
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@aurelia/expression-parser
Advanced tools
[](https://opensource.org/licenses/MIT) [](http://www.typescriptlang.org/) [](https://opensource.org/licenses/MIT) [](http://www.typescriptlang.org/) [.
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.