SECURITY ADVISORIES

Affected versions. All versions. Dates.

The PexLens research team publishes as a formal advisory. Each advisory includes a permanent ID you can cite in a ticket, an audit report, or an email.
0
advisories published
0
rated critical
0
CVE IDs credited
0h
median publish time

03 Severity Explained

What each level asks you to do

Severity is Editorial

A researcher may raise or lower the CVSS-derived level based on real-world exploitability. When they do, the advisory shows both the computed score and the reason for the override.
Critical
CVSS 9.0 – 10.0

Act today

Active exploitation or a malicious package in wide use. Assume compromise and rotate credentials.
High
CVSS 7.0 – 8.9

Act this week

Serious impact but conditions apply — specific configuration, version or reachable code path.
Medium
CVSS 4.0 – 6.9

Next planned release

Real but limited impact, or hard to reach in a typical deployment.
Low
CVSS 0.1 – 3.9

Note it

Worth recording for completeness. No urgency, but the register stays honest by including it.

03 ADVISORY SEVERITY

We score severity using industry standards.

Every advisory is evaluated using CVSS v3.1 to help you prioritize risk and focus on what matters most.
CVSS v3.1
Common Vulnerability Scoring System
Critical
CVSS 9.0 – 10.0
Active exploitation or a malicious package in wide use. Assume compromise and rotate credentials.
High
CVSS 7.0 – 8.9
Serious impact but conditions apply — specific configuration, version or reachable code path.
Medium
CVSS 4.0 – 6.9
Real but limited impact, or hard to reach in a typical deployment.
Low
CVSS 0.1 – 3.9
Worth recording for completeness. No urgency, but the register stays honest by including it.

ADVISORY CLASSES

Two types of findings we publish.

Malicious Packages

Intentional
Packages with intentional malicious behavior.
  • May steal credentials, tokens, crypto or sensitive data
  • Often part of campaigns or supply-chain attacks
  • Indicators of compromise (IOCs) are provided

Vulnerabilities

Unintentional
Unintentional security weaknesses in otherwise legitimate packages.
  • Bugs or design flaws that can be exploited
  • Impact depends on configuration and usage
  • CVE ID assigned when eligible

All advisories undergo human review and validation before publication. See our disclosure timeline and research process to learn how we work.

Learn about our process
Sandbox & Runtime Analysis

Deep insights into suspicious behavior.

We execute packages in isolated environments to analyze runtime behavior and detect malicious and risky activity across all packages.
Total Scans
0
Malicious / Elevated Detections
0
Mitre Att&ck Techniques
0
Monitored Files
0
Processes & DNS
0
Threat Intelligence

Threat signals from across the ecosystem.

We collect and analyze threat indicators from multiple sources across the ecosystem and the open web.
IOC IP Addresses
0.0K
IOC Domains
0.3M
IOC Emails
0.7K
Bitcoin Addresses
0.7K
Socket Alerts
0.0K
Stay Ahead of Supply Chain Threats

Get early access to advisories and research.

Request a demo to see how PexLens helps you identify, prioritize and respond faster.