Skip to content

Scan rule · RSC-SEC-078

Shipped library with a known vulnerability

SecuritySeverity: HighCWE-1395OWASP A06-2021

Detects front-end libraries and their version in the served bundle and in recovered source maps (retire.js signatures) and matches the version against OSV or the bundled retire.js database. Reports only on a confidently detected version.

Scan tier

External scan (anonymous)Source code from source maps

How to fix it

Raise the affected library to the patched version and set up a recurring update run.

Scan your own app for free