VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-69258Critical· 9.1
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into intern…

▾ Midnightflowiseai · flowiseEPSS 0.67%via NVD
CVE-2026-69259High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-c…

▾ Twilightflowiseai · flowiseEPSS 0.82%via NVD
CVE-2026-69252High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A lo…

▾ Twilightflowiseai · flowiseEPSS 0.54%via NVD
CVE-2026-69253High· 8.8
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sa…

▾ Twilightflowiseai · flowiseEPSS 0.66%via NVD
CVE-2026-69254High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages…

▾ Twilightflowiseai · flowiseEPSS 0.69%via NVD
GHSA-2364-jh4q-m9vmMedium
1mo ago

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

▾ Sunlitflowise · flowisevia GHSA
CVE-2026-69250High· 7.5
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a s…

▾ Twilightflowiseai · flowiseEPSS 0.57%via NVD
CVE-2026-69251High· 8.8PoC
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig…

▾ Midnightflowiseai · flowiseEPSS 2.7%via NVD
CVE-2026-48121Medium· 6.7
1mo ago

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, c…

▾ Sunlitlangchain · @langchain/langgraph-checkpoint-mongodbEPSS 0.36%via NVD
CVE-2026-69240Critical· 9.8
1mo ago

Sequelize is a Node.js ORM tool

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DA…

▾ Midnightsequelize · sequelizeEPSS 0.54%via NVD
CVE-2026-16729Medium· 4.8
1mo ago

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

▾ Sunlitundici · undiciEPSS 0.19%via GHSA
CVE-2026-14643Medium· 5.9
1mo ago

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

▾ Sunlitundici · undiciEPSS 0.40%via GHSA
CVE-2026-15157Medium· 4.2
1mo ago

undici vulnerable to CRLF Injection via blob-like body 'type' property

undici vulnerable to CRLF Injection via blob-like body 'type' property

▾ Sunlitundici · undiciEPSS 0.19%via GHSA
CVE-2026-69198Medium
1mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's ow…

▾ Sunlitip-address · ip-addressEPSS 0.48%via NVD
CVE-2026-69192High· 8.6
1mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, an…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.66%via NVD
CVE-2026-69185High· 7.5
1mo ago

Socket.IO enables bidirectional and low-latency communication for every platform

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, w…

▾ Twilightsocket.io-parser · socket.io-parserEPSS 0.63%via NVD
CVE-2026-13697High· 7.4
1mo ago

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

▾ Twilightundici · undiciEPSS 0.57%via GHSA
CVE-2026-16728Medium· 4.8
1mo ago

undici vulnerable to downstream response desynchronization via retry interceptor

undici vulnerable to downstream response desynchronization via retry interceptor

▾ Sunlitundici · undiciEPSS 0.18%via GHSA
CVE-2026-69152High· 7.5
1mo ago

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152)

A flaw was found in the brace-expansion library. The `expand()` function does not apply `maxLength` when constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2026-69153High· 7.5
1mo ago

postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)

A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and exp…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.45%via CSAF
CVE-2026-68945High· 8.2
1mo ago

@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache (CVE-2026-68945)

A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP requests during server-side rendering, incorrectly generates cache keys when repeated request parameters are present, causing semantically dif…

▾ TwilightRed Hat · Red Hat Ceph Storage 4EPSS 0.18%via CSAF
CVE-2026-69149High
1mo ago

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

▾ Twilightangular · @angular/platform-serverEPSS 0.35%via GHSA
CVE-2026-69151High
1mo ago

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

▾ Twilightangular · @angular/compilerEPSS 0.33%via GHSA
CVE-2026-48063Critical
1mo ago

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…

▾ Midnightbaileys · baileysEPSS 0.22%via NVD
GHSA-3mcp-22mf-vrw3Medium· 7.5
1mo ago

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

▾ Sunlitaxios · axiosvia GHSA
CVE-2026-67321Medium· 7.5
1mo ago

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serializati…

▾ Sunlitaxios · axiosEPSS 0.53%via NVD
CVE-2026-18446High· 7.5
1mo ago

fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)

A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy wit…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-53606Medium· 5.4
1mo ago

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes

▾ Sunlitsanitize-html · sanitize-htmlEPSS 0.23%via GHSA
CVE-2026-53609Critical· 9.1
1mo ago

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

▾ Midnightapostrophe · apostropheEPSS 0.38%via GHSA
CVE-2026-53607Low· 3.7
1mo ago

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

▾ Sunlitapostrophe · apostropheEPSS 0.32%via GHSA
CVEs tagged “npm” — page 13 · VulnSea