Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
GHSA-4m3v-q747-pc6hMediumOpenClaw: Mattermost slash token revocation could lag until monitor refresh
OpenClaw: Mattermost slash token revocation could lag until monitor refresh
CVE-2026-53811High· 8.8OpenClaw: Matrix allowFrom could bind to mutable display names
OpenClaw: Matrix allowFrom could bind to mutable display names
GHSA-w5ww-7chg-mxcqHighOpenClaw: Telegram interactive callbacks could skip commands.allowFrom
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
GHSA-77q5-rr5v-x43qHighOpenClaw: Trusted retry endpoint checks could match hostname prefixes
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
GHSA-j472-gf56-x589HighOpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
GHSA-p73f-w79w-jqr5HighOpenClaw: Native command authorization could skip owner-command enforcement
OpenClaw: Native command authorization could skip owner-command enforcement
CVE-2026-53815High· 6.5OpenClaw: Message read actions could skip channel allowlist checks
OpenClaw: Message read actions could skip channel allowlist checks
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-qh2f-99mv-mrcfMediumOpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
GHSA-2j8v-hwgc-x698HighOpenClaw: Shell wrapper argv could change between approval and execution
OpenClaw: Shell wrapper argv could change between approval and execution
CVE-2026-53812Medium· 7.7OpenClaw's browser act interactions could bypass private-network navigation checks
OpenClaw's browser act interactions could bypass private-network navigation checks
CVE-2026-53810High· 8.8OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53817High· 8.0OpenClaw: Control UI locality spoofing could mint a durable admin device token
OpenClaw: Control UI locality spoofing could mint a durable admin device token
CVE-2026-53814High· 8.4OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
GHSA-mgq6-vr84-7m2jHigh· 8.0OpenClaw: QQBot native approval buttons did not enforce configured approver identity
OpenClaw: QQBot native approval buttons did not enforce configured approver identity
GHSA-mhq8-78pj-5j79High· 7.1OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
GHSA-hw9r-h9mr-4jffHigh· 8.8OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates
GHSA-p2fh-f5fc-44hrMedium· 6.5OpenClaw: memory-wiki ingest could read local files with operator.write scope
OpenClaw: memory-wiki ingest could read local files with operator.write scope
GHSA-wv26-j37q-2g7pMediumOpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions
GHSA-83w9-h5wv-j9xmHighOpenClaw: Node pairing reconnection could confuse approval scope state
OpenClaw: Node pairing reconnection could confuse approval scope state
GHSA-jvm4-4j77-39p6HighOpenClaw: QQBot streaming command could mutate config without explicit allowFrom
OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
GHSA-cqwv-9qjx-vxw2Medium· 5.3OpenClaw: Skill Workshop apply flow could override pending approval
OpenClaw: Skill Workshop apply flow could override pending approval
CVE-2026-53943Critical· 9.6Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
GHSA-9c3v-684m-579cMedium· 6.5OpenClaw MCP SSE redirects could forward Authorization headers
OpenClaw MCP SSE redirects could forward Authorization headers
CVE-2026-48819Medium· 4.8@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
CVE-2026-48816Medium· 6.5sigstore-js has Insufficient Verification of Data Authenticity
sigstore-js has Insufficient Verification of Data Authenticity
CVE-2026-48815Medium· 5.9sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)
A flaw was found in sigstore. The `certificateOIDs` option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This…
CVE-2026-49987High· 8.8repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
CVE-2026-49988Mediumrepomix: attach_packed_output can bypass file-read secret scanning for supported local files
repomix: attach_packed_output can bypass file-read secret scanning for supported local files