VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-59875Medium· 5.3
2mo ago

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records

▾ Sunlittar · tarEPSS 0.51%via GHSA
CVE-2026-59731High· 8.2
2mo ago

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

▾ Twilightastro · astroEPSS 0.47%via GHSA
GHSA-f4gw-2p7v-4548Medium
2mo ago

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

▾ Sunlitaxios · axiosvia GHSA
GHSA-mmx7-hfxf-jppxMedium
2mo ago

Axios: Prototype pollution gadgets can alter axios request construction

Axios: Prototype pollution gadgets can alter axios request construction

▾ Sunlitaxios · axiosvia GHSA
GHSA-jqh4-m9w3-8hp9Medium
2mo ago

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

▾ Sunlitaxios · axiosvia GHSA
GHSA-mwf2-3pr3-8698Medium
2mo ago

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

▾ Sunlitaxios · axiosvia GHSA
GHSA-7q8q-rj6j-mhjqMedium
2mo ago

Axios: Nested axios option objects can consume polluted prototype values

Axios: Nested axios option objects can consume polluted prototype values

▾ Sunlitaxios · axiosvia GHSA
GHSA-hcpx-6fm6-wx23Medium
2mo ago

Axios form serializer maxDepth bypass via {} metatoken

Axios form serializer maxDepth bypass via {} metatoken

▾ Sunlitaxios · axiosvia GHSA
GHSA-gcfj-64vw-6mp9High
2mo ago

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

▾ Twilightaxios · axiosvia GHSA
CVE-2026-53515High· 7.1
2mo ago

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

▾ Twilightbetter-auth · @better-auth/ssoEPSS 0.43%via GHSA
GHSA-4g3v-8h47-v7g6Medium
2mo ago

Astro: Reflected XSS via unescaped View Transition animation properties

Astro: Reflected XSS via unescaped View Transition animation properties

▾ Sunlitastro · astrovia GHSA
CVE-2026-59870Medium· 5.3
2mo ago

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

▾ Sunlitjs-yaml · js-yamlEPSS 0.64%via GHSA
GHSA-pmv8-rq9r-6j72Medium
2mo ago

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

▾ Sunlitaxios · axiosvia GHSA
GHSA-xj6q-8x83-jv6gMedium
2mo ago

Axios: Prototype pollution auth subfields can inject Basic auth

Axios: Prototype pollution auth subfields can inject Basic auth

▾ Sunlitaxios · axiosvia GHSA
GHSA-42h9-826w-cgv3Medium
2mo ago

Axios: Excessive recursion in formDataToJSON can cause denial of service

Axios: Excessive recursion in formDataToJSON can cause denial of service

▾ Sunlitaxios · axiosvia GHSA
CVE-2026-16221High· 7.5
2mo ago

fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)

A flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrep…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.25%via CSAF
CVE-2026-55177High
2mo ago

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

▾ Twilighttak-ps · @tak-ps/cloudtakvia GHSA
CVE-2026-53597High
2mo ago

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

▾ Twilightprompty · @prompty/coreEPSS 0.97%via GHSA
CVE-2026-50272High· 7.5
2mo ago

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

▾ Twilightdd-trace · dd-traceEPSS 0.79%via GHSA
CVE-2026-50289High
2mo ago

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

▾ Twilightsysteminformation · systeminformationEPSS 3.6%via GHSA
GHSA-62gx-5q78-wrvxHigh· 8.8
2mo ago

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

▾ Twilightobsidian-local-rest-api · obsidian-local-rest-apivia GHSA
CVE-2026-54466Critical
2mo ago

websocket-driver: Message corruption via abuse of protocol length headers

websocket-driver: Message corruption via abuse of protocol length headers

▾ Midnightwebsocket-driver · websocket-driverEPSS 0.38%via GHSA
CVE-2026-54490Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.45%via GHSA
CVE-2026-54335Low· 3.7
2mo ago

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

▾ Sunlitfeathersjs · @feathersjs/commonsEPSS 0.39%via GHSA
GHSA-9hc2-hjx8-q6pvCritical· 9.6
2mo ago

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

▾ Midnighttidgi · tidgivia GHSA
CVE-2026-55608Medium· 4.2
2mo ago

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

▾ Sunlitn8n-mcp · n8n-mcpEPSS 0.28%via GHSA
CVE-2026-54052Critical· 9.9
2mo ago

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

▾ Midnightn8n-mcp · n8n-mcpEPSS 0.39%via GHSA
CVE-2026-50131High· 8.6PoC
2mo ago

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

▾ Midnightfedify · @fedify/fedifyEPSS 0.42%via GHSA
CVE-2026-49978High· 8.1
2mo ago

dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)

A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM eleme…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.40%via CSAF
CVE-2026-48801High· 7.5
2mo ago

linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)

A flaw was found in linkify-it, a library for recognizing links with full Unicode support. The LinkifyIt.prototype.match function, the package's primary public API, has an algorithmic complexity of O(N²) for inputs containing many fuzzy li…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.18EPSS 0.52%via CSAF
CVEs tagged “npm” — page 20 · VulnSea