← the swarm
DEPENDENCY CVES
ROT
Maps your dependency tree to CVEs that are actually reachable.
4 findings in sample scan4 CWE classes
// WHAT IT HUNTS
- Known-vulnerable dependencies
- Reachable CVEs
- Prototype pollution
- ReDoS in transitive deps
- Dependency confusion & typosquats
// CWE COVERAGE
CWE-1321CWE-1333CWE-937CWE-1104
Maps your dependency tree to known CVEs and reachable, exploitable versions.
// IN THE SAMPLE SCAN
What ROT found in acme/api-gateway
HIGHPrototype pollution in lodash 4.17.11package-lock.json:2210 · CVE-2021-23337ROTview →MEDRegular expression DoS in axios 0.21.0package-lock.json:88 · CVE-2021-3749ROTview →LOWOutdated minimist 1.2.5 (prototype pollution)package-lock.json:1502 · CVE-2021-44906ROTview →LOWsemver ReDoS in transitive dependencypackage-lock.json:1990 · CVE-2022-25883ROTview →
Point ROT at your code.
Every scan runs the full swarm and returns a single report.