VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

GHSA-4m3v-q747-pc6hMedium
2mo ago

OpenClaw: Mattermost slash token revocation could lag until monitor refresh

OpenClaw: Mattermost slash token revocation could lag until monitor refresh

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53811High· 8.8
2mo ago

OpenClaw: Matrix allowFrom could bind to mutable display names

OpenClaw: Matrix allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
GHSA-w5ww-7chg-mxcqHigh
2mo ago

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

OpenClaw: Telegram interactive callbacks could skip commands.allowFrom

▾ Twilightopenclaw · openclawvia GHSA
GHSA-77q5-rr5v-x43qHigh
2mo ago

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

▾ Twilightopenclaw · openclawvia GHSA
GHSA-j472-gf56-x589High
2mo ago

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

▾ Twilightopenclaw · openclawvia GHSA
GHSA-p73f-w79w-jqr5High
2mo ago

OpenClaw: Native command authorization could skip owner-command enforcement

OpenClaw: Native command authorization could skip owner-command enforcement

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53815High· 6.5
2mo ago

OpenClaw: Message read actions could skip channel allowlist checks

OpenClaw: Message read actions could skip channel allowlist checks

▾ Twilightopenclaw · openclawEPSS 0.36%via GHSA
GHSA-xww8-gqvh-92x9High· 8.0
2mo ago

OpenClaw: Exec approval display truncation could hide the command being approved

OpenClaw: Exec approval display truncation could hide the command being approved

▾ Twilightopenclaw · openclawvia GHSA
GHSA-qh2f-99mv-mrcfMedium
2mo ago

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-2j8v-hwgc-x698High
2mo ago

OpenClaw: Shell wrapper argv could change between approval and execution

OpenClaw: Shell wrapper argv could change between approval and execution

▾ TwilightOpenclaw · Openclawvia GHSA
CVE-2026-53812Medium· 7.7
2mo ago

OpenClaw's browser act interactions could bypass private-network navigation checks

OpenClaw's browser act interactions could bypass private-network navigation checks

▾ Sunlitopenclaw · openclawEPSS 0.39%via GHSA
CVE-2026-53810High· 8.8
2mo ago

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

▾ Twilightopenclaw · openclawEPSS 0.62%via GHSA
GHSA-rggc-m335-3wvjHigh
2mo ago

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53817High· 8.0
2mo ago

OpenClaw: Control UI locality spoofing could mint a durable admin device token

OpenClaw: Control UI locality spoofing could mint a durable admin device token

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53814High· 8.4
2mo ago

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

▾ Twilightopenclaw · openclawEPSS 0.39%via GHSA
GHSA-mgq6-vr84-7m2jHigh· 8.0
2mo ago

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

▾ Twilightopenclaw · openclawvia GHSA
GHSA-mhq8-78pj-5j79High· 7.1
2mo ago

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

▾ Twilightopenclaw · openclawvia GHSA
GHSA-hw9r-h9mr-4jffHigh· 8.8
2mo ago

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

▾ Twilightopenclaw · openclawvia GHSA
GHSA-p2fh-f5fc-44hrMedium· 6.5
2mo ago

OpenClaw: memory-wiki ingest could read local files with operator.write scope

OpenClaw: memory-wiki ingest could read local files with operator.write scope

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-wv26-j37q-2g7pMedium
2mo ago

OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions

OpenClaw's Slack plugin approvals used the exec approver gate for plugin actions

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-83w9-h5wv-j9xmHigh
2mo ago

OpenClaw: Node pairing reconnection could confuse approval scope state

OpenClaw: Node pairing reconnection could confuse approval scope state

▾ Twilightopenclaw · openclawvia GHSA
GHSA-jvm4-4j77-39p6High
2mo ago

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

▾ Twilightopenclaw · openclawvia GHSA
GHSA-cqwv-9qjx-vxw2Medium· 5.3
2mo ago

OpenClaw: Skill Workshop apply flow could override pending approval

OpenClaw: Skill Workshop apply flow could override pending approval

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53943Critical· 9.6
2mo ago

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

▾ Midnightghost · ghostEPSS 0.45%via GHSA
GHSA-9c3v-684m-579cMedium· 6.5
2mo ago

OpenClaw MCP SSE redirects could forward Authorization headers

OpenClaw MCP SSE redirects could forward Authorization headers

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-48819Medium· 4.8
2mo ago

@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key

@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key

▾ Sunlithey-api · @hey-api/openapi-tsEPSS 0.35%via GHSA
CVE-2026-48816Medium· 6.5
2mo ago

sigstore-js has Insufficient Verification of Data Authenticity

sigstore-js has Insufficient Verification of Data Authenticity

▾ Sunlitsigstore · @sigstore/verifyEPSS 0.16%via GHSA
CVE-2026-48815Medium· 5.9
2mo ago

sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)

A flaw was found in sigstore. The `certificateOIDs` option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.19%via CSAF
CVE-2026-49987High· 8.8
2mo ago

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

▾ Twilightrepomix · repomixEPSS 0.70%via GHSA
CVE-2026-49988Medium
2mo ago

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

▾ Sunlitrepomix · repomixEPSS 0.18%via GHSA
CVEs tagged “npm” — page 23 · VulnSea