Cheerio · Vulnerability Disclosure

Cheerio Vulnerability Disclosure

Vulnerability disclosure

Cheerio publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Data ExtractionDOMHTMLHTML ParsingjQueryMIT LicenseNode.jsnpmOpen-SourceParserScrapingServer-SideWeb ScrapingXML
Program: security.txt present

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
https://tidelift.com/security
Contact
https://github.com/cheeriojs/cheerio/security/advisories/new

Source

Vulnerability Disclosure

cheerio-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-05'
method: searched
probe: true
source: https://github.com/cheeriojs/cheerio/blob/main/SECURITY.md
note: >-
  probe-security-programs.py reported vdp=none because cheerio.js.org serves no
  /.well-known/security.txt and no /security page — the project publishes its policy
  in the repository instead, at SECURITY.md, which is where a Node.js library's
  consumers look. Fetched verbatim 2026-09-05 (HTTP 200 from raw.githubusercontent.com).
policy:
  - https://github.com/cheeriojs/cheerio/blob/main/SECURITY.md
  - https://tidelift.com/security
  - https://github.com/cheeriojs/cheerio/security/advisories/new
contact:
  - https://tidelift.com/security
  - https://github.com/cheeriojs/cheerio/security/advisories/new
coordinator: Tidelift
private_reporting: GitHub private vulnerability reporting (Security Advisories)
public_issues_accepted: false
supported_versions:
  - version: 1.x
    supported: true
  - version: '<1.0'
    supported: false
    note: Only the latest release on the 1.x branch receives security updates.
sla:
  acknowledgment: 72 hours
  process:
    - Acknowledgment within 72 hours
    - Triage — severity, impact, affected versions
    - Fix and release a patch
    - Disclosure via a GitHub Security Advisory, crediting the reporter unless anonymity is requested
in_scope:
  - Denial of service (ReDoS, quadratic parsing, excessive memory or CPU on crafted input)
  - Prototype pollution through parsed content or API misuse
  - Cross-site scripting enablement through unexpected serialization output
  - Supply chain — compromised dependencies, build pipeline or release artifacts
  - Information disclosure through parsing or serialization behavior
out_of_scope:
  - Vulnerabilities in applications using cheerio caused by their own logic (e.g. not sanitizing cheerio output before rendering)
  - Social engineering attacks against maintainers
related_documents:
  - https://github.com/cheeriojs/cheerio/blob/main/THREAT_MODEL.md
  - https://github.com/cheeriojs/cheerio/blob/main/INCIDENT_RESPONSE.md
  - https://cheerio.js.org/docs/advanced/security/
evidence:
  - source: https://raw.githubusercontent.com/cheeriojs/cheerio/main/SECURITY.md
    kind: security-policy
    http_status: 200
    fetched: '2026-09-05'
  - source: https://raw.githubusercontent.com/cheeriojs/cheerio/main/THREAT_MODEL.md
    kind: threat-model
    http_status: 200
    fetched: '2026-09-05'
  - source: https://raw.githubusercontent.com/cheeriojs/cheerio/main/INCIDENT_RESPONSE.md
    kind: incident-response-plan
    http_status: 200
    fetched: '2026-09-05'
  - source: https://cheerio.js.org/.well-known/security.txt
    kind: security.txt
    http_status: 404
    fetched: '2026-09-05'
    result: absent — policy is published in the repository instead
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cheerio-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.