Live package.json & requirements.txt CVE Dependency Auditor (2026)

Paste any Node.js `package.json` or Python `requirements.txt` manifest to query the live Google OSV.dev (Open Source Vulnerabilities) & GitHub Security Advisory database for known CVEs, GHSAs, CVSS scores, and patched versions.

Live package.json & requirements.txt CVE Dependency Auditor — Interactive Console
Runs locally in your browser • Instant output
Dependency CVE Audit TableVerified GHSA / CVE Database (Click 'Query Live OSV.dev Batch API' for real-time check)
PackageSeverityAdvisory / CVE IDPatched
lodash@4.17.19HIGH
GHSA-35jh-r3h4-6jhm / CVE-2021-23337
Command Injection via template function & Prototype Pollution in zipObjectDeep.
>=4.17.21
axios@0.21.1HIGH
GHSA-cph5-m8f7-6c5x / CVE-2021-3749
Server-Side Request Forgery (SSRF) & Regular Expression Denial of Service (ReDoS).
>=1.7.4
express@4.17.1MODERATE
GHSA-rv95-896h-c2vc / CVE-2024-29041
Open Redirect vulnerability in malformed URL location handling.
>=4.19.2
next@14.1.0HIGH
GHSA-fr5h-rqp8-mj6g / CVE-2024-34351
Server-Side Request Forgery (SSRF) in Server Actions Host header redirect.
>=14.2.10
jsonwebtoken@8.5.1CRITICAL
GHSA-27h2-hvpr-p74q / CVE-2022-23529
Improper verification of secretOrPublicKey enables arbitrary code execution.
>=9.0.0
One-Line Upgrade & Remediation Command
npm install lodash@^4.17.21 axios@^1.7.4 express@^4.19.2 next@^14.2.10 jsonwebtoken@^9.0.0 && npm audit fix
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Live package.json & requirements.txt CVE Dependency Auditor](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/github-security-advisory-npm-pip-auditor/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/github-security-advisory-npm-pip-auditor/">Live package.json & requirements.txt CVE Dependency Auditor — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Live package.json & requirements.txt CVE Dependency Auditor

Quick Answer & 2026 Technical Summary (package json vulnerability scanner osv)Updated 2026 Standard

Your browser parses the package names and version numbers locally and sends a batch query to Google's open-source **OSV.dev API** (`api.osv.dev`), which aggregates live advisories from the **GitHub Security Advisory Database (GHSA)**, **National Vulnerability Database (NVD)**, **PyPA Advisory Database (PYSEC)**, and **RustSec/GoVulnDB**. Use this interactive package json vulnerability scanner osv above to test online package.json cve security scanner, requirements.txt vulnerability checker osv.dev, and github security advisory dependency auditor locally in your browser with zero server uploads.

Target Keyword Spec: package json vulnerability scanner osv | Modules: Live Google OSV.dev & GitHub Advisory (GHSA/CVE) Batch Query Engine • SemVer Range Normalizer & Pinning Hygiene Linter • CVSS Severity Breakdown & Patched Version Resolver
Primary Focus: package json vulnerability scanner osv
Core Capability: online package.json cve security scanner
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Live Google OSV.dev & GitHub Advisory (GHSA/CVE) Batch Query Engineonline package.json cve security scannerParse `dependencies` and `devDependencies` from `package.json` or pinned pa...Rapid CI/CD & Pull Request Dependency Triage
SemVer Range Normalizer & Pinning Hygiene Linterrequirements.txt vulnerability checker osv.devStrip caret (`^`), tilde (`~`), and `>=` range operators to test resolved v...Auditing Legacy Repositories Before Running `npm install`
CVSS Severity Breakdown & Patched Version Resolvergithub security advisory dependency auditorInspect full advisory details including GHSA/CVE/PYSEC identifiers, CVSS v3...DevSecOps Supply-Chain Pinning & SBOM Hygiene
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

10 Best DevSecOps & Automation Tools to Use in 2026

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Live package.json & requirements.txt CVE Dependency Auditor

01

Select Ecosystem (`package.json` npm or `requirements.txt` PyPI)

Choose Node.js (`package.json`) or Python (`requirements.txt`), or load one of the built-in vulnerable manifest presets (Legacy Express/Lodash or Vulnerable Django/Requests).

02

Paste Your Manifest & Run the Live OSV.dev Audit

Click 'Run Live CVE Audit' to parse all package names and versions and execute a live batch query against the OSV.dev / GitHub Advisory API.

03

Inspect Discovered CVEs, GHSA Advisories & Fixed Versions

Expand any flagged package to view its CVE/GHSA IDs, CVSS severity, vulnerability summary, and the exact `fixed` SemVer release.

04

Copy the Upgrade CLI Command or Patched Manifest

Copy the generated `npm install` / `pip install` remediation one-liner to upgrade all vulnerable dependencies to their patched versions.

Key Capabilities & Technical Architecture

Live Google OSV.dev & GitHub Advisory (GHSA/CVE) Batch Query Engine

Parse `dependencies` and `devDependencies` from `package.json` or pinned packages from `requirements.txt` and query `https://api.osv.dev/v1/querybatch` directly from your browser.

SemVer Range Normalizer & Pinning Hygiene Linter

Strip caret (`^`), tilde (`~`), and `>=` range operators to test resolved versions while flagging risky wildcard (`*`), `latest`, Git URL, and unpinned floating dependencies.

CVSS Severity Breakdown & Patched Version Resolver

Inspect full advisory details including GHSA/CVE/PYSEC identifiers, CVSS v3/v4 severity ratings, CWE classifications, vulnerability summaries, and the exact minimum fixed version.

One-Click Remediation CLI (`npm install` / `pip install`) & SBOM Exporter

Generate copy-ready `npm install pkg@fixed` or `pip install pkg==fixed` upgrade commands alongside a CycloneDX-style JSON Software Bill of Materials (SBOM) summary.

Practical Use Cases

Rapid CI/CD & Pull Request Dependency Triage

Paste any project's `package.json` or `requirements.txt` during code review to immediately check for known Remote Code Execution (RCE), Prototype Pollution, or ReDoS CVEs.

Auditing Legacy Repositories Before Running `npm install`

Inspect unfamiliar open-source repos or CTF templates in the browser before executing local package installation scripts on your workstation.

DevSecOps Supply-Chain Pinning & SBOM Hygiene

Identify floating `^`/`~` SemVer ranges that expose builds to transitive dependency drift and generate exact pinned upgrade manifests.

Frequently Asked Questions (FAQs)

How does this tool scan dependencies for real CVEs directly in the browser?+

Your browser parses the package names and version numbers locally and sends a batch query to Google's open-source **OSV.dev API** (`api.osv.dev`), which aggregates live advisories from the **GitHub Security Advisory Database (GHSA)**, **National Vulnerability Database (NVD)**, **PyPA Advisory Database (PYSEC)**, and **RustSec/GoVulnDB**.

Why are caret (`^`) and tilde (`~`) version ranges risky in production `package.json` files?+

In npm SemVer syntax, `^1.2.3` permits any minor or patch update up to `<2.0.0`. If you deploy without a committed `package-lock.json` and `npm ci`, a freshly published compromised minor version (supply-chain typosquatting or maintainer account takeover) can be pulled automatically during CI builds.

What is the difference between a CVE ID and a GHSA ID?+

CVE (Common Vulnerabilities and Exposures, e.g., `CVE-2021-23337`) is the centralized identifier assigned by MITRE and CVE Numbering Authorities (CNAs). GHSA (GitHub Security Advisory, e.g., `GHSA-35jh-r3h4-6jhm`) is GitHub's native open-source ecosystem advisory identifier, which maps directly to CVEs and tracks exact affected/patched SemVer ranges for npm, PyPI, Maven, Cargo, and Go.

Why should DevSecOps pipelines use `npm ci` instead of `npm install`?+

`npm install` can modify `package-lock.json` and resolve newer sub-dependencies that match loose ranges in `package.json`. In contrast, `npm ci` strictly enforces the exact cryptographic SHA-512 integrity hashes and versions recorded in `package-lock.json` and aborts immediately if `package.json` and the lockfile are out of sync.

Does pasting my `package.json` leak private proprietary code?+

No. Your manifest is parsed locally in your browser, and only the list of `{ package: { name, ecosystem }, version }` objects is queried against the public OSV.dev API over HTTPS.