CRAIR CRA Readiness Snapshot

unopim/unopim · composer.lock + package.json · 12 Sep 2026, 10:12 UTC
0 days until the EU Cyber Resilience Act 24-hour reporting obligation applies (11 September 2026), including for products already on the market.
217
dependencies in scope
66
known vulnerabilities
1
actively exploited (CISA KEV)
75.0%
highest exploit probability (EPSS)

What you would have to assess for ENISA reporting tomorrow

From 11 September 2026, an actively exploited vulnerability in software you ship must be reported to ENISA within 24 hours of awareness (CRA Art. 14). In this snapshot, 1 finding is in the CISA KEV catalog (0 in production dependencies):

PackageYour versionCVEFixed inExploit context
vite dev ^6.3.0 (unpinned) CVE-2025-31125 6.2.4 KEV listed 2026-01-22

⚠ No lockfile — SBOM is not reproducible

This scan is based on a manifest (composer.lock, package.json), not a lockfile. 5 of 217 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.

All findings (66)

PackageVersionAdvisorySeverityEPSSFixed inSummary
vite dev ^6.3.0 CVE-2025-30208 MODERATE 75.0% 6.2.3 Vite bypasses server.fs.deny when using ?raw??
vite dev ^6.3.0 CVE-2025-31486 MODERATE 40.5% 6.2.5 Vite allows server.fs.deny to be bypassed with .svg or relative paths
axios dev ^1.6.4 CVE-2021-3749 HIGH 8.5% 0.21.2 axios Inefficient Regular Expression Complexity vulnerability
axios dev ^1.6.4 CVE-2019-10742 HIGH 6.0% 0.18.1 Denial of Service in axios
vite dev ^6.3.0 CVE-2026-39363 HIGH 3.4% 8.0.5 Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
vite dev ^6.3.0 CVE-2023-34092 HIGH 3.1% 2.9.16 Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
axios dev ^1.6.4 CVE-2026-25639 HIGH 2.8% 1.13.5 Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
axios dev ^1.6.4 CVE-2020-28168 MODERATE 2.4% 0.21.1 Axios vulnerable to Server-Side Request Forgery
vite dev ^6.3.0 CVE-2026-39364 HIGH 2.1% 8.0.5 Vite: `server.fs.deny` bypassed with queries
axios dev ^1.6.4 CVE-2026-40175 MODERATE 1.9% 1.15.0 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
vite dev ^6.3.0 CVE-2025-32395 MODERATE 1.7% 6.2.6 Vite has an `server.fs.deny` bypass with an invalid `request-target`
vite dev ^6.3.0 CVE-2022-35204 HIGH 1.3% 2.9.13 Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service
vite dev ^6.3.0 CVE-2025-58751 LOW 1.2% 7.1.5 Vite middleware may serve files starting with the same name with the public directory
axios dev ^1.6.4 CVE-2024-39338 HIGH 1.2% 1.7.4 Server-Side Request Forgery in axios
axios dev ^1.6.4 CVE-2025-62718 MODERATE 1.2% 1.15.0 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
vite dev ^6.3.0 CVE-2025-46565 MODERATE 1.2% 6.3.4 Vite's server.fs.deny bypassed with /. for files under project root
axios dev ^1.6.4 CVE-2025-58754 HIGH 1.1% 1.12.0 Axios is vulnerable to DoS attack through lack of data size check
vite dev ^6.3.0 CVE-2024-45811 MODERATE 1.1% 5.4.6 Vite's `server.fs.deny` is bypassed when using `?import&raw`
axios dev ^1.6.4 CVE-2026-44494 HIGH 1.0% 1.16.0 axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
vite dev ^6.3.0 CVE-2025-62522 MODERATE 1.0% 7.1.11 vite allows server.fs.deny bypass via backslash on Windows
vite dev ^6.3.0 CVE-2023-49293 MODERATE 1.0% 4.4.12 Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
vite dev ^6.3.0 CVE-2026-39365 MODERATE 0.9% 8.0.5 Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
axios dev ^1.6.4 CVE-2026-44492 HIGH 0.9% 1.16.0 axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
axios dev ^1.6.4 CVE-2026-42033 HIGH 0.8% 1.15.1 Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
axios dev ^1.6.4 CVE-2026-44495 HIGH 0.8% 1.15.2 axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
vite dev ^6.3.0 CVE-2024-23331 HIGH 0.8% 2.9.17 Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
axios dev ^1.6.4 CVE-2025-27152 HIGH 0.8% 1.8.2 axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
axios dev ^1.6.4 CVE-2026-42039 MODERATE 0.7% 1.15.1 Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
axios dev ^1.6.4 CVE-2026-39865 MODERATE 0.7% 1.13.2 Axios HTTP/2 Session Cleanup State Corruption Vulnerability
axios dev ^1.6.4 CVE-2026-42264 HIGH 0.7% 1.15.2 Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

+ 36 further findings (mostly lower severity) — available in the full export.

SBOM summary

217 direct dependencies scanned (212 pinned to exact versions) from composer.lock, package.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.

Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.

This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.

Download SBOM (CycloneDX) Want this to watch your product continuously and draft the ENISA report the day something turns exploited? Start monitoring for €99/mo Talk to us