Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
GHSA-xrmc-c5cg-rv7xHigh· 8.8SafeInstall agent guard shell parsing can miss raw package execution
SafeInstall agent guard shell parsing can miss raw package execution
CVE-2026-49866High· 7.5libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVE-2026-49977Medium· 4.3tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
CVE-2026-5078Medium· 5.3morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
GHSA-382c-vx95-w3p5Medium· 6.5Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-59887High· 7.5linkify-it: linkify-it: Denial of Service via crafted mailto: links (CVE-2026-59887)
A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invok…
CVE-2026-59879Medium· 5.3⚖ disputedimmutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)
A flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a partic…
CVE-2026-59874High· 7.5tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header c…
CVE-2026-59873High· 7.5tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This o…
CVE-2026-59871Medium· 5.3node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)
A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path process…
CVE-2026-59877High· 7.5⚖ disputedprotobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)
A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an op…
GHSA-p2fr-6hmx-4528Medium· 6.4@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
CVE-2026-53514High· 7.7Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
CVE-2026-53516High· 8.3Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-86j7-9j95-vpqjHigh· 7.7Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-9h47-pqcx-hjr4High· 8.7Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
CVE-2026-53517High· 8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-53518High· 8.1@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-2vg6-77g8-24mpLow· 3.8Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
GHSA-j8v8-g9cx-5qf4High· 8.3@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
CVE-2026-53512Critical· 9.1Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVE-2026-55501High· 7.39router: Login brute-force protection bypass via spoofed X-Forwarded-For header
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
GHSA-vjc7-jrh9-9j86Critical· 10.09router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
CVE-2026-55500Critical· 9.99routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
CVE-2026-53486Critical· 9.1Decompress: Archive extraction can create files and links outside of the target directory
Decompress: Archive extraction can create files and links outside of the target directory
CVE-2026-59800Critical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
CVE-2026-49352Critical· 9.8PoC9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVE-2026-49353High· 7.59router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CVE-2026-52746High· 7.5jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion