Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-53608High· 8.7@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
CVE-2026-62324Medium· 5.4Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case…
CVE-2026-54756MediumJodit has prototype pollution via Jodit.configure() / ConfigMerge
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
CVE-2026-58263High· 7.2Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
CVE-2026-65841MediumJodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SV…
CVE-2026-52887Critical· 10.0PoCNocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
CVE-2026-55100Highhashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …
CVE-2026-54737High· 7.3@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, a…
GHSA-xrmj-5g4g-8987Medium· 4.2@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
GHSA-p7w7-4929-vpj5High· 7.5`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
CVE-2026-54753Medium· 5.9`nx graph` dev server permissive CORS policy
`nx graph` dev server permissive CORS policy
CVE-2026-54729HighDSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no addres…
GHSA-pqh8-p93p-2rx7Medium· 4.3@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
CVE-2026-68499Medium· 6.2re2 provides Node.js bindings for Google's RE2 regular expression engine
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor …
CVE-2026-67550Medium· 5.7re2 provides Node.js bindings for Google's RE2 regular expression engine
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and spl…
CVE-2026-54722HighDSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the …
CVE-2026-54705Medium· 6.3mathlive's Lack of Escaping of HTML allows for XSS
mathlive's Lack of Escaping of HTML allows for XSS
CVE-2026-11393High· 9.0AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
GHSA-pc2w-4mq8-32qwLow· 3.7@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVE-2026-54662High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVE-2026-54663Medium· 6.1swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVE-2026-54661High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVE-2026-54664High· 8.3swagger-typescript-api vulnerable to code injection via unescaped enum string values
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVE-2026-54666High· 8.3swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVE-2026-54658Critical· 9.8@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
CVE-2026-54639High· 8.8Style Dictionary - Prototype Pollution in convertTokenData utility function
Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-52888Medium· 6.8NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
CVE-2026-54545High· 7.1@wakaru/cli arbitrary file write during bundle unpack
@wakaru/cli arbitrary file write during bundle unpack
GHSA-vg6v-j97m-h5xqMedium· 6.8@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition