retire.js: detecting vulnerable JavaScript dependencies

retire.js · Apache-2.0

retire.js identifies JavaScript libraries with known vulnerabilities. It fingerprints library versions from file contents and URLs, then matches them against a vulnerability database. It is one of the few checks that works equally well from outside — you do not need the source repository, only the bundle the site serves.

Install

npm install -g retire

Core commands

# a project directory
retire --path ./frontend

# only JavaScript, ignore node_modules
retire --path ./frontend --js --ignore node_modules

# JSON for import
retire --path ./frontend --outputformat json --outputpath retire.json

# severity threshold
retire --path ./frontend --severity high

For remote scanning, download the bundles first and scan the directory — the browser extension covers ad-hoc checks but does not script well.

Output

{"file":"static/jquery-1.8.3.min.js","results":[{"component":"jquery","version":"1.8.3",
 "vulnerabilities":[{"severity":"medium","identifiers":{"CVE":["CVE-2015-9251"]},
 "info":["https://github.com/jquery/jquery/issues/2432"]}]}]}

Where it sits in Tandera

retire.js runs in the analyze phase of recon_web_lite and recon_web_full, against the JavaScript assets recovered during crawling. Because it needs no active payloads, it is allowed in the NonIntrusive lite flow.

Its CVE identifiers map onto the finding catalogue, so a vulnerable library becomes a finding with a CVE, a CVSS score and EPSS context rather than a raw version string.

Using it in a pentest

Version-based findings need exploitability context or they are noise. “jQuery 1.8.3 has CVE-2015-9251” is true and nearly useless on its own. The client needs to know whether the vulnerable code path is reachable in this application. Check it before you assign a severity.

Check the CDN, not just the bundle. Applications frequently load a modern framework locally and an ancient utility library from a CDN. The CDN copy is the one nobody tracks.

Prefer the version over the CVE in the remediation. “Upgrade jQuery to 3.5.0 or later” is actionable. A list of CVE identifiers is a research task you are handing back to the client.

early access

Get Tandera before your next engagement.

Join the waitlist for early access. We are onboarding pentest teams in waves.

Priority onboarding for pentest teams.
A direct line to the people building it.
Early-access pricing, locked in.

No spam, no card. Unsubscribe anytime.

enespt-br