VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-53608High· 8.7
1mo ago

@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag

@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag

▾ Twilightapostrophecms · @apostrophecms/seoEPSS 0.35%via GHSA
CVE-2026-62324Medium· 5.4
1mo ago

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case…

▾ Sunlitjodit · joditEPSS 0.31%via NVD
CVE-2026-54756Medium
1mo ago

Jodit has prototype pollution via Jodit.configure() / ConfigMerge

Jodit has prototype pollution via Jodit.configure() / ConfigMerge

▾ Sunlitjodit · joditEPSS 0.46%via GHSA
CVE-2026-58263High· 7.2
1mo ago

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

▾ Twilightjodit · joditEPSS 0.30%via GHSA
CVE-2026-65841Medium
1mo ago

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SV…

▾ Sunlitjodit · joditEPSS 0.53%via NVD
CVE-2026-52887Critical· 10.0PoC
1mo ago

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

▾ Abyssalnocobase · @nocobase/plugin-notification-in-app-messageEPSS 0.89%via GHSA
CVE-2026-55100High
1mo ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …

▾ Twilighthashi-vault-js · hashi-vault-jsEPSS 0.56%via NVD
CVE-2026-54737High· 7.3
1mo ago

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, a…

▾ Twilightphun-ky · @phun-ky/defaults-deepEPSS 0.46%via NVD
GHSA-xrmj-5g4g-8987Medium· 4.2
1mo ago

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
GHSA-p7w7-4929-vpj5High· 7.5
1mo ago

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

▾ Twilightdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-54753Medium· 5.9
1mo ago

`nx graph` dev server permissive CORS policy

`nx graph` dev server permissive CORS policy

▾ Sunlitnx · nxEPSS 1.2%via GHSA
CVE-2026-54729High
1mo ago

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no addres…

▾ Twilightdssrf · dssrfEPSS 0.48%via NVD
GHSA-pqh8-p93p-2rx7Medium· 4.3
1mo ago

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-68499Medium· 6.2
1mo ago

re2 provides Node.js bindings for Google's RE2 regular expression engine

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor …

▾ Sunlitre2 · re2EPSS 0.18%via NVD
CVE-2026-67550Medium· 5.7
1mo ago

re2 provides Node.js bindings for Google's RE2 regular expression engine

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and spl…

▾ Sunlitre2 · re2EPSS 0.16%via NVD
CVE-2026-54722High
1mo ago

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the …

▾ Twilightdssrf · dssrfEPSS 0.57%via NVD
CVE-2026-54705Medium· 6.3
2mo ago

mathlive's Lack of Escaping of HTML allows for XSS

mathlive's Lack of Escaping of HTML allows for XSS

▾ Sunlitmathlive · mathliveEPSS 0.36%via GHSA
CVE-2026-11393High· 9.0
2mo ago

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

▾ Twilightaws · @aws/agentcoreEPSS 0.34%via GHSA
GHSA-pc2w-4mq8-32qwLow· 3.7
2mo ago

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-54660High· 7.4
2mo ago

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.44%via GHSA
CVE-2026-54662High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54663Medium· 6.1
2mo ago

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

▾ Sunlitswagger-typescript-api · swagger-typescript-apiEPSS 0.32%via GHSA
CVE-2026-54661High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54664High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped enum string values

swagger-typescript-api vulnerable to code injection via unescaped enum string values

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54666High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54658Critical· 9.8
2mo ago

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

▾ Midnighthypequery · @hypequery/clickhouseEPSS 0.82%via GHSA
CVE-2026-54639High· 8.8
2mo ago

Style Dictionary - Prototype Pollution in convertTokenData utility function

Style Dictionary - Prototype Pollution in convertTokenData utility function

▾ Twilightstyle-dictionary · style-dictionaryEPSS 0.36%via GHSA
CVE-2026-52888Medium· 6.8
2mo ago

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

▾ Sunlitnocobase · @nocobase/plugin-collection-sqlEPSS 0.47%via GHSA
CVE-2026-54545High· 7.1
2mo ago

@wakaru/cli arbitrary file write during bundle unpack

@wakaru/cli arbitrary file write during bundle unpack

▾ Twilightwakaru · @wakaru/cliEPSS 0.20%via GHSA
GHSA-vg6v-j97m-h5xqMedium· 6.8
2mo ago

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

▾ Sunlitnovu · @novu/application-genericvia GHSA
CVEs tagged “npm” — page 14 · VulnSea