VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-65015High
2mo ago

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

▾ Twilightn8n · n8nEPSS 0.61%via GHSA
CVE-2026-65598High
2mo ago

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

▾ Twilightn8n · n8nEPSS 0.34%via GHSA
CVE-2026-65597High
2mo ago

n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

▾ Twilightn8n · n8nEPSS 0.30%via GHSA
CVE-2026-65592High
2mo ago

n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`

n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`

▾ Twilightn8n · n8nEPSS 0.24%via GHSA
CVE-2026-65599Medium
2mo ago

n8n: Google Service Account Private Key Exposed in JWT Header

n8n: Google Service Account Private Key Exposed in JWT Header

▾ Sunlitn8n · n8nEPSS 0.25%via GHSA
GHSA-2rp8-mm9q-fp49Medium· 5.7
2mo ago

TypeORM: migration:generate template-literal code injection

TypeORM: migration:generate template-literal code injection

▾ Sunlittypeorm · typeormvia GHSA
GHSA-9mqv-5hh9-4cggMedium· 5.3
2mo ago

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

▾ Sunlithono · @hono/node-servervia GHSA
GHSA-8r6m-32jq-jx6qHigh
2mo ago

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

▾ Twilightfast-xml-parser · fast-xml-parservia GHSA
GHSA-f88m-g3jw-g9cjHigh
2mo ago

sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

▾ Twilightsharp · sharpvia GHSA
CVE-2026-59880High
2mo ago

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

▾ Twilightimmutable · immutableEPSS 0.66%via GHSA
CVE-2026-13760High· 7.3
2mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling

▾ Twilightaws-cdk-lib · aws-cdk-libEPSS 1.2%via GHSA
CVE-2026-59892High· 7.5
2mo ago

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header

▾ Twilightopentelemetry · @opentelemetry/propagator-jaegerEPSS 0.78%via GHSA
CVE-2026-59891Critical· 9.6PoC
2mo ago

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

▾ Abyssalsigstore · @sigstore/ociEPSS 0.47%via GHSA
GHSA-p63j-vcc4-9vmvCritical· 9.4
2mo ago

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

▾ Midnightvitest · @vitest/browservia GHSA
GHSA-c2j3-45gr-mqc4Low
2mo ago

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-2p49-hgcm-8545High· 8.2
2mo ago

SVGO removeScripts plugin leaves some executable scripts intact

SVGO removeScripts plugin leaves some executable scripts intact

▾ Twilightsvgo · svgovia GHSA
GHSA-frvp-7c67-39w9Medium· 5.9
2mo ago

Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

▾ Sunlithono · @hono/node-servervia GHSA
CVE-2026-59897Medium· 4.8
2mo ago

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

▾ Sunlithono · honoEPSS 0.18%via GHSA
CVE-2026-59895Medium· 6.1
2mo ago

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

▾ Sunlithono · honoEPSS 0.33%via GHSA
CVE-2026-59896Medium· 6.5
2mo ago

hono/jsx does not isolate context per request, leading to cross-request data disclosure

hono/jsx does not isolate context per request, leading to cross-request data disclosure

▾ Sunlithono · honoEPSS 0.30%via GHSA
CVE-2026-59727Low
2mo ago

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

▾ Sunlitastro · astroEPSS 0.54%via GHSA
CVE-2026-59728Medium· 4.3
2mo ago

@astrojs/rss: XML Injection via Unescaped RSS Feed Fields

@astrojs/rss: XML Injection via Unescaped RSS Feed Fields

▾ Sunlitastrojs · @astrojs/rssEPSS 0.37%via GHSA
CVE-2026-59729Medium
2mo ago

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

▾ Sunlitastro · astroEPSS 0.54%via GHSA
CVE-2026-59730Low
2mo ago

@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect

@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect

▾ Sunlitastrojs · @astrojs/nodeEPSS 0.46%via GHSA
CVE-2026-12590Low· 3.7
2mo ago

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

▾ Sunlitbody-parser · body-parserEPSS 0.41%via GHSA
GHSA-hp3v-mfqw-h74cLow· 3.7
2mo ago

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

▾ Sunlitastrojs · @astrojs/netlifyvia GHSA
GHSA-8mv7-9c27-98vcMedium
2mo ago

Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

▾ Sunlitastro · astrovia GHSA
CVE-2026-61835High· 7.7
2mo ago

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

▾ Twilightdirectus · directusEPSS 0.41%via GHSA
CVE-2026-61836High· 8.6
2mo ago

Directus: Authorization-dependent response served from unsegmented cache key

Directus: Authorization-dependent response served from unsegmented cache key

▾ Twilightdirectus · directusEPSS 0.47%via GHSA
CVE-2026-13311High· 7.5
2mo ago

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

▾ Twilightshell-quote · shell-quoteEPSS 0.60%via GHSA
CVEs tagged “npm” — page 19 · VulnSea