npm

openai

1 versiondiscovered · its AI-security audit & verification record by name.

4.73.1vulnerability foundresolved-commitverified
coverage →

openai/openai-node @ c3d4e5f60718293a…

AI security assessmentfindingsrisk: mediumqwen2.5-7b-instruct

Retry/backoff loop can be driven unbounded by a crafted rate-limit response.

2026-08-16confidence 74%not a signed attestation — automated pre-screen
  • mediumUnbounded retry amplification on crafted Retry-AfterCWE-400src/core.ts:512
Methodology
Sources @ c3d4e5f607
README.md, src/core.ts, src/streaming.ts, src/error.ts, src/resources/chat/completions.ts, src/lib/AbstractPage.ts
Parts 6 files, 12700 bytes (truncated)
Techniques llm-static-source-review, prompt-injection-detection, insecure-tool-and-function-calling, unsafe-eval-exec-of-model-output, ssrf-detection, secret-exposure-detection, classic-software-vulnerability-review
Parameters qwen2.5-7b-instruct · temp 0 · max 900 tok · local
  • This audit found an active vulnerability (CWE-400) at this exact commit — do not skip-scan; signet gate fails this version.

    classes examined: CWE-400

Gate this package in CI

Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.

signet gate --purl pkg:npm/openai@4.73.1 --registry https://signet.seekerslab.com

README badge

Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.

![signet](https://signet.seekerslab.com/v1/badge/npm/openai.svg)

← Back to the package dictionary