sbomtriageExample
Example workspace. A real scan of a polyglot monorepo with 20 real packages across npm, PyPI, Go, Cargo, NuGet and RubyGems, saved on 2026-09-30. It’s read-only, so nothing here changes a real project.Scan your own software

example-monorepo

grade C · last checked 5 days ago · 1 recent history entry
Example report
181 of 181
TierAdvisoryComponentCVSSEPSSFixSeen
Fix now
Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection
django
3.2.0
9.873.6%3.2.14—
Fix now
Nokogiri affected by zlib's Out-of-bounds Write vulnerability
nokogiri
1.11.0
7.551.7%1.13.4—
Fix now
Resource exhaustion in Django
django
3.2.0
7.562.6%3.2.18—
Fix soon
Possible shell escape sequence injection vulnerability in Rack
rack
2.2.3
101.9%2.2.3.1—
Fix soon
Improper Input Validation in PyYAML
pyyaml
5.3.1
9.86.0%5.4—
Fix soon
Buffer overflow in SmallVec::insert_many
smallvec
1.6.0
9.81.7%1.6.1—
Fix soon
.NET Core Remote Code Execution Vulnerability
System.Text.Encodings.Web
4.7.1
9.830.1%4.7.2—
Fix soon
SQL Injection in Django
django
3.2.0
9.844.4%3.2.5—
Fix soon
SQL Injection in Django
django
3.2.0
9.818.7%3.2.13—
Fix soon
SQL Injection in Django
django
3.2.0
9.82.9%3.2.13—
Fix soon
ejs template injection vulnerability
ejs
3.1.6
9.832.8%3.1.7—
Fix soon
Django bypasses validation when using one form field to upload multiple files
django
3.2.0
9.81.4%3.2.19—
Fix soon
Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
traverse
7.20.0
9.30.5%7.23.2—
Fix soon
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
django
3.2.0
9.119.4%4.2.26—
Fix soon
Nokogiri has vulnerable dependencies on libxml2 and libxslt
nokogiri
1.11.0
8.817.6%1.13.2—
Fix soon
Nokogiri Implements libxml2 version vulnerable to use-after-free
nokogiri
1.11.0
8.821.9%1.11.4—
Fix soon
Django vulnerable to Reflected File Download attack
django
3.2.0
8.80.9%3.2.15—
Fix soon
Nokogiri contains libxml Out-of-bounds Write vulnerability
nokogiri
1.11.0
8.617.0%1.11.4—
Fix soon
Integer Overflow or Wraparound in libxml2 affects Nokogiri
nokogiri
1.11.0
8.6—1.13.5—
Fix soon
axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
axios
0.21.1
8.60.8%0.32.0—
Fix soon
Nokogiri Improperly Handles Unexpected Data Type
nokogiri
1.11.0
8.23.2%1.13.6—
Fix soon
Command Injection in lodash
lodash
4.17.15
8.121.3%4.17.21—
Fix soon
`Cookie` HTTP header isn't stripped on cross-origin redirects
urllib3
1.25.8
8.11.2%1.26.17—
Fix soon
Jinja has a sandbox breakout through indirect reference to format method
jinja2
2.11.2
7.80.5%3.1.5—
Fix soon
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
nokogiri
1.11.0
7.8—1.18.4—

Read-only example. Scan your software to record triage decisions.

Muting takes a finding out of the plan and the grade, and needs a reason. The reason is shown here, in the report and in every export, so anyone reading the grade can see what was left out and disagree.