Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
GHSA-qw6m-8fw2-2v64High· 8.3Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-2xgg-r2wc-c5r2High· 7.6Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
CVE-2026-15074High· 7.5@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
CVE-2026-7120Medium· 5.3@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
GHSA-464c-974j-9xm6Low· 3.3AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
GHSA-qwww-vcr4-c8h2HighReact Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
GHSA-pm4m-ph32-ghv5High· 7.5js-yaml: Exponential parsing time in flow collections leads to denial of service
js-yaml: Exponential parsing time in flow collections leads to denial of service
CVE-2026-55607HighClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-h3rm-78g3-j7cpHigh· 7.1@better-auth/stripe: cross-organization billing tampering in organization subscription actions
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
GHSA-qq9h-g4jm-xgf3High· 8.3Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
GHSA-wqjv-9729-c5q2Medium· 5.3SvelteKit: Big remote form function payloads can cause Node process to crash
SvelteKit: Big remote form function payloads can cause Node process to crash
GHSA-866w-xmhq-wj7xMedium· 4.3SvelteKit: Prototype pollution in file input deletion path in remote-function forms
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
CVE-2026-59952MediumValibot: record() issue paths can make flatten() throw for inherited Object property names
Valibot: record() issue paths can make flatten() throw for inherited Object property names
GHSA-53g2-mvcc-q9x3Medium· 4.6Trix: Stored XSS via HTMLParser attribute injection on paste
Trix: Stored XSS via HTMLParser attribute injection on paste
GHSA-38hq-7x33-php4Medium· 4.7@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
GHSA-7gfh-x38p-prh3Critical· 9.8Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
GHSA-664h-wqgq-64gwMedium· 6.5Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
GHSA-w28w-gp39-m4p6Critical· 10.0Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
GHSA-r28c-9q8g-f849High· 7.5PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-r292-9mhp-454mMedium· 5.3node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
CVE-2026-54672High· 7.8electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
CVE-2026-54673Highelectron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
CVE-2026-55575HighLiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…
CVE-2026-53666Medium· 6.1React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
CVE-2026-53667Medium· 6.9React Router: RSCErrorHandler Missing Protocol Validation (XSS)
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
CVE-2026-53668Medium· 6.9React Router: Open redirect leading to XSS
React Router: Open redirect leading to XSS
CVE-2026-53669MediumReact Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
GHSA-x445-f3h2-j279Medium· 6.8Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them