Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-65015Highn8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
CVE-2026-65598Highn8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
CVE-2026-65597Highn8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65592Highn8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-65599Mediumn8n: Google Service Account Private Key Exposed in JWT Header
n8n: Google Service Account Private Key Exposed in JWT Header
GHSA-2rp8-mm9q-fp49Medium· 5.7TypeORM: migration:generate template-literal code injection
TypeORM: migration:generate template-literal code injection
GHSA-9mqv-5hh9-4cggMedium· 5.3Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
GHSA-8r6m-32jq-jx6qHighfast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
GHSA-f88m-g3jw-g9cjHighsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
CVE-2026-59880HighImmutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
CVE-2026-13760High· 7.3aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling
CVE-2026-59892High· 7.5OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
CVE-2026-59891Critical· 9.6PoCCredential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
GHSA-p63j-vcc4-9vmvCritical· 9.4@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
GHSA-c2j3-45gr-mqc4LowDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
GHSA-2p49-hgcm-8545High· 8.2SVGO removeScripts plugin leaves some executable scripts intact
SVGO removeScripts plugin leaves some executable scripts intact
GHSA-frvp-7c67-39w9Medium· 5.9Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-59897Medium· 4.8Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
CVE-2026-59895Medium· 6.1Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-59896Medium· 6.5hono/jsx does not isolate context per request, leading to cross-request data disclosure
hono/jsx does not isolate context per request, leading to cross-request data disclosure
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-59728Medium· 4.3@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
CVE-2026-59729MediumAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
CVE-2026-59730Low@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
CVE-2026-12590Low· 3.7body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-hp3v-mfqw-h74cLow· 3.7@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
GHSA-8mv7-9c27-98vcMediumAstro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
CVE-2026-61835High· 7.7Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
CVE-2026-61836High· 8.6Directus: Authorization-dependent response served from unsegmented cache key
Directus: Authorization-dependent response served from unsegmented cache key
CVE-2026-13311High· 7.5shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)