Snyk operates a developer-focused security platform centered on dependency scanning, vulnerability assessment, and remediation tooling, with its vulnerability profile concentrated in components such as its CLI, Advisor service, and Broker proxy that integrate into software supply-chain workflows. The recurring weakness classes—including OS command injection, sensitive information exposure, improper authentication, code injection, and path traversal—reflect the input-handling and privilege-boundary demands inherent to tools that parse, execute, or broker access across development environments and artifact repositories. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snyk over time
Of all the CVEs published by Snyk as a CNA, 0.9% affect products that Snyk develops as a vendor.
Of all the CVEs published that affect products developed by Snyk, 80.0% are self-published by Snyk as a CNA.
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24441HIGH The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in | Nov 30, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-48963CRITICAL The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untru | Oct 23, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-40764HIGH Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untru | Oct 3, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
CVE-2024-48964HIGH The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the un | Oct 23, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-22984MEDIUM The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the | Nov 30, 2022 | 6.3 | 23 | NO | NO |
CVE-2025-6624HIGH Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials pr | Jun 26, 2025 | 7.2 | 20 | NO | NO |
CVE-2023-1767MEDIUM The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature of Snyk Advisor is to display the contents of a scanned packa | Apr 20, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-1065MEDIUM This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. | Feb 28, 2023 | 5.3 | 19 | NO | NO |
CVE-2020-7649MEDIUM This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal. | Jul 25, 2022 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snyk.
Media articles that mention a CVE ID that affects a product developed by Snyk — matched by CVE ID, not by vendor name.