Firecrawl Alexandria
OSV.dev open source vulnerabilities
OSV.dev, Google's open source vulnerability database (api.osv.dev), keyless: known vulnerabilities for a package version, purl or Git commit across npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet, Packagist, Linux distributions and more; batch checks of up to 100 dependencies; and full OSV records by OSV, GHSA or CVE id. Every record carries its source database (GitHub Advisory Database, PyPI, Go, RustSec, NVD, Debian, ...) and licence for attribution.
Try OSV.dev open source vulnerabilities now.
Choose an example or ask your own question.
TRY ASKING
Codefollows the fields above
const result = await firecrawl.scrape({
alexandria: {
provider: "osv-dev",
capability: "vulnerabilities/query",
options: {
ecosystem: "npm",
name: "lodash",
version: "4.17.15",
},
},
});2Response example
This is a sample shape. Press Run to see live data from OSV.dev open source vulnerabilities.
{
"attribution": "Vulnerability data from OSV.dev (https://osv.dev), which aggregates the source databases named in each record's `source`. Each record remains under its source database's licence (`source.license`; null where OSV.dev does not state one). Records are reformatted here; see `url` for the original.",
"count": 6,
"next_cursor": null,
"observed_at_ms": 1791423053962,
"query": {
"commit": null,
"ecosystem": "npm",
"name": "lodash",
"purl": null,
"version": "4.17.15"
},
"source_url": "https://api.osv.dev/v1/query",
"vulnerable": true,
"vulns": [
{
"affected": [
{
"ecosystem": "npm",
"name": "lodash",
"purl": "pkg:npm/lodash",
"ranges": [
{
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.17.21"
}
],
"repo": null,
"type": "SEMVER"
}
]
}
],
"affected_scope": "queried_package",
"aliases": [
"CVE-2020-28500"
],
"cwe_ids": [
"CWE-1333",
"CWE-400"
],
"database_severity": "MODERATE",
"fixed_in": [
"4.17.21"
],
"id": "GHSA-29mw-wpgm-hmr9",
"modified": "2025-09-29T21:12:31.102523Z",
"published": "2022-01-06T20:30:46Z",
"related": [],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
],
"source": {
"database": "GitHub Advisory Database",
"home_url": "https://github.com/github/advisory-database",
"license": "CC-BY-4.0",
"prefix": "GHSA",
"record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"
},
"summary": "Regular Expression Denial of Service (ReDoS) in lodash",
"upstream": [],
"url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9",
"withdrawn": null
},
{
"affected": [
{
"ecosystem": "npm",
"name": "lodash",
"purl": "pkg:npm/lodash",
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.17.21"
}
],
"repo": null,
"type": "SEMVER"
}
]
}
],
"affected_scope": "queried_package",
"aliases": [
"CVE-2021-23337",
"CVE-2026-4800",
"GHSA-r5fr-rjxr-66jc"
],
"cwe_ids": [
"CWE-77",
"CWE-94"
],
"database_severity": "HIGH",
"fixed_in": [
"4.17.21"
],
"id": "GHSA-35jh-r3h4-6jhm",
"modified": "2026-09-10T03:49:04.067984836Z",
"published": "2021-05-06T16:05:51Z",
"related": [],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"source": {
"database": "GitHub Advisory Database",
"home_url": "https://github.com/github/advisory-database",
"license": "CC-BY-4.0",
"prefix": "GHSA",
"record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-35jh-r3h4-6jhm/GHSA-35jh-r3h4-6jhm.json"
},
"summary": "Command Injection in lodash",
"upstream": [],
"url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm",
"withdrawn": null
},
{
"affected": [
{
"ecosystem": "npm",
"name": "lodash",
"purl": "pkg:npm/lodash",
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.18.0"
}
],
"repo": null,
"type": "SEMVER"
}
]
}
],
"affected_scope": "queried_package",
"aliases": [
"CVE-2025-13465",
"CVE-2026-2950",
"GHSA-xxjr-mmjv-4gpg"
],
"cwe_ids": [
"CWE-1321"
],
"database_severity": "MODERATE",
"fixed_in": [
"4.18.0"
],
"id": "GHSA-f23m-r3pf-42rh",
"modified": "2026-09-10T03:50:44.050013812Z",
"published": "2026-04-01T23:50:27Z",
"related": [],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"type": "CVSS_V3"
}
],
"source": {
"database": "GitHub Advisory Database",
"home_url": "https://github.com/github/advisory-database",
"license": "CC-BY-4.0",
"prefix": "GHSA",
"record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-f23m-r3pf-42rh/GHSA-f23m-r3pf-42rh.json"
},
"summary": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
"upstream": [],
"url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh",
"withdrawn": null
},
{
"affected": [
{
"ecosystem": "npm",
"name": "lodash",
"purl": "pkg:npm/lodash",
"ranges": [
{
"events": [
{
"introduced": "3.7.0"
},
{
"fixed": "4.17.19"
}
],
"repo": null,
"type": "SEMVER"
}
]
}
],
"affected_scope": "queried_package",
"aliases": [
"CVE-2020-8203"
],
"cwe_ids": [
"CWE-1321",
"CWE-770"
],
"database_severity": "HIGH",
"fixed_in": [
"4.17.19"
],
"id": "GHSA-p6mc-m468-83gw",
"modified": "2025-08-12T21:56:17.174859Z",
"published": "2020-07-15T19:15:48Z",
"related": [],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"type": "CVSS_V3"
}
],
"source": {
"database": "GitHub Advisory Database",
"home_url": "https://github.com/github/advisory-database",
"license": "CC-BY-4.0",
"prefix": "GHSA",
"record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-p6mc-m468-83gw/GHSA-p6mc-m468-83gw.json"
},
"summary": "Prototype Pollution in lodash",
"upstream": [],
"url": "https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw",
"withdrawn": null
},
{
"affected": [
{
"ecosystem": "npm",
"name": "lodash",
"purl": "pkg:npm/lodash",
"ranges": [
{
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.18.0"
}
],
"repo": null,
"type": "SEMVER"
}
]
}
],
"affected_scope": "queried_package",
"aliases": [
"CVE-2021-23337",
"CVE-2026-4800",
"GHSA-35jh-r3h4-6jhm"
],
"cwe_ids": [
"CWE-94"
],
"database_severity": "HIGH",
"fixed_in": [
"4.18.0"
],
"id": "GHSA-r5fr-rjxr-66jc",
"modified": "2026-09-10T03:51:02.970455926Z",
"published": "2026-04-01T23:51:12Z",
"related": [],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"source": {
"database": "GitHub Advisory Database",
"home_url": "https://github.com/github/advisory-database",
"license": "CC-BY-4.0",
"prefix": "GHSA",
"record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-r5fr-rjxr-66jc/GHSA-r5fr-rjxr-66jc.json"
},
"summary": "lodash vulnerable to Code Injection via `_.template` imports key names",
"upstream": [],
"url": "https://osv.dev/vulnerability/GHSA-r5fr-rjxr-66jc",
"withdrawn": null
},
{
"affected": [
{
"ecosystem": "npm",
"name": "lodash",
"purl": "pkg:npm/lodash",
"ranges": [
{
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.17.23"
}
],
"repo": null,
"type": "SEMVER"
}
]
}
],
"affected_scope": "queried_package",
"aliases": [
"CVE-2025-13465",
"CVE-2026-2950",
"GHSA-f23m-r3pf-42rh"
],
"cwe_ids": [
"CWE-1321"
],
"database_severity": "MODERATE",
"fixed_in": [
"4.17.23"
],
"id": "GHSA-xxjr-mmjv-4gpg",
"modified": "2026-09-10T03:50:33.722177022Z",
"published": "2026-01-21T23:01:22Z",
"related": [],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P",
"type": "CVSS_V4"
}
],
"source": {
"database": "GitHub Advisory Database",
"home_url": "https://github.com/github/advisory-database",
"license": "CC-BY-4.0",
"prefix": "GHSA",
"record_url": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-xxjr-mmjv-4gpg/GHSA-xxjr-mmjv-4gpg.json"
},
"summary": "Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
"upstream": [],
"url": "https://osv.dev/vulnerability/GHSA-xxjr-mmjv-4gpg",
"withdrawn": null
}
]
}