Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-59875Medium· 5.3node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
CVE-2026-59731High· 8.2Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
GHSA-f4gw-2p7v-4548MediumAxios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
GHSA-mmx7-hfxf-jppxMediumAxios: Prototype pollution gadgets can alter axios request construction
Axios: Prototype pollution gadgets can alter axios request construction
GHSA-jqh4-m9w3-8hp9MediumAxios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
GHSA-mwf2-3pr3-8698MediumAxios: HTTP/2 streamed uploads bypass `maxBodyLength`
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
GHSA-7q8q-rj6j-mhjqMediumAxios: Nested axios option objects can consume polluted prototype values
Axios: Nested axios option objects can consume polluted prototype values
GHSA-hcpx-6fm6-wx23MediumAxios form serializer maxDepth bypass via {} metatoken
Axios form serializer maxDepth bypass via {} metatoken
GHSA-gcfj-64vw-6mp9HighAxios Node HTTP adapter can use an inherited proxy after interceptor config cloning
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
CVE-2026-53515High· 7.1@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
GHSA-4g3v-8h47-v7g6MediumAstro: Reflected XSS via unescaped View Transition animation properties
Astro: Reflected XSS via unescaped View Transition animation properties
CVE-2026-59870Medium· 5.3js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
GHSA-pmv8-rq9r-6j72MediumAxios: Deep formToJSON Key Recursion Can Cause Denial of Service
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
GHSA-xj6q-8x83-jv6gMediumAxios: Prototype pollution auth subfields can inject Basic auth
Axios: Prototype pollution auth subfields can inject Basic auth
GHSA-42h9-826w-cgv3MediumAxios: Excessive recursion in formDataToJSON can cause denial of service
Axios: Excessive recursion in formDataToJSON can cause denial of service
CVE-2026-16221High· 7.5fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)
A flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrep…
CVE-2026-55177HighCloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
CVE-2026-53597HighPrompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
CVE-2026-50272High· 7.5dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50289Highsysteminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
GHSA-62gx-5q78-wrvxHigh· 8.8obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete
obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete
CVE-2026-54466Criticalwebsocket-driver: Message corruption via abuse of protocol length headers
websocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-54490Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
CVE-2026-54335Low· 3.7Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
GHSA-9hc2-hjx8-q6pvCritical· 9.6TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution
TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution
CVE-2026-55608Medium· 4.2n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
CVE-2026-54052Critical· 9.9n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
CVE-2026-50131High· 8.6PoCFedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
CVE-2026-49978High· 8.1dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)
A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM eleme…
CVE-2026-48801High· 7.5linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)
A flaw was found in linkify-it, a library for recognizing links with full Unicode support. The LinkifyIt.prototype.match function, the package's primary public API, has an algorithmic complexity of O(N²) for inputs containing many fuzzy li…