StackRadar

CVE-2024-53866

Medium

Advisory

Published 10 Dec 2024In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.8
base score, highest
EPSS
0.009
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
pnpmnpm7.28.0, 8.3.1, 8.10.2, 8.15.1+5 more9.15.010
OSV records
GHSA-vm32-9rqf-rh3r

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
pnpm@9.10.0
9.15.0

Open the chart page →

3,451
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
pnpm@7.28.0
9.15.0

Open the chart page →

2,635
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
pnpm@9.10.0
9.15.0

Open the chart page →

32,501
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
pnpm@9.12.2
9.15.0

Open the chart page →

19,224
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
pnpm@8.15.9
9.15.0

Open the chart page →

1,847
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
pnpm@9.10.0
9.15.0

Open the chart page →

3,451
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
pnpm@9.14.2
9.15.0

Open the chart page →

3,614
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
pnpm@8.15.1
9.15.0

Open the chart page →

2,178
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
pnpm@8.10.2
9.15.0

Open the chart page →

13,819
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pnpm@9.5.0
9.15.0

Open the chart page →

4,647
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2024-53866.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
pnpm@8.3.1
9.15.0

Open the chart page →

4,560

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hoppscotch/hoppscotch:2024.8.2f1da831950b7
pnpm@9.10.0
9.15.0
2
activepieces/activepieces:0.23.0c26188b44e62
pnpm@7.28.0
9.15.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
pnpm@9.14.2
9.15.0
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
pnpm@8.10.2
9.15.0
1
kubebb/component-store:latestfd8ecbd73213
pnpm@8.15.1
9.15.0
1
langgenius/dify-web:1.0.0d64914ff0d6d
pnpm@9.12.2
9.15.0
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
pnpm@8.3.1
9.15.0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
pnpm@9.10.0
9.15.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pnpm@9.5.0
9.15.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
pnpm@8.15.9
9.15.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.