Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
MAL-2025-37947
See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/url.resolve/MAL-2025-37947.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-37947
Published
2025-08-14T18:52:04Z
Modified
2025-08-14T18:52:04Z
Summary
Malicious code in url.resolve (npm)
Details
The package url.resolve was found to contain malicious code.
Database specific
{ "malicious-packages-origins": null }
References
Credits
Amazon Inspector - FINDER
actran@amazon.com
Affected packages
npm
/
url.resolve
Package
Name
url.resolve
View open source insights on deps.dev
Purl
pkg:npm/url.resolve
Affected ranges
Type
SEMVER
Events
Introduced
0
Unknown introduced version / All previous versions are affected
MAL-2025-37947 - OSV