Is this CVE real for this package version?
A published CVE can still be disputed, overstated, or wrongly scoped. For each CVE and package version, tots runs two independent investigations: one tests the code in a sandbox, and one collects what maintainers, databases, and vendors have said. A judge model (Jev) scores the evidence, and a fixed policy turns those scores into the label.
| CVE | Package version | Official | tots | Code | People |
|---|---|---|---|---|---|
| CVE-2024-45296 | path-to-regexp@6.2.2 | CVE: PUBLISHED | SUPPORTED | Reproduces on 6.2.2 fixed 6.3.0: clean | Maintainers confirm 2 say affected · 0 say not |
| CVE-2024-10491 | express@5.2.1 | CVE: PUBLISHED | DISPUTED | Reproduces on 5.2.1 no fixed release found | Maintainers dispute 3 say affected · 5 say not |
Assess a CVE
Live investigations are turned off for this deployment.