VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

GHSA-xrmc-c5cg-rv7xHigh· 8.8
2mo ago

SafeInstall agent guard shell parsing can miss raw package execution

SafeInstall agent guard shell parsing can miss raw package execution

▾ Twilightsafeinstall-cli · safeinstall-clivia GHSA
CVE-2026-49866High· 7.5
2mo ago

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

▾ Twilightlibp2p · @libp2p/gossipsubEPSS 0.63%via GHSA
CVE-2026-49977Medium· 4.3
2mo ago

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

▾ Sunlittarteaucitronjs · tarteaucitronjsEPSS 0.35%via GHSA
CVE-2026-5078Medium· 5.3
2mo ago

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

▾ Sunlitmorgan · morganEPSS 0.41%via GHSA
GHSA-382c-vx95-w3p5Medium· 6.5
2mo ago

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

▾ Sunlitjsonbored · @jsonbored/gittensory-mcpvia GHSA
CVE-2026-59887High· 7.5
2mo ago

linkify-it: linkify-it: Denial of Service via crafted mailto: links (CVE-2026-59887)

A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invok…

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.64%via CSAF
CVE-2026-59879Medium· 5.3⚖ disputed
2mo ago

immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)

A flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a partic…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via CSAF
CVE-2026-59874High· 7.5
2mo ago

tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)

A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header c…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-59873High· 7.5
2mo ago

tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)

A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This o…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-59871Medium· 5.3
2mo ago

node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)

A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path process…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.64%via CSAF
CVE-2026-59877High· 7.5⚖ disputed
2mo ago

protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)

A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an op…

▾ TwilightRed Hat · Red Hat OpenShift Service Mesh 3.3EPSS 0.67%via CSAF
GHSA-p2fr-6hmx-4528Medium· 6.4
2mo ago

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

▾ Sunlitbetter-auth · @better-auth/oauth-providervia GHSA
CVE-2026-53514High· 7.7
2mo ago

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

▾ Twilightbetter-auth · better-authEPSS 0.20%via GHSA
CVE-2026-53516High· 8.3
2mo ago

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

▾ Twilightbetter-auth · better-authEPSS 0.29%via GHSA
GHSA-86j7-9j95-vpqjHigh· 7.7
2mo ago

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

▾ Twilightbetter-auth · better-authvia GHSA
GHSA-9h47-pqcx-hjr4High· 8.7
2mo ago

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

▾ Twilightbetter-auth · better-authvia GHSA
CVE-2026-53517High· 8.1
2mo ago

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVE-2026-53513Critical· 9.6
2mo ago

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

▾ Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA
CVE-2026-53518High· 8.1
2mo ago

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA
GHSA-2vg6-77g8-24mpLow· 3.8
2mo ago

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

▾ Sunlitbetter-auth · better-authvia GHSA
GHSA-j8v8-g9cx-5qf4High· 8.3
2mo ago

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

▾ Twilightbetter-auth · @better-auth/scimvia GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

▾ Midnightbetter-auth · better-authEPSS 0.27%via GHSA
CVE-2026-55501High· 7.3
2mo ago

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

▾ Twilight9router · 9routerEPSS 0.52%via GHSA
GHSA-vjc7-jrh9-9j86Critical· 10.0
2mo ago

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

▾ Midnight9router · 9routervia GHSA
CVE-2026-55500Critical· 9.9
2mo ago

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

▾ Midnight9router · 9routerEPSS 0.69%via GHSA
CVE-2026-53486Critical· 9.1
2mo ago

Decompress: Archive extraction can create files and links outside of the target directory

Decompress: Archive extraction can create files and links outside of the target directory

▾ Midnightxhmikosr · @xhmikosr/decompressEPSS 0.75%via GHSA
CVE-2026-59800Critical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routerEPSS 2.0%via GHSA
CVE-2026-49352Critical· 9.8PoC
2mo ago

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

▾ Abyssal9router · 9routerEPSS 0.60%via GHSA
CVE-2026-49353High· 7.5
2mo ago

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

▾ Twilight9router · 9routerEPSS 0.36%via GHSA
CVE-2026-52746High· 7.5
2mo ago

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

▾ Twilightjsonata · jsonataEPSS 0.69%via GHSA
CVEs tagged “npm” — page 21 · VulnSea