scancodeio
Automate software composition analysis pipelines
Activity
- Latest release
- 2mo ago
- Total releases
- 49
- Cadence
- ~21 days
- Last 12 months
- 9
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Mar 03, 2023
| Version | Released | |
|---|---|---|
38.0.0
major
|
38.0.0
major
Dependencies (66)
+ 58 more
Changelog
Compare changes
|
|
37.2.0
minor
|
37.2.0
minor
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
37.1.0
minor
|
37.1.0
minor
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
37.0.0
major
|
37.0.0
major
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
36.1.0
minor
|
36.1.0
minor
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
36.0.1
patch
|
36.0.1
patch
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
36.0.0
major
|
36.0.0
major
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
35.5.0
minor
|
35.5.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
35.4.1
patch
|
35.4.1
patch
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
35.4.0
minor
|
35.4.0
minor
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
35.3.0
minor
|
35.3.0
minor
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
35.1.0
minor
|
35.1.0
minor
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
35.0.0
major
|
35.0.0
major
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
34.11.0
minor
| ||
34.10.1
patch
| ||
34.10.0
minor
| ||
34.9.5
patch
| ||
34.9.4
patch
| ||
34.9.3
patch
| ||
34.9.2
patch
| ||
34.9.1
patch
| ||
34.9.0
minor
| ||
34.8.3
patch
| ||
34.8.2
patch
| ||
34.8.1
patch
|
34.8.1
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
34.8.0
minor
|
34.8.0
minor
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
34.7.1
patch
| ||
34.7.0
minor
| ||
34.6.3
patch
| ||
34.6.2
patch
| ||
34.6.1
patch
| ||
34.6.0
minor
| ||
34.5.0
minor
| ||
34.4.0
minor
| ||
34.3.0
minor
| ||
34.2.0
minor
| ||
34.1.0
minor
| ||
34.0.0
major
|
34.0.0
major
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
33.1.0
minor
|
33.1.0
minor
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
33.0.0
major
|
33.0.0
major
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
32.7.0
minor
|
32.7.0
minor
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
32.6.0
minor
|
32.6.0
minor
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
32.5.2
patch
|
32.5.2
patch
Dependencies (42)
+ 34 more
Changelog
Compare changes
|
|
32.5.1
patch
1 CVE
CVE-2023-40024
PYSEC-2026-1905
GHSA-6xcx-gx7r-rccj
Jul 07, 2026
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryIn the DetailsIn the
PoC
ImpactAttackers can exploit the vulnerability to inject malicious scripts into the response generated by the Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
32.5.1
Fixed in
32.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev |
32.5.1
patch
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
32.5.0
minor
2 CVEs
CVE-2023-40024
PYSEC-2026-1905
GHSA-6xcx-gx7r-rccj
Jul 07, 2026
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryIn the DetailsIn the
PoC
ImpactAttackers can exploit the vulnerability to inject malicious scripts into the response generated by the Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
32.5.1
Fixed in
32.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39523
PYSEC-2026-1904
GHSA-2ggp-cmvm-f62f
Jul 07, 2026
ScanCode.io command injection in docker image fetch process
6.8
/ 10
Medium
Adjacent
Low
Low
None
Unchanged
Low
Low
High
Command Injection in docker fetch processSummaryA possible command injection in the docker fetch process as it allows to append malicious commands in the docker_reference parameter. DetailsIn the function
However, the
A malicious user who is able to create or add inputs to a project can inject commands. Although the command injections are blind and the user will not receive direct feedback without logs, it is still possible to cause damage to the server/container. The vulnerability appears for example if a malicious user adds a semicolon after the input of PoC
Mitigations
The Tested on:
References [1] https://github.com/nexB/scancode.io/blob/main/scanpipe/pipes/fetch.py#L185 Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
Fixed in
32.5.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
32.5.0
minor
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
32.4.0
minor
2 CVEs
CVE-2023-40024
PYSEC-2026-1905
GHSA-6xcx-gx7r-rccj
Jul 07, 2026
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryIn the DetailsIn the
PoC
ImpactAttackers can exploit the vulnerability to inject malicious scripts into the response generated by the Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
32.5.1
Fixed in
32.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39523
PYSEC-2026-1904
GHSA-2ggp-cmvm-f62f
Jul 07, 2026
ScanCode.io command injection in docker image fetch process
6.8
/ 10
Medium
Adjacent
Low
Low
None
Unchanged
Low
Low
High
Command Injection in docker fetch processSummaryA possible command injection in the docker fetch process as it allows to append malicious commands in the docker_reference parameter. DetailsIn the function
However, the
A malicious user who is able to create or add inputs to a project can inject commands. Although the command injections are blind and the user will not receive direct feedback without logs, it is still possible to cause damage to the server/container. The vulnerability appears for example if a malicious user adds a semicolon after the input of PoC
Mitigations
The Tested on:
References [1] https://github.com/nexB/scancode.io/blob/main/scanpipe/pipes/fetch.py#L185 Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
Fixed in
32.5.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
32.4.0
minor
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
32.2.0
minor
2 CVEs
CVE-2023-40024
PYSEC-2026-1905
GHSA-6xcx-gx7r-rccj
Jul 07, 2026
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryIn the DetailsIn the
PoC
ImpactAttackers can exploit the vulnerability to inject malicious scripts into the response generated by the Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
32.5.1
Fixed in
32.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39523
PYSEC-2026-1904
GHSA-2ggp-cmvm-f62f
Jul 07, 2026
ScanCode.io command injection in docker image fetch process
6.8
/ 10
Medium
Adjacent
Low
Low
None
Unchanged
Low
Low
High
Command Injection in docker fetch processSummaryA possible command injection in the docker fetch process as it allows to append malicious commands in the docker_reference parameter. DetailsIn the function
However, the
A malicious user who is able to create or add inputs to a project can inject commands. Although the command injections are blind and the user will not receive direct feedback without logs, it is still possible to cause damage to the server/container. The vulnerability appears for example if a malicious user adds a semicolon after the input of PoC
Mitigations
The Tested on:
References [1] https://github.com/nexB/scancode.io/blob/main/scanpipe/pipes/fetch.py#L185 Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
Fixed in
32.5.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
32.2.0
minor
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
32.1.0
minor
2 CVEs
CVE-2023-40024
PYSEC-2026-1905
GHSA-6xcx-gx7r-rccj
Jul 07, 2026
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryIn the DetailsIn the
PoC
ImpactAttackers can exploit the vulnerability to inject malicious scripts into the response generated by the Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
32.5.1
Fixed in
32.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39523
PYSEC-2026-1904
GHSA-2ggp-cmvm-f62f
Jul 07, 2026
ScanCode.io command injection in docker image fetch process
6.8
/ 10
Medium
Adjacent
Low
Low
None
Unchanged
Low
Low
High
Command Injection in docker fetch processSummaryA possible command injection in the docker fetch process as it allows to append malicious commands in the docker_reference parameter. DetailsIn the function
However, the
A malicious user who is able to create or add inputs to a project can inject commands. Although the command injections are blind and the user will not receive direct feedback without logs, it is still possible to cause damage to the server/container. The vulnerability appears for example if a malicious user adds a semicolon after the input of PoC
Mitigations
The Tested on:
References [1] https://github.com/nexB/scancode.io/blob/main/scanpipe/pipes/fetch.py#L185 Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
Fixed in
32.5.1
References
Updated Jul 07, 2026 · Source: OSV.dev |
32.1.0
minor
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
32.0.1
initial
2 CVEs
CVE-2023-40024
PYSEC-2026-1905
GHSA-6xcx-gx7r-rccj
Jul 07, 2026
Scancode.io Reflected Cross-Site Scripting (XSS) in license endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryIn the DetailsIn the
PoC
ImpactAttackers can exploit the vulnerability to inject malicious scripts into the response generated by the Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
32.5.1
Fixed in
32.5.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39523
PYSEC-2026-1904
GHSA-2ggp-cmvm-f62f
Jul 07, 2026
ScanCode.io command injection in docker image fetch process
6.8
/ 10
Medium
Adjacent
Low
Low
None
Unchanged
Low
Low
High
Command Injection in docker fetch processSummaryA possible command injection in the docker fetch process as it allows to append malicious commands in the docker_reference parameter. DetailsIn the function
However, the
A malicious user who is able to create or add inputs to a project can inject commands. Although the command injections are blind and the user will not receive direct feedback without logs, it is still possible to cause damage to the server/container. The vulnerability appears for example if a malicious user adds a semicolon after the input of PoC
Mitigations
The Tested on:
References [1] https://github.com/nexB/scancode.io/blob/main/scanpipe/pipes/fetch.py#L185 Affected versions
32.0.1
32.1.0
32.2.0
32.4.0
32.5.0
Fixed in
32.5.1
References
Updated Jul 07, 2026 · Source: OSV.dev |

