The Cycle Import Check Project maintains a niche development utility focused on detecting circular dependencies within import structures, presenting a minimal attack surface limited to its single specialized tool. As a narrowly scoped component, this vendor's vulnerability profile reflects its focused role in the build and development pipeline rather than broad system exposure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cycle Import Check Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24377CRITICAL The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization. | Dec 14, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cycle Import Check Project.
Media articles that mention a CVE ID that affects a product developed by Cycle Import Check Project — matched by CVE ID, not by vendor name.