Security: C2Xai
15
Vulnerabilities
32
Credential Leaks
⚡
View AI Prompts
AI Fix Prompts
Auto-generated prompts to fix every issue — copy into Claude, GPT, or any AI coder
Vulnerabilities (15)
| Severity | ID | Package | Version | Summary |
|---|---|---|---|---|
| critical | CVE-2025-62718 | axios | 1.13.5 | |
| critical | GHSA-3p68-rc4w-qgx5 | axios | 1.13.5 | |
| critical | GHSA-fvcv-3m26-pcqx | axios | 1.13.5 | |
| critical | CVE-2026-40175 | axios | 1.13.5 | |
| high | CVE-2026-39364 | vite | 7.1.11 | |
| high | CVE-2026-31812 | quinn-proto | 0.11.13 | |
| high | GHSA-v2wj-q39q-566r | vite | 7.1.11 | |
| high | GHSA-p9ff-h696-f583 | vite | 7.1.11 | |
| high | GHSA-6xvm-j4wr-6v98 | quinn-proto | 0.11.13 | |
| high | GHSA-cxww-7g56-2vh6 | actions/download-artifact | v4 | |
| high | GHSA-q4gf-8mx6-v5v3 | next | 16.2.2 | |
| high | CVE-2026-39363 | vite | 7.1.11 | |
| medium | CVE-2026-39365 | vite | 7.1.11 | |
| medium | GHSA-wrw7-89jp-8q8g | glib | 0.18.5 | |
| medium | GHSA-4w7w-66w2-5vf9 | vite | 7.1.11 |
Credential Findings (32)
| Severity | Pattern | File | Line |
|---|---|---|---|
| critical | Vault Token | lib/utils/file-transform-utils.ts | 111 |
| critical | Vault Token | lib/rate-limit/refund.ts | 28 |
| critical | Vault Token | lib/rate-limit/refund.ts | 35 |
| critical | Vault Token | lib/rate-limit/refund.ts | 56 |
| critical | Vault Token | lib/usage-tracker.ts | 48 |
| critical | Vault Token | app/components/MessagePartHandler.tsx | 91 |
| critical | Vault Token | app/components/MessagePartHandler.tsx | 92 |
| critical | Vault Token | app/components/extra-usage/BuyExtraUsageDialog.tsx | 63 |
| critical | Vault Token | app/hooks/useChatHandlers.ts | 81 |
| critical | Vault Token | app/hooks/useChatHandlers.ts | 85 |
| critical | Vault Token | app/hooks/useChatHandlers.ts | 91 |
| critical | Vault Token | app/hooks/useFileUpload.ts | 45 |
| critical | Vault Token | convex/extraUsage.ts | 596 |
| critical | Vault Token | convex/extraUsage.ts | 597 |
| critical | Vault Token | convex/extraUsage.ts | 609 |
| critical | Vault Token | convex/extraUsage.ts | 610 |
| critical | Vault Token | convex/extraUsage.ts | 624 |
| critical | Vault Token | convex/extraUsage.ts | 625 |
| critical | Vault Token | convex/extraUsage.ts | 648 |
| critical | Vault Token | convex/extraUsage.ts | 650 |
| critical | Vault Token | e2e/page-objects/UpgradeDialog.ts | 102 |
| critical | Vault Token | e2e/page-objects/UpgradeDialog.ts | 106 |
| critical | Vault Token | e2e/page-objects/UpgradeDialog.ts | 111 |
| critical | JWT Secret Key | lib/ai/tools/utils/hybrid-sandbox-manager.ts | 278 |
| critical | Vault Token | lib/db/actions.ts | 283 |
| critical | Vault Token | lib/db/actions.ts | 637 |
| critical | Vault Token | lib/db/actions.ts | 652 |
| critical | Vault Token | lib/db/actions.ts | 776 |
| high | [sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URL | app/components/AllFilesDialog.tsx | 297 |
| high | [sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URL | app/components/FilePartRenderer.tsx | 174 |
| high | [sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URL | app/components/FilePartRenderer.tsx | 224 |
| high | [sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URL | app/components/AllFilesDialog.tsx | 51 |