Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Snyk/
  3. Snyk AI Security Posture Management

Snyk AI Security Posture Management

AI-SPMAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 17 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~47 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Code-first governance for AI applications (AI-SPM).

by Snyk · snyk.io · source ↗

Known CVEs (17)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-6624 ↗HIGH 7.22025

    Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environme…

  • CVE-2024-21571 ↗HIGH 8.12024

    Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within the Code Agent container. Exploiti…

  • CVE-2024-48964 ↗HIGH 7.52024

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due …

  • CVE-2024-48963 ↗HIGH 7.52024

    The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to …

  • CVE-2024-2243 ↗HIGH 7.62024

    A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and t…

  • CVE-2023-1767 ↗MEDIUM 4.32023

    The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature of Snyk Advisor is to display the contents of a scanned package's Readme on its p…

  • CVE-2023-1065 ↗MEDIUM 6.52023

    This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expose …

  • CVE-2022-24441 ↗MEDIUM 5.82022

    The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as…

  • CVE-2022-22984 ↗MEDIUM 5.02022

    The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-pl…

  • CVE-2022-40764 ↗HIGH 7.82022

    Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Vi…

  • CVE-2020-7649 ↗MEDIUM 4.92022

    This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.

  • CVE-2020-7654 ↗HIGH 7.52020

    All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.

  • CVE-2020-7650 ↗MEDIUM 6.52020

    All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files …

  • CVE-2020-7648 ↗MEDIUM 6.52020

    All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragmen…

  • CVE-2020-7653 ↗MEDIUM 6.52020

    All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelist…

  • CVE-2020-7652 ↗MEDIUM 6.52020

    All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.

  • CVE-2020-7651 ↗MEDIUM 4.32020

    All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Application Security (ASPM) products

see all →
  • AI SAST · Arnica
  • Acunetix Web Application & API Security · Acunetix
  • Adronite · Adronite
  • Almanax · Almanax
  • Amplify Security Fix Your Code · Amplify Security
  • Anchore Anchore Enterprise · Anchore
  • Apiiro AI SAST · Apiiro
  • Apiiro ASPM Platform · Apiiro