DuckDB powered by WebAssembly
@duckdb/duckdb-wasm has critical vulnerabilities — do not use
Update to >= 1.30.0 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2025-59037 | DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware | 1.30.0 |
| critical | MAL-2025-46991 | Malicious code in @duckdb/duckdb-wasm (npm) | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/@duckdb/duckdb-wasmFirst published · 2021-10-06T19:08:26.926Z
Last updated · 2026-04-13T05:52:20.674Z