VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

959 CVEsRSS

CVE-2026-91127High· 8.2
3d ago

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled h…

Twilightfile-viewer · @file-viewer/docEPSS 0.24%via NVD
CVE-2026-84992Medium· 6.1PoC
3d ago

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language …

Twilightimzbf · md-editor-v3EPSS 0.23%via NVD
CVE-2026-77301High· 7.5PoC
3d ago

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value …

Midnightadm-zip · adm-zipEPSS 0.41%via NVD
CVE-2026-86039High· 8.2
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…

Twilightlibp2p · js-libp2pEPSS 0.18%via NVD
CVE-2026-86038High· 7.5PoC
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …

Midnightlibp2p · @libp2p/gossipsubEPSS 0.16%via NVD
CVE-2026-71538High· 8.5
4d ago

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not provide the npm CLI path, can construct a she…

TwilightCycloneDX · cyclonedx-node-npmEPSS 0.15%via NVD
CVE-2026-63472Critical· 9.1PoC
4d ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing…

Abyssalvendurehq · vendureEPSS 0.41%via NVD
CVE-2026-63461Medium· 5.3
4d ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied filters using the caller-controlled filterOperat…

Sunlitvendurehq · vendureEPSS 0.32%via NVD
CVE-2026-63460High· 7.5PoC
4d ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service…

Midnightvendurehq · vendureEPSS 0.41%via NVD
CVE-2026-63459High· 8.7
4d ago

Vendure is an open-source headless commerce platform

Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrat…

Twilightvendure · @vendure/dashboardEPSS 0.29%via NVD
CVE-2026-61793Medium· 6.9PoC
4d ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…

Twilightnuxt-modules · og-imageEPSS 0.46%via NVD
CVE-2026-54546Medium· 5.0PoC
4d ago

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/ro…

Twilightdfpc-coe · CloudTAKEPSS 0.27%via NVD
CVE-2026-54504High· 8.8PoC
4d ago

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with STA…

Midnightandrea9293 · mcp-documentation-serverEPSS 0.67%via NVD
CVE-2026-63506High· 8.8PoC
5d ago

Tina is a headless content management system

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…

Midnighttinacms · tinacmsEPSS 0.49%via NVD
CVE-2026-63225Medium· 4.4
5d ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…

SunlitRedocly · redocly-cliEPSS 0.17%via NVD
CVE-2026-77360Medium· 6.3PoC
5d ago

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in packages/server/src/plugins/cors.ts copies a client's incoming Vary request header into…

Twilightmiddleapi · orpcEPSS 0.62%via NVD
CVE-2026-68904High· 7.0
5d ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated reconnection cycle when an OPC UA server's clock skew causes …

Twilightnode-opcua-transport · node-opcua-transportEPSS 0.42%via NVD
CVE-2026-88976Medium· 6.1
5d ago

Plate is a rich-text editor with AI and shadcn/ui

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an app…

Sunlitudecode · plateEPSS 0.25%via NVD
CVE-2026-63671High· 8.1PoC
5d ago

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and…

Midnightnuxt-content · mdcEPSS 0.38%via NVD
CVE-2026-61560Critical· 9.8PoC
6d ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from th…

Abyssalzereight · @zereight/mcp-gitlabEPSS 0.70%via NVD
GHSA-5648-rgj9-v224High· 8.1
6d ago

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

Twilightzereight · @zereight/mcp-gitlabvia GHSA
CVE-2026-61568Critical· 9.6
6d ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route bro…

Midnightzereight · @zereight/mcp-gitlabEPSS 0.32%via NVD
CVE-2026-61559Critical· 9.6PoC
6d ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP…

Abyssalzereight · gitlab-mcpEPSS 0.27%via NVD
CVE-2026-59973High· 8.5PoC
6d ago

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISp…

Midnightagentfront · frontmcpEPSS 0.38%via NVD
CVE-2026-59965High· 7.1PoC
6d ago

Payload Plugins is a collection of plugins designed to enhance Payload CMS

Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts a…

Midnightjhb-software · payload-pluginsEPSS 0.29%via NVD
CVE-2026-59160High· 8.8PoC
6d ago

Yeger is a monorepo for npm packages maintained under the yeger scope

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by defaul…

MidnightDerYeger · yegerEPSS 0.41%via NVD
CVE-2026-53957High· 7.7PoC
6d ago

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-…

Midnightcontentful · contentful-mcp-serverEPSS 0.25%via NVD
CVE-2026-54688Medium· 6.5PoC
6d ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllow…

Twilightihor-sokoliuk · mcp-searxngEPSS 0.36%via NVD
CVE-2026-54689Medium· 6.3PoC
6d ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is en…

Twilightihor-sokoliuk · mcp-searxngEPSS 0.13%via NVD
CVE-2026-55178High· 7.5
6d ago

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a…

Twilightgeolens-io · geolensEPSS 0.37%via NVD
CVEs tagged “npm” · VulnSea