Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
GHSA-gj2h-2fpw-fhv9Medium@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
GHSA-g6g7-pvmx-m74pCritical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
GHSA-322x-v876-g883High@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
GHSA-x4hg-hfwf-p9mwMedium@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
CVE-2026-50288High@asymmetric-effort/specifyjs: URL parse failure silently allows request
@asymmetric-effort/specifyjs: URL parse failure silently allows request
GHSA-5c7w-4wm3-85vwMedium@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection
GHSA-qcr8-x557-7cp3Medium@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state
GHSA-xw57-23p8-9wc5Medium@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
GHSA-2944-57xv-2682Medium@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
GHSA-j5qp-p44g-2m49Medium@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
CVE-2026-50290Medium@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
GHSA-vv65-f55v-xm6gHighGrackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)
Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)
GHSA-f9ff-5x35-7gfwHighGrackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names
OpenClaw: Slack allowFrom could bind to mutable display names
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-gp79-m99v-gjmhMediumOpenClaw: Mattermost handlers could fall open when channel type was missing
OpenClaw: Mattermost handlers could fall open when channel type was missing
GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
GHSA-grc3-2j34-p6gmMediumOpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs
GHSA-hcm3-8f6r-6xwgMedium· 6.5OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
GHSA-xr4f-mjxj-w6w5High· 8.3OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
GHSA-77pv-3w4q-vrj5MediumOpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53819High· 8.8OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows
CVE-2026-53813High· 7.8OpenClaw: Fake package roots could influence memory-core artifact loading
OpenClaw: Fake package roots could influence memory-core artifact loading
CVE-2026-53809Medium· 3.8OpenClaw: Embedded runner policy could be confused by provider aliases
OpenClaw: Embedded runner policy could be confused by provider aliases
GHSA-6c4r-g249-wv3cMediumOpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts
GHSA-3wqp-prf6-2m72Low· 3.1OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement
GHSA-275c-xpvc-jgfwMediumOpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
CVE-2026-53818Medium· 6.6OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers
CVE-2026-53806High· 8.8OpenClaw: Combined POSIX shell options could confuse exec revalidation
OpenClaw: Combined POSIX shell options could confuse exec revalidation
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance