VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

GHSA-qw6m-8fw2-2v64High· 8.3
2mo ago

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-2xgg-r2wc-c5r2High· 7.6
2mo ago

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

▾ Twilightbudibase · @budibase/servervia GHSA
CVE-2026-15074High· 7.5
2mo ago

@fastify/static vulnerable to route guard bypass via path traversal

@fastify/static vulnerable to route guard bypass via path traversal

▾ Twilightfastify · @fastify/staticEPSS 0.67%via GHSA
CVE-2026-7120Medium· 5.3
2mo ago

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

▾ Sunlitfastify · @fastify/staticEPSS 0.37%via GHSA
GHSA-464c-974j-9xm6Low· 3.3
2mo ago

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

▾ Sunlitaws-cdk-lib · aws-cdk-libvia OSV
GHSA-qwww-vcr4-c8h2High
2mo ago

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

▾ Twilightreact-router · react-routervia GHSA
GHSA-pm4m-ph32-ghv5High· 7.5
2mo ago

js-yaml: Exponential parsing time in flow collections leads to denial of service

js-yaml: Exponential parsing time in flow collections leads to denial of service

▾ Twilightjs-yaml · js-yamlvia GHSA
CVE-2026-55607High
2mo ago

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.69%via GHSA
GHSA-rjg6-39jm-rgg4Critical· 9.9
2mo ago

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

▾ Midnightbetter-auth · @better-auth/scimvia GHSA
GHSA-h3rm-78g3-j7cpHigh· 7.1
2mo ago

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

▾ Twilightbetter-auth · @better-auth/stripevia GHSA
GHSA-qq9h-g4jm-xgf3High· 8.3
2mo ago

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

▾ Twilightbetter-auth · better-authvia GHSA
GHSA-wqjv-9729-c5q2Medium· 5.3
2mo ago

SvelteKit: Big remote form function payloads can cause Node process to crash

SvelteKit: Big remote form function payloads can cause Node process to crash

▾ Sunlitsveltejs · @sveltejs/kitvia GHSA
GHSA-866w-xmhq-wj7xMedium· 4.3
2mo ago

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

▾ Sunlitsveltejs · @sveltejs/kitvia GHSA
CVE-2026-59952Medium
2mo ago

Valibot: record() issue paths can make flatten() throw for inherited Object property names

Valibot: record() issue paths can make flatten() throw for inherited Object property names

▾ Sunlitvalibot · valibotEPSS 0.52%via GHSA
GHSA-53g2-mvcc-q9x3Medium· 4.6
2mo ago

Trix: Stored XSS via HTMLParser attribute injection on paste

Trix: Stored XSS via HTMLParser attribute injection on paste

▾ Sunlittrix · trixvia GHSA
GHSA-38hq-7x33-php4Medium· 4.7
2mo ago

@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass

@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass

▾ Sunlitbackstage · @backstage/plugin-auth-backendvia GHSA
GHSA-7gfh-x38p-prh3Critical· 9.8
2mo ago

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

▾ Midnightvelocityjs · velocityjsvia GHSA
GHSA-664h-wqgq-64gwMedium· 6.5
2mo ago

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

▾ Sunlitmongoose · mongoosevia GHSA
GHSA-w28w-gp39-m4p6Critical· 10.0
2mo ago

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

▾ Midnightprompty · @prompty/corevia GHSA
GHSA-r28c-9q8g-f849High· 7.5
2mo ago

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

▾ Twilightpostcss · postcssvia GHSA
GHSA-r292-9mhp-454mMedium· 5.3
2mo ago

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

▾ Sunlittar · tarvia GHSA
CVE-2026-54672High· 7.8
2mo ago

electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`

electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`

▾ Twilightapp-builder-lib · app-builder-libEPSS 0.19%via GHSA
CVE-2026-54673High
2mo ago

electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`

electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`

▾ Twilightbuilder-util-runtime · builder-util-runtimeEPSS 0.41%via GHSA
CVE-2026-55575High
2mo ago

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

▾ Twilightliquidjs · liquidjsEPSS 0.52%via GHSA
CVE-2026-14257High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)

A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-53666Medium· 6.1
2mo ago

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

▾ Sunlitreact-router · react-routerEPSS 0.42%via GHSA
CVE-2026-53667Medium· 6.9
2mo ago

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

▾ Sunlitreact-router · react-routerEPSS 0.36%via GHSA
CVE-2026-53668Medium· 6.9
2mo ago

React Router: Open redirect leading to XSS

React Router: Open redirect leading to XSS

▾ Sunlitreact-router · react-routerEPSS 0.34%via GHSA
CVE-2026-53669Medium
2mo ago

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

▾ Sunlitreact-router · react-routerEPSS 0.32%via GHSA
GHSA-x445-f3h2-j279Medium· 6.8
2mo ago

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

▾ Sunlitauth · @auth/corevia GHSA
CVEs tagged “npm” — page 16 · VulnSea