A critical RCE vulnerability (CVSS 8.1) in pac-resolver via unsafe Node.js VM module usage. The package had ~3M weekly downloads and was a transitive dependency of AWS CDK, Firebase CLI, and many enterprise applications via the proxy-agent package.
VULN_RECENT_FREQUENCY + maintainer health preconditions
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | VULN_RECENT_FREQUENCY + maintainer health preconditions |
| Socket | After damage | Detects after CVE published |
| Snyk | After damage | CVE detection after publication; reactive not proactive |
| Sonatype (Nexus) | After damage | Detects after CVE published |
| Black Duck | After damage | Detects after CVE published |
| Endor Labs | After damage | CVE detection + reachability analysis after publication; reactive |