Spectra Assure
Community
Docs
failRisk: Vulnerabilities
Scanned: 9 days ago

NuGet

latest
Top 1k
Create Nuget repos, Register Repos, Manage Modules and Packages with a single DSC Module. This Module Exports 5 Resources, Nuget, PSRepo, PackageRepo, Nuget_Module, and Nuget_Package Examples show off all the core functionality as well as support Kitchen integration. View the source @ https://github.com/PowerShellOrg/NuGet to raise issues or modify functionality
License: unknown
Published: about 9 years ago




SAFE Assessment

Compliance

Licenses
No license compliance issues
Secrets
3 debugging symbols found

Security

Vulnerabilities
1 severe vulnerabilities exploited
Hardening
No application hardening issues

Threats

Tampering
No evidence of software tampering
Malware
No evidence of malware inclusion

Popularity

9.05M
Total Downloads
Contributors
Declared Dependencies
1
Dependents

Top issues

Problem

Software composition analysis has identified a component with one or more known severe vulnerabilities. Available threat intelligence telemetry has confirmed that the reported high or critical severity vulnerabilities are actively being exploited by malicious actors.

Prevalence in PowerShell Gallery community

2 packages
found in
Top 100
26 packages
found in
Top 1k
118 packages
found in
Top 10k
190 packages
in community

Next steps

We strongly advise updating the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Problem

Software composition analysis has identified a component with one or more known vulnerabilities. Based on the CVSS scoring, these vulnerabilities have been marked as critical severity.

Prevalence in PowerShell Gallery community

2 packages
found in
Top 100
21 packages
found in
Top 1k
107 packages
found in
Top 10k
170 packages
in community

Next steps

Perform impact analysis for the reported CVEs.
We strongly advise updating the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Problem

Software composition analysis has identified a component with one or more known vulnerabilities. Based on the CVSS scoring, these vulnerabilities have been marked as high severity.

Prevalence in PowerShell Gallery community

2 packages
found in
Top 100
27 packages
found in
Top 1k
118 packages
found in
Top 10k
195 packages
in community

Next steps

Perform impact analysis for the reported CVEs.
Update the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Problem

Software composition analysis has identified a component with one or more known vulnerabilities. Based on the CVSS scoring, these vulnerabilities have been marked as medium severity.

Prevalence in PowerShell Gallery community

2 packages
found in
Top 100
23 packages
found in
Top 1k
77 packages
found in
Top 10k
146 packages
in community

Next steps

Perform impact analysis for the reported CVEs.
Update the component to the latest version.
If the update can't resolve the issue, create a plan to isolate or replace the affected component.

Problem

Program database (PDB) files are typically only used during software development. They contain private debug symbols that make it significantly easier to reverse engineer a closed source application. In some cases, having a program database file is equivalent to having access to the source code. Presence of program databases could indicate that one or more software components have been built using a debug profile, instead of the release.

Prevalence in PowerShell Gallery community

3 packages
found in
Top 100
108 packages
found in
Top 1k
239 packages
found in
Top 10k
423 packages
in community

Next steps

Remove private debug database files from the software package before you release it.

Top behaviors

Prevalence in PowerShell Gallery community

Behavior often found in this community (Common)
4 packages
found in
Top 100
53 packages
found in
Top 1k
326 packages
found in
Top 10k
512 packages
in community

Prevalence in PowerShell Gallery community

Behavior uncommon for this community (Uncommon)
0 packages
found in
Top 100
21 packages
found in
Top 1k
132 packages
found in
Top 10k
194 packages
in community

Prevalence in PowerShell Gallery community

Behavior often found in this community (Common)
90 packages
found in
Top 100
509 packages
found in
Top 1k
3113 packages
found in
Top 10k
5185 packages
in community

Prevalence in PowerShell Gallery community

Behavior commonly used by malicious software (Important)
Behavior uncommon for this community (Uncommon)
0 packages
found in
Top 100
4 packages
found in
Top 1k
12 packages
found in
Top 10k
20 packages
in community

Prevalence in PowerShell Gallery community

Behavior often found in this community (Common)
100 packages
found in
Top 100
804 packages
found in
Top 1k
6518 packages
found in
Top 10k
11726 packages
in community

Top vulnerabilities

Vulnerability Exploitation Lifecycle
(5 Active Vulnerabilities)
3 (3 Fixable)
CVE-2017-5946c
CVE-2018-1000201h
CVE-2025-54314l
2 (2 Fixable)
CVE-2018-1000544c
CVE-2019-16892m
None
None
Exploits Unknown
Exploits Exist
Exploited by Malware
Patching Mandated