{"id":8441032,"name":"@janhq/core","ecosystem":"npm","description":"Jan app core lib","homepage":"https://jan.ai/","licenses":"AGPL-3.0","normalized_licenses":["AGPL-3.0"],"repository_url":"","keywords_array":["jan","core"],"namespace":"janhq","versions_count":12,"first_release_published_at":"2023-10-17T06:57:23.781Z","latest_release_published_at":"2024-12-10T09:31:27.314Z","latest_release_number":"0.2.0","last_synced_at":"2026-10-08T09:09:28.526Z","created_at":"2023-10-17T09:18:08.232Z","updated_at":"2026-10-08T09:09:28.526Z","registry_url":"https://www.npmjs.com/package/@janhq/core","install_command":"npm install @janhq/core","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"0.2.0"},"contentPolicy":null},"repo_metadata":{},"repo_metadata_updated_at":"2026-10-05T09:08:15.969Z","dependent_packages_count":7,"downloads":89,"downloads_period":"last-month","dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":37.122662779541514,"dependent_packages_count":52.636007497571505,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":44.87933513855651},"purl":"pkg:npm/%40janhq/core","advisories":[{"uuid":"GSA_kwCzR0hTQS04NzhoLXJxY3EtbXYzeM4AA8s7","url":"https://github.com/advisories/GHSA-878h-rqcq-mv3x","title":"Jan path traversal vulnerability","description":"An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-06-04T21:32:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-37273","https://github.com/HackAllSec/CVEs/tree/main/Jan%20Arbitrary%20File%20Upload%20vulnerability","https://github.com/advisories/GHSA-878h-rqcq-mv3x"],"source_kind":"github","identifiers":["GHSA-878h-rqcq-mv3x","CVE-2024-37273"],"repository_url":"https://github.com/HackAllSec/CVEs","blast_radius":1.0,"created_at":"2024-06-11T20:05:43.266Z","updated_at":"2026-09-24T15:09:05.079Z","epss_percentage":0.00989,"epss_percentile":0.60994,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NzhoLXJxY3EtbXYzeM4AA8s7","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NzhoLXJxY3EtbXYzeM4AA8s7","packages":[{"ecosystem":"npm","package_name":"@janhq/core","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.1.11"}],"purl":"pkg:npm/%40janhq%2Fcore"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NzhoLXJxY3EtbXYzeM4AA8s7/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xZmpoLW12cTYtYzVwOM4AA8s6","url":"https://github.com/advisories/GHSA-qfjh-mvq6-c5p8","title":"Jan path traversal vulnerability","description":"An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file. @janhq/core has been deprecated in favor of janhq/jan, this vulnerability has been patched there in v0.5.2.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-06-04T21:32:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-36858","https://github.com/HackAllSec/CVEs/tree/main/Jan%20Arbitrary%20File%20Upload%20vulnerability","https://github.com/janhq/jan/pull/3152","https://github.com/advisories/GHSA-qfjh-mvq6-c5p8"],"source_kind":"github","identifiers":["GHSA-qfjh-mvq6-c5p8","CVE-2024-36858"],"repository_url":"https://github.com/HackAllSec/CVEs","blast_radius":1.0,"created_at":"2024-06-11T20:05:43.576Z","updated_at":"2026-08-28T13:07:39.204Z","epss_percentage":0.03035,"epss_percentile":0.86513,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xZmpoLW12cTYtYzVwOM4AA8s6","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xZmpoLW12cTYtYzVwOM4AA8s6","packages":[{"ecosystem":"npm","package_name":"@janhq/core","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.1.11"}],"purl":"pkg:npm/%40janhq%2Fcore"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xZmpoLW12cTYtYzVwOM4AA8s6/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01anFjLXFqNTctNGhyY84AA8s5","url":"https://github.com/advisories/GHSA-5jqc-qj57-4hrc","title":"Jan path traversal vulnerability","description":"Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-06-04T21:32:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-36857","https://github.com/HackAllSec/CVEs/tree/main/Jan%20AFR%20vulnerability","https://github.com/advisories/GHSA-5jqc-qj57-4hrc"],"source_kind":"github","identifiers":["GHSA-5jqc-qj57-4hrc","CVE-2024-36857"],"repository_url":"https://github.com/HackAllSec/CVEs","blast_radius":1.0,"created_at":"2024-06-11T20:05:43.616Z","updated_at":"2026-09-30T09:09:59.014Z","epss_percentage":0.02054,"epss_percentile":0.805,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01anFjLXFqNTctNGhyY84AA8s5","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01anFjLXFqNTctNGhyY84AA8s5","packages":[{"ecosystem":"npm","package_name":"@janhq/core","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.1.11"}],"purl":"pkg:npm/%40janhq%2Fcore"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01anFjLXFqNTctNGhyY84AA8s5/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/@janhq/core","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/npm/@janhq/core","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/@janhq/core/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@janhq%2Fcore/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@janhq%2Fcore/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@janhq%2Fcore/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@janhq%2Fcore/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@janhq%2Fcore/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@janhq%2Fcore/codemeta","maintainers":[{"uuid":"jan-service-account","login":"jan-service-account","name":null,"email":"service@jan.ai","url":null,"packages_count":33,"html_url":"https://www.npmjs.com/~jan-service-account","role":null,"created_at":"2023-10-17T17:19:09.998Z","updated_at":"2023-10-17T17:19:09.998Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/jan-service-account/packages"},{"uuid":"louisle","login":"louisle","name":null,"email":"louis@jan.ai","url":null,"packages_count":25,"html_url":"https://www.npmjs.com/~louisle","role":null,"created_at":"2023-10-17T17:19:09.964Z","updated_at":"2023-10-17T17:19:09.964Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/louisle/packages"},{"uuid":"vanalite","login":"vanalite","name":null,"email":"vanalite0604@gmail.com","url":null,"packages_count":13,"html_url":"https://www.npmjs.com/~vanalite","role":null,"created_at":"2025-12-22T12:34:22.251Z","updated_at":"2025-12-22T12:34:22.251Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/vanalite/packages"}]}