Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-47219High· 7.5find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server (CVE-2026-47219)
A flaw was found in find-my-way, a routing module for Node.js. A remote attacker could exploit this vulnerability when find-my-way is used with Node's HTTP/2 server. By sending specially crafted HTTP/2 method values, an attacker can cause …
CVE-2026-54272High· 7.2ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifie…
CVE-2026-55685Medium· 6.5react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)
A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…
CVE-2026-45623High· 7.5postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)
A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can l…
GHSA-8q49-2h5h-434xMedium· 5.9FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-pvcr-8mvp-w8qrHigh· 7.7Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-cr7p-cr3q-h5cmMedium· 5.3Budibase: Account Enumeration via Login Lockout Response Differential
Budibase: Account Enumeration via Login Lockout Response Differential
GHSA-pmpg-2mxq-6xwrHigh· 7.1Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-v42f-v8xc-j435High· 8.5Budibase: SSRF via DNS rebinding in the REST datasource integration
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-hfhx-w8p8-4hc7MediumBudibase: SSRF via bare fetch() in uploadUrl during AI table generation
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-g5vv-q72c-7j78High· 7.5@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-vh45-f885-3848Critical· 9.1sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
GHSA-6v4m-fw66-8r4xMediumShescape: Path disclosure on Unix with Zsh
Shescape: Path disclosure on Unix with Zsh
GHSA-w4hw-qcx7-56prCriticalShescape: Shell injection via unescaped parentheses on Windows with CMD
Shescape: Shell injection via unescaped parentheses on Windows with CMD
GHSA-q53c-4prm-w95qMediumShescape: Home-directory disclosure in assignment context on Unix with Dash
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA-gm3r-q2wp-hw87HighShescape: Quadratic-time denial of service in the flag-protection
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-3r53-75j5-3g7jMedium· 5.6Quasar: Prototype pollution in the extend() utility
Quasar: Prototype pollution in the extend() utility
CVE-2026-44907High· 7.5react-server-dom: Denial of Service in Server Functions
react-server-dom: Denial of Service in Server Functions
GHSA-j9fc-w3mr-x6mvHigh· 8.8Budibase: Privilege escalation via public role assignment API missing app-level authorization
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-4qcj-m5wp-jmf4Medium· 4.3Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
GHSA-fcrw-f7gg-6g9fMedium· 4.9Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-c8vc-7pv3-g98pHighBudibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-q6x4-v3qx-85qwCritical· 9.6Budibase: SQL Injection via `multipleStatements: true`
Budibase: SQL Injection via `multipleStatements: true`
GHSA-ppr4-5f46-j9c6HighBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
GHSA-xcx6-4f2g-hhgxHigh· 7.7Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-xg5g-26x8-cvf4High· 8.5Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-hp6v-6jw7-gv2fCriticalBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
GHSA-mqhr-6j6h-74p5CriticalBudibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
GHSA-hr66-5mqr-8mpxHigh· 7.5Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-gh4h-34gr-87r7Medium· 5.7Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders