StackRadar

tooljet Helm chart

krzwiatrzyk

Scored 14 Sept 2026

Latest 1.1.1 3 years agoapp version v1.18.0 0Artifact Hub

tooljet 1.1.1 deploys 2 container images: tooljet/tooljet-ce and bitnami/postgresql. Across the 1 measured, 386 findings0 critical, 6 high 2 on CISA KEV. The highest contribution is GHSA-fx4w-v43j-vc45 in typeorm 0.2.41, fixed in 0.3.0. Chart.yaml declares kubeVersion >1.16.0; rendered for Kubernetes 1.16.1.

Radar Score

5,41006101279

386 findings over 1 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
tooljet/tooljet-cev1.18.0061012795,410
bitnami/postgresql14.5.0-debian-11-r35unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

386 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-mh29-5h37-fv8mjs-yaml@4.1.04.1.1
LowDLA-3737-1imagemagick@8:6.9.10.23+dfsg-2.1+deb10u18:6.9.10.23+dfsg-2.1+deb10u6
LowGHSA-f38q-mgvj-vph7protobufjs@6.11.27.6.3
LowGHSA-7q8q-rj6j-mhjqaxios@0.26.00.33.0
LowGHSA-h67p-54hq-rp68js-yaml@4.1.04.2.0
LowDLA-3699-1libde265@1.0.3-1+b11.0.11-0+deb10u6
LowGHSA-cj7v-w2c7-cp7c@nestjs/common@8.4.010.4.16
LowGHSA-3jxr-9vmj-r5cpbrace-expansion@1.1.111.1.16
LowGHSA-gh4j-gqv2-49f6fast-xml-parser@3.19.05.7.0
LowGHSA-mwcw-c2x4-8c55nanoid@3.3.23.3.8
LowGHSA-36xv-jgw5-4q75@nestjs/core@8.0.011.1.18
LowGHSA-vmf3-w455-68vhtar@4.4.137.5.16
LowDLA-3352-1libde265@1.0.3-1+b11.0.11-0+deb10u4
LowDLA-3583-1glib2.0@2.58.3-2+deb10u32.58.3-2+deb10u5
LowGHSA-5c9x-8gcm-mpgxaxios@0.26.00.31.1
LowGHSA-vf2m-468p-8v99axios@0.26.00.31.1
LowDLA-3814-1glib2.0@2.58.3-2+deb10u32.58.3-2+deb10u6
LowGHSA-vxvm-qww3-2fh7mongodb@4.2.24.17.0
LowGHSA-qx2v-qp2m-jg93postcss@8.4.128.5.10
LowGHSA-6339-gv7w-g5f4@sap/hana-client@2.12.222.21.31
LowGHSA-9h6g-pr28-7cqpnodemailer@6.7.26.9.9
LowGHSA-f7q4-pwc6-w24pelliptic@6.5.46.5.7
LowGHSA-q6x5-8v7m-xcrfprotobufjs@6.11.27.5.6
LowGHSA-q6x5-8v7m-xcrf@protobufjs/utf8@1.1.01.1.1
LowGHSA-2rp8-mm9q-fp49typeorm@0.2.410.3.31
LowGHSA-2x7j-588g-ccc2nodemailer@6.7.29.1.0
LowGHSA-5p4m-2wfm-xmqjjs-yaml@4.1.04.3.1
LowDLA-3602-1libx11@2:1.6.7-1+deb10u22:1.6.7-1+deb10u4
LowGHSA-fx83-v9x8-x52wprotobufjs@6.11.27.5.6
LowGHSA-jggg-4jg4-v7c6protobufjs@6.11.27.5.8
LowGHSA-4mjr-xmp4-gh2gqs@6.5.26.16.0
LowGHSA-xx6v-rp6x-q39caxios@0.26.00.31.1
LowDLA-3110-1glib2.0@2.58.3-2+deb10u32.58.3-2+deb10u4
LowGHSA-898c-q2cr-xwhgaxios@0.26.00.32.0
LowGHSA-r7g4-qg5f-qqm2nodemailer@6.7.28.0.8
LowGHSA-848j-6mx2-7j84elliptic@6.5.4no fix listed
LowGHSA-268h-hp4c-crq3nodemailer@6.7.28.0.9
LowGHSA-wqvq-jvpq-h66fnodemailer@6.7.28.0.9
LowGHSA-g8qq-57p8-ggw5sanitize-html@2.7.02.17.7
LowDLA-3297-1tiff@4.1.0+git191117-2~deb10u24.1.0+git191117-2~deb10u6
LowGHSA-vccv-cmxp-4j9hsanitize-html@2.7.02.17.5
LowGHSA-wmmp-3585-3rmpnodemailer@6.7.29.1.0
LowDLA-3333-1tiff@4.1.0+git191117-2~deb10u24.1.0+git191117-2~deb10u7
LowDLA-3474-1systemd@241-7~deb10u8241-7~deb10u10
LowGHSA-w7fw-mjwx-w883qs@6.10.36.14.2
LowGHSA-6rw7-vpxm-498pqs@6.5.26.14.1
LowDLA-3771-1python2.7@2.7.16-2+deb10u12.7.16-2+deb10u4
LowDLA-3772-1python3.7@3.7.3-2+deb10u33.7.3-2+deb10u7
LowGHSA-v422-hmwv-36x6body-parser@1.20.01.20.6
LowGHSA-8m3c-c648-2xjjnodemailer@6.7.29.1.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.1.1latest3 years agov1.18.0061012795,410

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/krzwiatrzyk/tooljet.svg)](https://charts.stackradar.io/charts/krzwiatrzyk/tooljet)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.