---
type: "firecrawl-provider"
description: "OSV.dev, Google's open source vulnerability database (api.osv.dev), keyless: known vulnerabilities for a package version, purl or Git commit across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more; batch checks of up to 100 dependencies; and full OSV records by OSV, GHSA or CVE id. Every record carries its source database (GitHub Advisory Database, PyPI, Go, RustSec, NVD, Debian, ...) and licence for attribution."
use_when: "OSV.dev, Google's open source vulnerability database (api.osv.dev), keyless: known vulnerabilities for a package version, purl or Git commit across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more; batch checks of up to 100 dependencies; and full OSV records by OSV, GHSA or CVE id. Every record carries its source database (GitHub Advisory Database, PyPI, Go, RustSec, NVD, Debian, ...) and licence for attribution."
categories: "Developer"
capabilities: 3
credits_per_call: 5
---
# OSV.dev open source vulnerabilities on Firecrawl Alexandria

OSV.dev, Google's open source vulnerability database (api.osv.dev), keyless: known vulnerabilities for a package version, purl or Git commit across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more; batch checks of up to 100 dependencies; and full OSV records by OSV, GHSA or CVE id. Every record carries its source database (GitHub Advisory Database, PyPI, Go, RustSec, NVD, Debian, ...) and licence for attribution.

- Categories: Developer
- Category index: [Developer category](https://firecrawl.dev/alexandria/agents/categories/developer)
- Provider key: `osv-dev`
- Access: Firecrawl credits
- Cost: 5 credits per call

## More

- [Human guide](https://firecrawl.dev/app/alexandria/osv-dev)
- [OpenAPI spec](https://firecrawl.dev/alexandria/agents/providers/osv-dev/openapi.json)

## Capabilities

- [Query](https://firecrawl.dev/alexandria/agents/providers/osv-dev/vulnerabilities/query): Known vulnerabilities affecting one package version (or every version) across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more, from OSV.dev POST /v1/query. Accepts ecosystem+name(+version), a purl, or a Git commit. Each result gives the id and aliases (CVE/GHSA), summary, severity (CVSS vectors and the source rating), CWE ids, the affected ranges for the queried package, the versions that fix it, and per-source attribution and licence. An empty list means OSV.dev knows no vulnerability for that query.
- [Query batch](https://firecrawl.dev/alexandria/agents/providers/osv-dev/vulnerabilities/query_batch): Check up to 100 package versions, purls or commits in one OSV.dev POST /v1/querybatch call: for each query, whether it is vulnerable and the ids of the matching vulnerabilities (with last-modified time, osv.dev link and source database/licence). Results come back in query order. Fetch details for an id with vuln, or re-run one query with query.
- [Vuln](https://firecrawl.dev/alexandria/agents/providers/osv-dev/vulnerabilities/vuln): One full OSV record from OSV.dev GET /v1/vulns/{id} by OSV, GHSA, CVE, PYSEC, GO, RUSTSEC, DEBIAN or any other OSV id (or an osv.dev/vulnerability URL): summary and details, aliases, severity, every affected package with ranges and enumerated versions, references, credits and source-specific data, plus the source database and licence. CVE ids return OSV.dev's NVD-derived record, whose aliases point to the ecosystem advisories.

## 1. Choose this provider when

OSV.dev, Google's open source vulnerability database (api.osv.dev), keyless: known vulnerabilities for a package version, purl or Git commit across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more; batch checks of up to 100 dependencies; and full OSV records by OSV, GHSA or CVE id. Every record carries its source database (GitHub Advisory Database, PyPI, Go, RustSec, NVD, Debian, ...) and licence for attribution.

## 2. Minimal request

Call `POST https://api.firecrawl.dev/v2/scrape` with `{ alexandria: { provider, capability, options } }`. For a batch, send `{ alexandria: [...] }` with up to 10 calls.

```json
{
  "provider": "osv-dev",
  "capability": "vulnerabilities/query",
  "options": {
    "ecosystem": "npm",
    "name": "lodash",
    "version": "4.17.15"
  }
}
```

## 3. Add provider options

Use only the options needed for the task:

- `commit` (string): Full Git commit hash: vulnerabilities whose affected ranges include it (C/C++ and other source-level records). Pattern: ^[0-9a-fA-F]{40}$. Example: `<commit>`
- `cursor` (string): next_cursor from a previous answer for the same query (OSV.dev page token). Example: `<cursor>`
- `ecosystem` (string): OSV ecosystem: npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex, Hackage, CRAN, GitHub Actions, or a distribution with release (Debian:12, Alpine:v3.20, Ubuntu:22.04:LTS). Case-insensitive; cargo, golang, gem and composer are accepted. Use with `name`. Example: `<ecosystem>`
- `include_details` (boolean): Add each record's full Markdown description (`details`); off by default to keep answers small. Example: `false`
- `name` (string): Package name in the ecosystem: `lodash`, `jinja2`, `golang.org/x/net`, `org.apache.logging.log4j:log4j-core` (Maven group:artifact). Example: `<name>`
- `purl` (string): Package URL instead of ecosystem+name, optionally with the version: pkg:npm/lodash@4.17.15, pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1. Example: `<purl>`
- `version` (string): Exact version to check (4.17.15). Omit to list every vulnerability recorded for the package. Example: `<version>`

## 4. Request through your preferred interface

### JavaScript

```javascript
const result = await firecrawl.scrape({
  alexandria: {
    provider: "osv-dev",
    capability: "vulnerabilities/query",
    options: {
      ecosystem: "npm",
      name: "lodash",
      version: "4.17.15",
    },
  },
});
```

### Python

```python
result = firecrawl.scrape_alexandria({
  "provider": "osv-dev",
  "capability": "vulnerabilities/query",
  "options": {
    "ecosystem": "npm",
    "name": "lodash",
    "version": "4.17.15"
  }
})
```

### cURL

```sh
curl https://api.firecrawl.dev/v2/scrape \
  -H "Authorization: Bearer $FIRECRAWL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "alexandria": {
    "provider": "osv-dev",
    "capability": "vulnerabilities/query",
    "options": {
      "ecosystem": "npm",
      "name": "lodash",
      "version": "4.17.15"
    }
  }
}'
```

### CLI

```sh
firecrawl scrape 'osv-dev/vulnerabilities/query' \
  --options '{"ecosystem":"npm","name":"lodash","version":"4.17.15"}'
```


### MCP

Call the FCX MCP retrieve tool with this object:

```json
{
  "provider": "osv-dev",
  "capability": "vulnerabilities/query",
  "options": {
    "ecosystem": "npm",
    "name": "lodash",
    "version": "4.17.15"
  }
}
```

Ask for only the returned fields needed by the task.

## 5. Full request shape

```json
{
  "provider": "osv-dev",
  "capability": "vulnerabilities/query",
  "options": {
    "ecosystem": "npm",
    "name": "lodash",
    "version": "4.17.15"
  }
}
```

## 6. Response data

The response includes `success`, `provider`, `capability`, `creditsCost` and `data`. This example shows the provider payload in `data`:

```json
{
  "attribution": "Vulnerability data from OSV.dev (https://osv.dev), which aggregates the source databases named in each record's `source`. Each record remains under its source database's licence (`source.license`; null where OSV.dev does not state one). Records are reformatted here; see `url` for the original.",
  "count": 6,
  "next_cursor": null,
  "observed_at_ms": 1791423053962,
  "query": {
    "commit": null,
    "ecosystem": "npm",
    "name": "lodash",
    "purl": null,
    "version": "4.17.15"
  },
  "source_url": "https://api.osv.dev/v1/query",
  "vulnerable": true,
  "vulns": [
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.17.21"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2020-28500"
      ],
      "cwe_ids": [
        "CWE-1333",
        "CWE-400"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.17.21"
      ],
      "id": "GHSA-29mw-wpgm-hmr9",
      "modified": "2025-09-29T21:12:31.102523Z",
      "published": "2022-01-06T20:30:46Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
      },
      "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "4.17.21"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-r5fr-rjxr-66jc"
      ],
      "cwe_ids": [
        "CWE-77",
        "CWE-94"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.17.21"
      ],
      "id": "GHSA-35jh-r3h4-6jhm",
      "modified": "2026-09-10T03:49:04.067984836Z",
      "published": "2021-05-06T16:05:51Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-35jh-r3h4-6jhm/GHSA-35jh-r3h4-6jhm.json"
      },
      "summary": "Command Injection in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "4.18.0"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-xxjr-mmjv-4gpg"
      ],
      "cwe_ids": [
        "CWE-1321"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.18.0"
      ],
      "id": "GHSA-f23m-r3pf-42rh",
      "modified": "2026-09-10T03:50:44.050013812Z",
      "published": "2026-04-01T23:50:27Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"
      },
      "summary": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "3.7.0"
                },
                {
                  "fixed": "4.17.19"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2020-8203"
      ],
      "cwe_ids": [
        "CWE-1321",
        "CWE-770"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.17.19"
      ],
      "id": "GHSA-p6mc-m468-83gw",
      "modified": "2025-08-12T21:56:17.174859Z",
      "published": "2020-07-15T19:15:48Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-p6mc-m468-83gw/GHSA-p6mc-m468-83gw.json"
      },
      "summary": "Prototype Pollution in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.18.0"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-35jh-r3h4-6jhm"
      ],
      "cwe_ids": [
        "CWE-94"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.18.0"
      ],
      "id": "GHSA-r5fr-rjxr-66jc",
      "modified": "2026-09-10T03:51:02.970455926Z",
      "published": "2026-04-01T23:51:12Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-r5fr-rjxr-66jc/GHSA-r5fr-rjxr-66jc.json"
      },
      "summary": "lodash vulnerable to Code Injection via `_.template` imports key names",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.17.23"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-f23m-r3pf-42rh"
      ],
      "cwe_ids": [
        "CWE-1321"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.17.23"
      ],
      "id": "GHSA-xxjr-mmjv-4gpg",
      "modified": "2026-09-10T03:50:33.722177022Z",
      "published": "2026-01-21T23:01:22Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "type": "CVSS_V3"
        },
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P",
          "type": "CVSS_V4"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-xxjr-mmjv-4gpg/GHSA-xxjr-mmjv-4gpg.json"
      },
      "summary": "Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-xxjr-mmjv-4gpg",
      "withdrawn": null
    }
  ]
}
```

## API reference-derived contract

The following capability contract is generated from the same normalized Alexandria API reference exposed in the API spec.

### Query

- Capability: `vulnerabilities/query`
- Description: Known vulnerabilities affecting one package version (or every version) across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more, from OSV.dev POST /v1/query. Accepts ecosystem+name(+version), a purl, or a Git commit. Each result gives the id and aliases (CVE/GHSA), summary, severity (CVSS vectors and the source rating), CWE ids, the affected ranges for the queried package, the versions that fix it, and per-source attribution and licence. An empty list means OSV.dev knows no vulnerability for that query.
- Instructions: "Is lodash 4.17.15 vulnerable?", "what should I upgrade to": one package at a time. Use query_batch for a dependency list and vuln for the full record of one id.
- Cost: 5 credits per call
- Capability file: [Query](https://firecrawl.dev/alexandria/agents/providers/osv-dev/vulnerabilities/query)

Accepted options:
- `commit` (string): Full Git commit hash: vulnerabilities whose affected ranges include it (C/C++ and other source-level records). Pattern: ^[0-9a-fA-F]{40}$. Example: `<commit>`
- `cursor` (string): next_cursor from a previous answer for the same query (OSV.dev page token). Example: `<cursor>`
- `ecosystem` (string): OSV ecosystem: npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex, Hackage, CRAN, GitHub Actions, or a distribution with release (Debian:12, Alpine:v3.20, Ubuntu:22.04:LTS). Case-insensitive; cargo, golang, gem and composer are accepted. Use with `name`. Example: `<ecosystem>`
- `include_details` (boolean): Add each record's full Markdown description (`details`); off by default to keep answers small. Example: `false`
- `name` (string): Package name in the ecosystem: `lodash`, `jinja2`, `golang.org/x/net`, `org.apache.logging.log4j:log4j-core` (Maven group:artifact). Example: `<name>`
- `purl` (string): Package URL instead of ecosystem+name, optionally with the version: pkg:npm/lodash@4.17.15, pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1. Example: `<purl>`
- `version` (string): Exact version to check (4.17.15). Omit to list every vulnerability recorded for the package. Example: `<version>`

Response schema example:
```json
{
  "attribution": "Vulnerability data from OSV.dev (https://osv.dev), which aggregates the source databases named in each record's `source`. Each record remains under its source database's licence (`source.license`; null where OSV.dev does not state one). Records are reformatted here; see `url` for the original.",
  "count": 6,
  "next_cursor": null,
  "observed_at_ms": 1791423053962,
  "query": {
    "commit": null,
    "ecosystem": "npm",
    "name": "lodash",
    "purl": null,
    "version": "4.17.15"
  },
  "source_url": "https://api.osv.dev/v1/query",
  "vulnerable": true,
  "vulns": [
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.17.21"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2020-28500"
      ],
      "cwe_ids": [
        "CWE-1333",
        "CWE-400"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.17.21"
      ],
      "id": "GHSA-29mw-wpgm-hmr9",
      "modified": "2025-09-29T21:12:31.102523Z",
      "published": "2022-01-06T20:30:46Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
      },
      "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "4.17.21"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-r5fr-rjxr-66jc"
      ],
      "cwe_ids": [
        "CWE-77",
        "CWE-94"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.17.21"
      ],
      "id": "GHSA-35jh-r3h4-6jhm",
      "modified": "2026-09-10T03:49:04.067984836Z",
      "published": "2021-05-06T16:05:51Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-35jh-r3h4-6jhm/GHSA-35jh-r3h4-6jhm.json"
      },
      "summary": "Command Injection in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "4.18.0"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-xxjr-mmjv-4gpg"
      ],
      "cwe_ids": [
        "CWE-1321"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.18.0"
      ],
      "id": "GHSA-f23m-r3pf-42rh",
      "modified": "2026-09-10T03:50:44.050013812Z",
      "published": "2026-04-01T23:50:27Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"
      },
      "summary": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "3.7.0"
                },
                {
                  "fixed": "4.17.19"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2020-8203"
      ],
      "cwe_ids": [
        "CWE-1321",
        "CWE-770"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.17.19"
      ],
      "id": "GHSA-p6mc-m468-83gw",
      "modified": "2025-08-12T21:56:17.174859Z",
      "published": "2020-07-15T19:15:48Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-p6mc-m468-83gw/GHSA-p6mc-m468-83gw.json"
      },
      "summary": "Prototype Pollution in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.18.0"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-35jh-r3h4-6jhm"
      ],
      "cwe_ids": [
        "CWE-94"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.18.0"
      ],
      "id": "GHSA-r5fr-rjxr-66jc",
      "modified": "2026-09-10T03:51:02.970455926Z",
      "published": "2026-04-01T23:51:12Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-r5fr-rjxr-66jc/GHSA-r5fr-rjxr-66jc.json"
      },
      "summary": "lodash vulnerable to Code Injection via `_.template` imports key names",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.17.23"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-f23m-r3pf-42rh"
      ],
      "cwe_ids": [
        "CWE-1321"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.17.23"
      ],
      "id": "GHSA-xxjr-mmjv-4gpg",
      "modified": "2026-09-10T03:50:33.722177022Z",
      "published": "2026-01-21T23:01:22Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "type": "CVSS_V3"
        },
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P",
          "type": "CVSS_V4"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-xxjr-mmjv-4gpg/GHSA-xxjr-mmjv-4gpg.json"
      },
      "summary": "Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-xxjr-mmjv-4gpg",
      "withdrawn": null
    }
  ]
}
```

### Query batch

- Capability: `vulnerabilities/query_batch`
- Description: Check up to 100 package versions, purls or commits in one OSV.dev POST /v1/querybatch call: for each query, whether it is vulnerable and the ids of the matching vulnerabilities (with last-modified time, osv.dev link and source database/licence). Results come back in query order. Fetch details for an id with vuln, or re-run one query with query.
- Instructions: Auditing a dependency list or lockfile: which of these packages at these versions have known vulnerabilities.
- Cost: 5 credits per call
- Capability file: [Query batch](https://firecrawl.dev/alexandria/agents/providers/osv-dev/vulnerabilities/query_batch)

Accepted options:
- `queries` (object[], required): 1-100 queries. Example: `[]`

Response schema example:
```json
{
  "attribution": "Vulnerability data from OSV.dev (https://osv.dev), which aggregates the source databases named in each record's `source`. Each record remains under its source database's licence (`source.license`; null where OSV.dev does not state one). Records are reformatted here; see `url` for the original.",
  "count": 4,
  "observed_at_ms": 1791423053967,
  "results": [
    {
      "count": 6,
      "index": 0,
      "next_cursor": null,
      "query": {
        "commit": null,
        "ecosystem": "npm",
        "name": "lodash",
        "purl": null,
        "version": "4.17.15"
      },
      "vulnerable": true,
      "vulns": [
        {
          "id": "GHSA-29mw-wpgm-hmr9",
          "modified": "2025-09-29T21:12:31.102523Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
        },
        {
          "id": "GHSA-35jh-r3h4-6jhm",
          "modified": "2026-09-10T03:49:04.067984Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm"
        },
        {
          "id": "GHSA-f23m-r3pf-42rh",
          "modified": "2026-09-10T03:50:44.050013Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh"
        },
        {
          "id": "GHSA-p6mc-m468-83gw",
          "modified": "2025-08-12T21:56:17.174859Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw"
        },
        {
          "id": "GHSA-r5fr-rjxr-66jc",
          "modified": "2026-09-10T03:51:02.970455Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc"
        },
        {
          "id": "GHSA-xxjr-mmjv-4gpg",
          "modified": "2026-09-10T03:50:33.722177Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-xxjr-mmjv-4gpg"
        }
      ]
    },
    {
      "count": 18,
      "index": 1,
      "next_cursor": null,
      "query": {
        "commit": null,
        "ecosystem": "PyPI",
        "name": "jinja2",
        "purl": null,
        "version": "2.4.1"
      },
      "vulnerable": true,
      "vulns": [
        {
          "id": "GHSA-462w-v97r-4m45",
          "modified": "2024-09-24T21:03:59.802687Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-462w-v97r-4m45"
        },
        {
          "id": "GHSA-8r7q-cvjq-x353",
          "modified": "2024-09-24T18:48:44.375484Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-8r7q-cvjq-x353"
        },
        {
          "id": "GHSA-cpwx-vrp4-4pq7",
          "modified": "2026-09-10T03:49:48.526758Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-cpwx-vrp4-4pq7"
        },
        {
          "id": "GHSA-fqh9-2qgg-h84h",
          "modified": "2024-09-23T20:03:14.751414Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-fqh9-2qgg-h84h"
        },
        {
          "id": "GHSA-g3rq-g295-4j3m",
          "modified": "2025-02-14T05:26:14.565160Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-g3rq-g295-4j3m"
        },
        {
          "id": "GHSA-h5c8-rqwp-cp95",
          "modified": "2026-09-10T03:50:00.236017Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-h5c8-rqwp-cp95"
        },
        {
          "id": "GHSA-h75v-3vvj-5mfj",
          "modified": "2026-09-10T03:50:13.786450Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-h75v-3vvj-5mfj"
        },
        {
          "id": "GHSA-hj2j-77xm-mc5v",
          "modified": "2024-09-24T21:04:16.963502Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-hj2j-77xm-mc5v"
        },
        {
          "id": "GHSA-q2x7-8rv6-6q7h",
          "modified": "2026-09-10T03:50:21.662855Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-q2x7-8rv6-6q7h"
        },
        {
          "id": "PYSEC-2014-8",
          "modified": "2023-11-08T03:57:34.512953Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2014-8"
        },
        {
          "id": "PYSEC-2014-82",
          "modified": "2026-06-10T17:01:55.953302Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2014-82"
        },
        {
          "id": "PYSEC-2019-217",
          "modified": "2023-11-08T04:00:58.644982Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2019-217"
        },
        {
          "id": "PYSEC-2019-220",
          "modified": "2023-11-08T03:58:21.453618Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2019-220"
        },
        {
          "id": "PYSEC-2021-66",
          "modified": "2023-11-08T04:03:28.543308Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2021-66"
        },
        {
          "id": "PYSEC-2026-1471",
          "modified": "2026-07-07T17:46:43.358335Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2026-1471"
        },
        {
          "id": "PYSEC-2026-1473",
          "modified": "2026-07-07T17:46:13.853151Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2026-1473"
        },
        {
          "id": "PYSEC-2026-1474",
          "modified": "2026-07-07T17:46:13.832160Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2026-1474"
        },
        {
          "id": "PYSEC-2026-1475",
          "modified": "2026-07-07T17:46:13.842466Z",
          "source": {
            "database": "PyPI Advisory Database",
            "home_url": "https://github.com/pypa/advisory-db",
            "license": "CC-BY-4.0",
            "prefix": "PYSEC"
          },
          "url": "https://osv.dev/vulnerability/PYSEC-2026-1475"
        }
      ]
    },
    {
      "count": 0,
      "index": 2,
      "next_cursor": null,
      "query": {
        "commit": null,
        "ecosystem": "npm",
        "name": "left-pad",
        "purl": null,
        "version": "1.3.0"
      },
      "vulnerable": false,
      "vulns": []
    },
    {
      "count": 7,
      "index": 3,
      "next_cursor": null,
      "query": {
        "commit": null,
        "ecosystem": null,
        "name": null,
        "purl": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
        "version": "2.14.1"
      },
      "vulnerable": true,
      "vulns": [
        {
          "id": "GHSA-3pxv-7cmr-fjr4",
          "modified": "2026-09-10T03:50:42.492278Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-3pxv-7cmr-fjr4"
        },
        {
          "id": "GHSA-6hg6-v5c8-fphq",
          "modified": "2026-09-10T03:50:43.570169Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-6hg6-v5c8-fphq"
        },
        {
          "id": "GHSA-7rjr-3q55-vv33",
          "modified": "2026-10-02T20:30:05.438504Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-7rjr-3q55-vv33"
        },
        {
          "id": "GHSA-8489-44mv-ggj8",
          "modified": "2026-06-09T10:45:14.253296Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-8489-44mv-ggj8"
        },
        {
          "id": "GHSA-jfh8-c2jp-5v3q",
          "modified": "2025-10-22T19:37:02.616807Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-jfh8-c2jp-5v3q"
        },
        {
          "id": "GHSA-p6xc-xr62-6r2g",
          "modified": "2026-06-09T10:30:14.432177Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-p6xc-xr62-6r2g"
        },
        {
          "id": "GHSA-vc5p-v9hr-52mj",
          "modified": "2026-09-10T03:50:32.126499Z",
          "source": {
            "database": "GitHub Advisory Database",
            "home_url": "https://github.com/github/advisory-database",
            "license": "CC-BY-4.0",
            "prefix": "GHSA"
          },
          "url": "https://osv.dev/vulnerability/GHSA-vc5p-v9hr-52mj"
        }
      ]
    }
  ],
  "source_url": "https://api.osv.dev/v1/querybatch",
  "total_vulns": 31
}
```

### Vuln

- Capability: `vulnerabilities/vuln`
- Description: One full OSV record from OSV.dev GET /v1/vulns/{id} by OSV, GHSA, CVE, PYSEC, GO, RUSTSEC, DEBIAN or any other OSV id (or an osv.dev/vulnerability URL): summary and details, aliases, severity, every affected package with ranges and enumerated versions, references, credits and source-specific data, plus the source database and licence. CVE ids return OSV.dev's NVD-derived record, whose aliases point to the ecosystem advisories.
- Instructions: Details of one vulnerability id from query or query_batch, or a CVE/GHSA someone mentions.
- Cost: 5 credits per call
- Capability file: [Vuln](https://firecrawl.dev/alexandria/agents/providers/osv-dev/vulnerabilities/vuln)

Accepted options:
- `id` (string): OSV id, e.g. GHSA-29mw-wpgm-hmr9, CVE-2021-44228, PYSEC-2021-19, GO-2022-0969, RUSTSEC-2021-0003, DEBIAN-CVE-2023-5678. GHSA and CVE ids are case-normalized. Example: `<id>`
- `url` (string): Pasted https://osv.dev/vulnerability/<id> URL instead of `id`. Example: `<url>`

Response schema example:
```json
{
  "attribution": "Vulnerability data from OSV.dev (https://osv.dev), which aggregates the source databases named in each record's `source`. Each record remains under its source database's licence (`source.license`; null where OSV.dev does not state one). Records are reformatted here; see `url` for the original.",
  "id": "GHSA-29mw-wpgm-hmr9",
  "observed_at_ms": 1791423053968,
  "source": {
    "database": "GitHub Advisory Database",
    "home_url": "https://github.com/github/advisory-database",
    "license": "CC-BY-4.0",
    "prefix": "GHSA",
    "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
  },
  "source_url": "https://api.osv.dev/v1/vulns/GHSA-29mw-wpgm-hmr9",
  "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9",
  "vuln": {
    "affected": [
      {
        "database_specific": {
          "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
        },
        "package": {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash"
        },
        "ranges": [
          {
            "events": [
              {
                "introduced": "4.0.0"
              },
              {
                "fixed": "4.17.21"
              }
            ],
            "type": "SEMVER"
          }
        ]
      },
      {
        "database_specific": {
          "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
        },
        "package": {
          "ecosystem": "npm",
          "name": "lodash-es",
          "purl": "pkg:npm/lodash-es"
        },
        "ranges": [
          {
            "events": [
              {
                "introduced": "4.0.0"
              },
              {
                "fixed": "4.17.21"
              }
            ],
            "type": "SEMVER"
          }
        ]
      },
      {
        "database_specific": {
          "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
        },
        "package": {
          "ecosystem": "npm",
          "name": "lodash.trimend",
          "purl": "pkg:npm/lodash.trimend"
        },
        "ranges": [
          {
            "events": [
              {
                "introduced": "4.0.0"
              },
              {
                "last_affected": "4.5.1"
              }
            ],
            "type": "SEMVER"
          }
        ]
      },
      {
        "database_specific": {
          "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
        },
        "package": {
          "ecosystem": "npm",
          "name": "lodash.trim",
          "purl": "pkg:npm/lodash.trim"
        },
        "ranges": [
          {
            "events": [
              {
                "introduced": "4.0.0"
              },
              {
                "last_affected": "4.5.1"
              }
            ],
            "type": "SEMVER"
          }
        ]
      },
      {
        "database_specific": {
          "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
        },
        "package": {
          "ecosystem": "RubyGems",
          "name": "lodash-rails",
          "purl": "pkg:gem/lodash-rails"
        },
        "ranges": [
          {
            "events": [
              {
                "introduced": "4.0.0"
              },
              {
                "fixed": "4.17.21"
              }
            ],
            "type": "ECOSYSTEM"
          }
        ],
        "versions": [
          "4.0.0",
          "4.11.2",
          "4.12.0",
          "4.13.1",
          "4.14.1",
          "4.15.0",
          "4.16.1",
          "4.16.3",
          "4.16.4",
          "4.16.6",
          "4.17.10",
          "4.17.11",
          "4.17.14",
          "4.17.15",
          "4.17.2",
          "4.17.4",
          "4.17.5",
          "4.3.0",
          "4.5.1",
          "4.6.1"
        ]
      }
    ],
    "aliases": [
      "CVE-2020-28500"
    ],
    "database_specific": {
      "cwe_ids": [
        "CWE-1333",
        "CWE-400"
      ],
      "github_reviewed": true,
      "github_reviewed_at": "2021-03-19T22:45:28Z",
      "nvd_published_at": "2021-02-15T11:15:00Z",
      "severity": "MODERATE"
    },
    "details": "All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `toNumber`, `trim` and `trimEnd` functions. \n\nSteps to reproduce (provided by reporter Liyuan Chen):\n```js\nvar lo = require('lodash');\n\nfunction build_blank(n) {\n    var ret = \"1\"\n    for (var i = 0; i < n; i++) {\n        ret += \" \"\n    }\n    return ret + \"1\";\n}\nvar s = build_blank(50000) var time0 = Date.now();\nlo.trim(s) \nvar time_cost0 = Date.now() - time0;\nconsole.log(\"time_cost0: \" + time_cost0);\nvar time1 = Date.now();\nlo.toNumber(s) var time_cost1 = Date.now() - time1;\nconsole.log(\"time_cost1: \" + time_cost1);\nvar time2 = Date.now();\nlo.trimEnd(s);\nvar time_cost2 = Date.now() - time2;\nconsole.log(\"time_cost2: \" + time_cost2);\n```",
    "id": "GHSA-29mw-wpgm-hmr9",
    "modified": "2025-09-29T21:12:31.102523Z",
    "published": "2022-01-06T20:30:46Z",
    "references": [
      {
        "type": "ADVISORY",
        "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28500"
      },
      {
        "type": "WEB",
        "url": "https://github.com/github/advisory-database/pull/6139"
      },
      {
        "type": "WEB",
        "url": "https://github.com/lodash/lodash/pull/5065"
      },
      {
        "type": "WEB",
        "url": "https://github.com/lodash/lodash/pull/5065/commits/02906b8191d3c100c193fe6f7b27d1c40f200bb7"
      },
      {
        "type": "WEB",
        "url": "https://github.com/lodash/lodash/commit/c4847ebe7d14540bb28a8b932a9ce1b9ecbfee1a"
      },
      {
        "type": "WEB",
        "url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
      },
      {
        "type": "WEB",
        "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
      },
      {
        "type": "WEB",
        "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
      },
      {
        "type": "WEB",
        "url": "https://www.oracle.com//security-alerts/cpujul2021.html"
      },
      {
        "type": "WEB",
        "url": "https://snyk.io/vuln/SNYK-JS-LODASH-1018905"
      },
      {
        "type": "WEB",
        "url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074893"
      },
      {
        "type": "WEB",
        "url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895"
      },
      {
        "type": "WEB",
        "url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074892"
      },
      {
        "type": "WEB",
        "url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074894"
      },
      {
        "type": "WEB",
        "url": "https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074896"
      },
      {
        "type": "WEB",
        "url": "https://security.netapp.com/advisory/ntap-20210312-0006"
      },
      {
        "type": "WEB",
        "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2020-28500.yml"
      },
      {
        "type": "WEB",
        "url": "https://github.com/lodash/lodash/blob/npm/trimEnd.js%23L8"
      },
      {
        "type": "PACKAGE",
        "url": "https://github.com/lodash/lodash"
      },
      {
        "type": "WEB",
        "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf"
      }
    ],
    "schema_version": "1.9.0",
    "severity": [
      {
        "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
        "type": "CVSS_V3"
      }
    ],
    "summary": "Regular Expression Denial of Service (ReDoS) in lodash"
  },
  "withdrawn": false
}
```
