StackRadar

tooljet Helm chart

krzwiatrzyk

Scored 14 Sept 2026

Latest 1.1.1 3 years agoapp version v1.18.0 0Artifact Hub

tooljet 1.1.1 deploys 2 container images: tooljet/tooljet-ce and bitnami/postgresql. Across the 1 measured, 386 findings0 critical, 6 high 2 on CISA KEV. The highest contribution is GHSA-fx4w-v43j-vc45 in typeorm 0.2.41, fixed in 0.3.0. Chart.yaml declares kubeVersion >1.16.0; rendered for Kubernetes 1.16.1.

Radar Score

5,41006101279

386 findings over 1 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
tooljet/tooljet-cev1.18.0061012795,410
bitnami/postgresql14.5.0-debian-11-r35unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

279 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-vcc3-ghjq-m6frdecode-uri-component@0.2.00.5.0
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.70.1.12
LowGHSA-44fp-w29j-9vj5multer@1.4.42.0.0
LowGHSA-hj48-42vr-x3v9path-parse@1.0.61.0.7
LowGHSA-cfm4-qjh2-4765node-forge@1.2.11.3.0
LowGHSA-v62p-rq8g-8h59pbkdf2@3.1.23.1.3
LowDLA-3614-1python3.7@3.7.3-2+deb10u33.7.3-2+deb10u6
LowDSA-5122-1gzip@1.9-31.9-3+deb10u1
LowDSA-5123-1xz-utils@5.2.4-15.2.4-1+deb10u1
LowGHSA-62hf-57xw-28j9axios@0.26.00.31.1
LowGHSA-h7cp-r72f-jxh6pbkdf2@3.1.23.1.3
LowGHSA-x6wf-f3px-wcqx@xmldom/xmldom@0.7.50.8.13
LowDSA-5073-1expat@2.2.6-2+deb10u12.2.6-2+deb10u2
LowGHSA-34x7-hfp2-rc4vtar@4.4.137.5.7
LowGHSA-mq66-vcfc-8246mercurial@4.8.24.9
LowGHSA-fjgf-rc76-4x9pmulter@1.4.42.0.2
LowGHSA-g5hg-p3ph-g8qgmulter@1.4.42.0.1
LowGHSA-3g43-6gmg-66jwaxios@0.26.00.31.1
LowGHSA-cxjh-pqwp-8mfpfollow-redirects@1.14.71.15.6
LowGHSA-ph9p-34f9-6g65tmp@0.2.10.2.6
LowGHSA-554w-wpv2-vw27node-forge@1.2.11.3.2
LowGHSA-hfxv-24rg-xrqfaxios@0.26.00.32.0
LowGHSA-j5f8-grm9-p9fcaxios@0.26.00.32.0
LowDLA-3288-1curl@7.64.0-4+deb10u27.64.0-4+deb10u4
LowDLA-3651-1postgresql-11@11.14-0+deb10u111.22-0+deb10u1
LowGHSA-685m-2w69-288qprotobufjs@6.11.27.5.6
LowGHSA-75px-5xx7-5xc7protobufjs@6.11.27.5.6
LowGHSA-rqff-837h-mm52url-parse@1.5.41.5.6
LowDSA-5087-1cyrus-sasl2@2.1.27+dfsg-1+deb10u12.1.27+dfsg-1+deb10u2
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowGHSA-5375-pq7m-f5r2@grpc/grpc-js@1.4.61.9.16
LowGHSA-pw2r-vq6v-hr8cfollow-redirects@1.14.71.14.8
LowGHSA-f5x3-32g6-xq36tar@4.4.136.2.1
LowGHSA-8cf7-32gw-wr33jsonwebtoken@8.5.19.0.0
LowGHSA-j8xg-fqg3-53r7word-wrap@1.2.31.2.4
LowGHSA-5m6q-g25r-mvwxnode-forge@1.2.11.4.0
LowGHSA-6g55-p6wh-862qpostcss@8.4.128.5.12
LowGHSA-pmwg-cvhr-8vh7axios@0.26.00.31.1
LowGHSA-qffp-2rhf-9h96tar@4.4.137.5.10
LowGHSA-22p9-wv53-3rq4linkify-it@3.0.35.0.1
LowGHSA-j759-j44w-7fr8@xmldom/xmldom@0.7.50.8.13
LowDSA-5142-1libxml2@2.9.4+dfsg1-7+deb10u22.9.4+dfsg1-7+deb10u4
LowDSA-5032-1djvulibre@3.5.27.1-103.5.27.1-10+deb10u1
LowGHSA-23hp-3jrh-7fpwtar@4.4.137.5.19
LowGHSA-93r5-fhx6-vmg9@xmldom/xmldom@0.7.50.8.15
LowGHSA-965w-775f-mr7g@xmldom/xmldom@0.7.50.8.15
LowGHSA-52cp-r559-cp3mjs-yaml@4.1.04.3.0
LowGHSA-27p8-2357-5qqv@xmldom/xmldom@0.7.50.8.15
LowGHSA-4w3w-2rp5-g8jm@xmldom/xmldom@0.7.50.8.14
LowGHSA-c7q8-3ch8-vqpv@xmldom/xmldom@0.7.50.8.15

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.1.1latest3 years agov1.18.0061012795,410

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/krzwiatrzyk/tooljet.svg)](https://charts.stackradar.io/charts/krzwiatrzyk/tooljet)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.