Firecrawl Alexandria

OSV.dev open source vulnerabilities

OSV.dev, Google's open source vulnerability database (api.osv.dev), keyless: known vulnerabilities for a package version, purl or Git commit across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more; batch checks of up to 100 dependencies; and full OSV records by OSV, GHSA or CVE id. Every record carries its source database (GitHub Advisory Database, PyPI, Go, RustSec, NVD, Debian, ...) and licence for attribution.

Try OSV.dev open source vulnerabilities now.

Choose an example or ask your own question.

OSV.dev open source vulnerabilities
TRY ASKING
1Request
string

Full Git commit hash: vulnerabilities whose affected ranges include it (C/C++ and other source-level records).

string

next_cursor from a previous answer for the same query (OSV.dev page token).

string

OSV ecosystem: npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Pub, Hex, Hackage, CRAN, GitHub Actions, or a distribution with release (Debian:12, Alpine:v3.20, Ubuntu:22.04:LTS). Case-insensitive; cargo, golang, gem and composer are accepted. Use with `name`.

string

Package name in the ecosystem: `lodash`, `jinja2`, `golang.org/x/net`, `org.apache.logging.log4j:log4j-core` (Maven group:artifact).

string

Exact version to check (4.17.15). Omit to list every vulnerability recorded for the package.

5 credits
Codefollows the fields above
const result = await firecrawl.scrape({
  alexandria: {
    provider: "osv-dev",
    capability: "vulnerabilities/query",
    options: {
      ecosystem: "npm",
      name: "lodash",
      version: "4.17.15",
    },
  },
});
2Response example

This is a sample shape. Press Run to see live data from OSV.dev open source vulnerabilities.

{
  "attribution": "Vulnerability data from OSV.dev (https://osv.dev), which aggregates the source databases named in each record's `source`. Each record remains under its source database's licence (`source.license`; null where OSV.dev does not state one). Records are reformatted here; see `url` for the original.",
  "count": 6,
  "next_cursor": null,
  "observed_at_ms": 1791423053962,
  "query": {
    "commit": null,
    "ecosystem": "npm",
    "name": "lodash",
    "purl": null,
    "version": "4.17.15"
  },
  "source_url": "https://api.osv.dev/v1/query",
  "vulnerable": true,
  "vulns": [
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.17.21"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2020-28500"
      ],
      "cwe_ids": [
        "CWE-1333",
        "CWE-400"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.17.21"
      ],
      "id": "GHSA-29mw-wpgm-hmr9",
      "modified": "2025-09-29T21:12:31.102523Z",
      "published": "2022-01-06T20:30:46Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
      },
      "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "4.17.21"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-r5fr-rjxr-66jc"
      ],
      "cwe_ids": [
        "CWE-77",
        "CWE-94"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.17.21"
      ],
      "id": "GHSA-35jh-r3h4-6jhm",
      "modified": "2026-09-10T03:49:04.067984836Z",
      "published": "2021-05-06T16:05:51Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-35jh-r3h4-6jhm/GHSA-35jh-r3h4-6jhm.json"
      },
      "summary": "Command Injection in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "4.18.0"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-xxjr-mmjv-4gpg"
      ],
      "cwe_ids": [
        "CWE-1321"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.18.0"
      ],
      "id": "GHSA-f23m-r3pf-42rh",
      "modified": "2026-09-10T03:50:44.050013812Z",
      "published": "2026-04-01T23:50:27Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"
      },
      "summary": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "3.7.0"
                },
                {
                  "fixed": "4.17.19"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2020-8203"
      ],
      "cwe_ids": [
        "CWE-1321",
        "CWE-770"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.17.19"
      ],
      "id": "GHSA-p6mc-m468-83gw",
      "modified": "2025-08-12T21:56:17.174859Z",
      "published": "2020-07-15T19:15:48Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-p6mc-m468-83gw/GHSA-p6mc-m468-83gw.json"
      },
      "summary": "Prototype Pollution in lodash",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.18.0"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-35jh-r3h4-6jhm"
      ],
      "cwe_ids": [
        "CWE-94"
      ],
      "database_severity": "HIGH",
      "fixed_in": [
        "4.18.0"
      ],
      "id": "GHSA-r5fr-rjxr-66jc",
      "modified": "2026-09-10T03:51:02.970455926Z",
      "published": "2026-04-01T23:51:12Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-r5fr-rjxr-66jc/GHSA-r5fr-rjxr-66jc.json"
      },
      "summary": "lodash vulnerable to Code Injection via `_.template` imports key names",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc",
      "withdrawn": null
    },
    {
      "affected": [
        {
          "ecosystem": "npm",
          "name": "lodash",
          "purl": "pkg:npm/lodash",
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.17.23"
                }
              ],
              "repo": null,
              "type": "SEMVER"
            }
          ]
        }
      ],
      "affected_scope": "queried_package",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-f23m-r3pf-42rh"
      ],
      "cwe_ids": [
        "CWE-1321"
      ],
      "database_severity": "MODERATE",
      "fixed_in": [
        "4.17.23"
      ],
      "id": "GHSA-xxjr-mmjv-4gpg",
      "modified": "2026-09-10T03:50:33.722177022Z",
      "published": "2026-01-21T23:01:22Z",
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "type": "CVSS_V3"
        },
        {
          "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P",
          "type": "CVSS_V4"
        }
      ],
      "source": {
        "database": "GitHub Advisory Database",
        "home_url": "https://github.com/github/advisory-database",
        "license": "CC-BY-4.0",
        "prefix": "GHSA",
        "record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-xxjr-mmjv-4gpg/GHSA-xxjr-mmjv-4gpg.json"
      },
      "summary": "Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
      "upstream": [],
      "url": "https://osv.dev/vulnerability/GHSA-xxjr-mmjv-4gpg",
      "withdrawn": null
    }
  ]
}
Browse the library