Is this CVE real for this package version?

A published CVE can still be disputed, overstated, or wrongly scoped. For each CVE and package version, tots runs two independent investigations: one tests the code in a sandbox, and one collects what maintainers, databases, and vendors have said. A judge model (Jev) scores the evidence, and a fixed policy turns those scores into the label.

CVEPackage versionOfficialtots
CVE-2024-45296path-to-regexp@6.2.2CVE: PUBLISHEDSUPPORTED
CVE-2024-10491express@5.2.1CVE: PUBLISHEDDISPUTED

Assess a CVE

Live investigations are turned off for this deployment.