Pattern

Transitive Dependency Vulnerability

transitive-vuln-persistence

Vulnerable artifacts persist because dependency scanners evaluate the resolved graph (including transitive packages) and supply-chain-injected modules can remain even after direct dependency updates, causing conflicting version ranges, hidden OWASP/NVD matches, and exploitable frontend control paths.