326,071 packages matching “command injection”
eslint-plugin-node-security
v5.2.3 · 3 hours ago
ESLint plugin for Node.js security — detects command injection, path traversal, SSRF, zip slip, and weak crypto (MD5/SHA-1, ECB, static IV) in fs, child_process, vm, and crypto.
No known vulnerabilities
correctover
v2.4.13 · 2 days ago
AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.
No known vulnerabilities
dsh-ccs-security
v1.0.1 · 5 days ago
Runtime security guard for DeepSeek Harness (DSH) — blocks command injection, SSRF, credential exfiltration, and destructive operations at runtime.
No known vulnerabilities
di
v0.0.1 · 13 years ago
Dependency Injection for Node.js. Heavily inspired by AngularJS.
No known vulnerabilities
tsyringe
v4.10.0 · 1 year ago
Lightweight dependency injection container for JavaScript/TypeScript
No known vulnerabilities
@plugin.land/run-command
v1.2.1 · 8 years ago
- https://blog.liftsecurity.io/2014/08/19/Avoid-Command-Injection-Node.js/
No known vulnerabilities
@sharkvoid/rasp
v2.2.12 · 1 month ago
Production-grade Runtime Application Self-Protection for Express, Next.js, Firebase, and Supabase. Defends against SQL injection, XSS, path traversal, command injection, bots, brute force, and AI-powered attackers. Powered by SharkVoid.
No known vulnerabilities
injection-js
v2.6.1 · 10 months ago
Dependency Injection library for JavaScript and TypeScript
No known vulnerabilities
strict-url-sanitise
v0.0.1 · 1 year ago
Strict URL sanitization with security-focused validation
No known vulnerabilities
eslint-plugin-mcp-security
v0.2.5 · 5 months ago
ESLint security rules for Model Context Protocol (MCP) servers — catches SANDWORM_MODE credential harvesting, path traversal, command injection, and CVE patterns at dev time
No known vulnerabilities
typed-inject
v5.0.0 · 1 year ago
Type safe dependency injection framework for TypeScript
No known vulnerabilities
@aikidosec/firewall
v1.8.37 · 7 days ago
Zen by Aikido is an embedded Application Firewall that autonomously protects Node.js apps against common and critical attacks, provides rate limiting, detects malicious traffic (including bots), and more.
No known vulnerabilities
awilix
v13.0.5 · 2 months ago
Extremely powerful dependency injection container.
No known vulnerabilities
nest-commander
v3.20.1 · 10 months ago
A module for making CLI applications with NestJS. Decorators for running commands and separating out config parsers included. This package works on top of commander.
No known vulnerabilities
git-clone-safe
v1.2.0 · 4 months ago
Safe drop-in replacement for git-clone package, fixing command injection vulnerability (CVE-2022-25900)
No known vulnerabilities
@deepseek-ai/dsh-commands
v0.0.1-rc.1 · 15 days ago
Plugin-owned human command registry for DeepSeek Harness UI surfaces
No known vulnerabilities
firewtwall
v2.4.7 · 2 months ago
Zero-dependency Web Application Firewall middleware for Node.js / Express — SQL injection, XSS, path traversal, command injection, rate limiting, and more.
No known vulnerabilities
vite-plugin-css-injected-by-js
v5.0.2 · 1 month ago
A Vite plugin that takes the CSS and adds it to the page through the JS. For those who want a single JS file.
No known vulnerabilities
aurelia-dependency-injection
v1.6.1 · 1 year ago
A lightweight, extensible dependency injection container for JavaScript.
No known vulnerabilities
@claude-flow/security
v3.0.0-alpha.12 · 1 month ago
Security module - CVE fixes, input validation, path security
No known vulnerabilities