not be 'root' node_modules/@surma/rollup-plugin-off-main-thread/Dockerfile Last USER command in Dockerfile should not be 'root'
HIGH DS-0017 'RUN update' instruction alone node_modules/@surma/rollup-plugin-off-main-thread/Dockerfile The instruction 'RUN update' should always be followed by ' insta
HIGH DS-0002 Image user should not be 'root' node_modules/jsonpath/Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)