VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

GHSA-gj2h-2fpw-fhv9Medium
2mo ago

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

▾ Sunlitnuxt · @nuxt/uivia GHSA
GHSA-g6g7-pvmx-m74pCritical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routervia GHSA
GHSA-322x-v876-g883High
2mo ago

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

▾ Twilightasymmetric-effort · @asymmetric-effort/nogginlessdomvia GHSA
GHSA-x4hg-hfwf-p9mwMedium
2mo ago

@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation

@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation

▾ Sunlitasymmetric-effort · @asymmetric-effort/nogginlessdomvia GHSA
CVE-2026-50288High
2mo ago

@asymmetric-effort/specifyjs: URL parse failure silently allows request

@asymmetric-effort/specifyjs: URL parse failure silently allows request

▾ Twilightasymmetric-effort · @asymmetric-effort/specifyjsEPSS 0.48%via GHSA
GHSA-5c7w-4wm3-85vwMedium
2mo ago

@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection

@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
GHSA-qcr8-x557-7cp3Medium
2mo ago

@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state

@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
GHSA-xw57-23p8-9wc5Medium
2mo ago

@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)

@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
GHSA-2944-57xv-2682Medium
2mo ago

@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction

@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
GHSA-j5qp-p44g-2m49Medium
2mo ago

@asymmetric-effort/specifyjs: No redirect target validation in secureFetch

@asymmetric-effort/specifyjs: No redirect target validation in secureFetch

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsvia GHSA
CVE-2026-50290Medium
2mo ago

@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString

@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString

▾ Sunlitasymmetric-effort · @asymmetric-effort/specifyjsEPSS 0.49%via GHSA
GHSA-vv65-f55v-xm6gHigh
2mo ago

Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)

Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)

▾ Twilightgrackle-ai · @grackle-ai/runtime-sdkvia GHSA
GHSA-f9ff-5x35-7gfwHigh
2mo ago

Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)

Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)

▾ Twilightgrackle-ai · @grackle-ai/mcpvia GHSA
GHSA-c29c-2q9c-pc86High
2mo ago

OpenClaw: Slack allowFrom could bind to mutable display names

OpenClaw: Slack allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawvia GHSA
GHSA-qjpc-qf9m-xwmrHigh· 8.8
2mo ago

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

▾ Twilightopenclaw · openclawvia GHSA
GHSA-gp79-m99v-gjmhMedium
2mo ago

OpenClaw: Mattermost handlers could fall open when channel type was missing

OpenClaw: Mattermost handlers could fall open when channel type was missing

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-w4v6-g3wm-w36cCritical
2mo ago

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

▾ Midnightopenclaw · openclawvia GHSA
GHSA-grc3-2j34-p6gmMedium
2mo ago

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-hcm3-8f6r-6xwgMedium· 6.5
2mo ago

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-xr4f-mjxj-w6w5High· 8.3
2mo ago

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

▾ Twilightopenclaw · openclawvia GHSA
GHSA-77pv-3w4q-vrj5Medium
2mo ago

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53819High· 8.8
2mo ago

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

▾ Twilightopenclaw · openclawEPSS 0.41%via GHSA
CVE-2026-53813High· 7.8
2mo ago

OpenClaw: Fake package roots could influence memory-core artifact loading

OpenClaw: Fake package roots could influence memory-core artifact loading

▾ Twilightopenclaw · openclawEPSS 0.17%via GHSA
CVE-2026-53809Medium· 3.8
2mo ago

OpenClaw: Embedded runner policy could be confused by provider aliases

OpenClaw: Embedded runner policy could be confused by provider aliases

▾ Sunlitopenclaw · openclawEPSS 0.13%via GHSA
GHSA-6c4r-g249-wv3cMedium
2mo ago

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-3wqp-prf6-2m72Low· 3.1
2mo ago

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-275c-xpvc-jgfwMedium
2mo ago

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53818Medium· 6.6
2mo ago

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-53806High· 8.8
2mo ago

OpenClaw: Combined POSIX shell options could confuse exec revalidation

OpenClaw: Combined POSIX shell options could confuse exec revalidation

▾ Twilightopenclaw · openclawEPSS 0.61%via GHSA
CVE-2026-53816High· 7.2
2mo ago

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

▾ Twilightopenclaw · openclawEPSS 0.50%via GHSA
CVEs tagged “npm” — page 22 · VulnSea