CRAIR CRA Readiness Snapshot

akaunting/akaunting · composer.lock + package-lock.json · 14 Sep 2026, 02:12 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
1661
dependencies in scope
56
known vulnerabilities
0
actively exploited (CISA KEV)
2.3%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.

All findings (56)

PackageVersionAdvisorySeverityEPSSFixed inSummary
ajv 6.10.0 CVE-2020-15366 MODERATE 2.3% 6.12.3 Prototype Pollution in Ajv
quill 1.3.7 CVE-2021-3163 MODERATE 1.3% Cross-site Scripting in quill
plank/laravel-mediable 5.9.1 CVE-2026-49970 HIGH 1.0% 7.0.0 Laravel-Mediable: path traversal vulnerability in the File::sanitizePath()
webpack dev 5.88.2 CVE-2024-43788 MODERATE 1.0% 5.94.0 Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS
cross-spawn dev 5.1.0 CVE-2024-21538 HIGH 0.9% 7.0.5 Regular Expression Denial of Service (ReDoS) in cross-spawn
dompdf/dompdf 2.0.8 CVE-2026-59942 MODERATE 0.7% 3.1.6 Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
laravel/framework 10.50.3 CVE-2026-48019 HIGH 0.7% 13.10.0 Laravel Framework: CRLF injection in default email rule
tar dev 6.2.1 CVE-2026-59871 MODERATE 0.6% 7.5.18 node-tar: Process crash via PAX numeric path type confusion
mathjs 14.9.1 CVE-2026-41139 HIGH 0.6% 15.2.0 mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
webpack-dev-server dev 4.15.2 CVE-2025-30359 MODERATE 0.6% 5.2.1 webpack-dev-server users' source code may be stolen when they access a malicious web site
tar dev 6.2.1 CVE-2026-59873 CRITICAL 0.6% 7.5.19 node-tar: Decompression/parse DoS via unlimited input
@babel/runtime 7.2.0 CVE-2025-27789 MODERATE 0.6% 7.26.10 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
@babel/runtime 7.1.2 CVE-2025-27789 MODERATE 0.6% 7.26.10 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
@babel/runtime 7.3.4 CVE-2025-27789 MODERATE 0.6% 7.26.10 Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
mathjs 14.9.1 CVE-2026-40897 HIGH 0.6% 15.2.0 Unsafe object property setter in mathjs
tar dev 6.2.1 CVE-2026-24842 HIGH 0.5% 7.5.7 node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
vue 2.7.16 CVE-2024-9506 LOW 0.5% 3.0.0-alpha.0 ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
webpack-dev-server dev 4.15.2 CVE-2026-14620 MODERATE 0.5% 5.2.6 webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
minimatch dev 3.0.8 CVE-2026-26996 HIGH 0.5% 10.2.1 minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
minimatch dev 3.0.8 CVE-2026-27903 HIGH 0.5% 10.2.3 minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
webpack-dev-server dev 4.15.2 CVE-2026-14631 MODERATE 0.5% 5.2.6 webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
dompdf/dompdf 2.0.8 CVE-2026-59941 MODERATE 0.5% 3.1.6 Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
tar dev 6.2.1 CVE-2026-59875 MODERATE 0.5% 7.5.17 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
vue-template-compiler dev 2.7.16 CVE-2024-6783 MODERATE 0.5% vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
ajv 6.10.0 CVE-2025-69873 MODERATE 0.5% 8.18.0 ajv has ReDoS when using `$data` option
minimatch dev 3.0.8 CVE-2026-27904 HIGH 0.5% 10.2.3 minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
serialize-javascript dev 6.0.2 CVE-2026-34043 MODERATE 0.5% 7.0.5 Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
tar dev 6.2.1 CVE-2026-29786 HIGH 0.4% 7.5.10 tar has Hardlink Path Traversal via Drive-Relative Linkpath
tar dev 6.2.1 CVE-2026-59874 HIGH 0.4% 7.5.18 node-tar: Negative tar entry size causes infinite loop in archive replace
swiper 9.4.1 CVE-2026-27212 CRITICAL 0.4% 12.1.2 Prototype pollution in swiper

+ 26 further findings (mostly lower severity) — available in the full export.

SBOM summary

1661 direct dependencies scanned (1661 pinned to exact versions) from composer.lock, package-lock.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us