VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-45822High· 7.5
2mo ago

decode-uri-component: decode-uri-component: Denial of Service via crafted input (CVE-2026-45822)

A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…

▾ TwilightRed Hat · Red Hat Quay 3.12EPSS 0.51%via CSAF
CVE-2026-13149High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)

A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time c…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.36%via CSAF
CVE-2026-48795High· 8.6
2mo ago

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

▾ Twilightadonisjs · @adonisjs/bodyparserEPSS 0.55%via GHSA
CVE-2026-13676High· 7.5
3mo ago

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its…

▾ Twilightopenjsf · fast-uriEPSS 0.48%via NVD
GHSA-fr4h-3cph-29xvHigh· 7.1
3mo ago

pnpm: Hoisted install imports lockfile alias outside node_modules

pnpm: Hoisted install imports lockfile alias outside node_modules

▾ Twilightpnpm · pnpmvia GHSA
GHSA-72r4-9c5j-mj57High· 7.1
3mo ago

pnpm: `patch-remove` could delete project-selected files outside the patches directory

pnpm: `patch-remove` could delete project-selected files outside the patches directory

▾ Twilightpnpm · pnpmvia GHSA
GHSA-qrv3-253h-g69cHigh· 8.2
3mo ago

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

▾ Twilightpnpm · pnpmvia GHSA
CVE-2026-48758Medium· 5.4
3mo ago

@sigstore/core has DSSE payloadType type-binding failure

@sigstore/core has DSSE payloadType type-binding failure

▾ Sunlitsigstore · @sigstore/coreEPSS 0.26%via GHSA
GHSA-5vwr-qchf-q4pfMedium
3mo ago

@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths

@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths

▾ Sunlitcyclonedx · @cyclonedx/cdxgenvia GHSA
GHSA-fhp4-pr5j-46m5High· 7.5
3mo ago

Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key

Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key

▾ Twilightmuhammara · muhammaravia GHSA
GHSA-3p34-w4f6-5xh2High· 7.5
3mo ago

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

▾ Twilightbetter-helperjs · better-helperjsvia GHSA
CVE-2026-49252Critical· 9.9
3mo ago

deepstream is vulnerable to prototype pollution

deepstream is vulnerable to prototype pollution

▾ Midnightdeepstream · @deepstream/serverEPSS 0.47%via GHSA
GHSA-rp72-5v5q-2446Low
3mo ago

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

▾ Sunlitcardano402 · @cardano402/mcp-servervia GHSA
CVE-2026-48995Medium
3mo ago

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

▾ Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-49357High
3mo ago

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

▾ Twilightline-desktop-mcp · line-desktop-mcpEPSS 0.56%via GHSA
CVE-2026-49293High· 7.5
3mo ago

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

▾ Twilightjs-toml · js-tomlEPSS 0.64%via GHSA
CVE-2026-49336Medium
3mo ago

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

▾ Sunlitmicrosoft · @microsoft/kiota-http-fetchlibraryEPSS 1.2%via GHSA
CVE-2026-50573Medium· 6.8
3mo ago

pnpm: Unsafe default behavior breaks integrity check

pnpm: Unsafe default behavior breaks integrity check

▾ Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-50021Medium· 6.8
3mo ago

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

▾ Sunlitpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-50014Medium· 6.4
3mo ago

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

▾ Sunlitpnpm · pnpmEPSS 0.32%via GHSA
CVE-2026-50016High· 8.8
3mo ago

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

▾ Twilightpnpm · pnpmEPSS 0.53%via GHSA
CVE-2026-50017Medium
3mo ago

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

▾ Sunlitpnpm · pnpmEPSS 0.44%via GHSA
CVE-2026-50015High· 7.3
3mo ago

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

▾ Twilightpnpm · pnpmEPSS 0.43%via GHSA
CVE-2026-55180Medium· 6.5
3mo ago

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

▾ Sunlitpnpm · pnpmEPSS 0.37%via GHSA
CVE-2026-55487High· 7.5
3mo ago

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

▾ Twilightpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-55697High· 7.5
3mo ago

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

▾ Twilightpnpm · pnpmEPSS 0.19%via GHSA
CVE-2026-55698High· 8.8
3mo ago

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

▾ Twilightpnpm · pnpmEPSS 0.30%via GHSA
CVE-2026-55699Medium· 6.5
3mo ago

pnpm: Reserved bin name deletes PNPM_HOME during global remove

pnpm: Reserved bin name deletes PNPM_HOME during global remove

▾ Sunlitpnpm · pnpmEPSS 0.45%via GHSA
CVE-2026-55700High· 7.1
3mo ago

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

▾ Twilightpnpm · pnpmEPSS 0.42%via GHSA
CVE-2026-46406Medium
3mo ago

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

▾ Sunlitanthropic-ai · @anthropic-ai/claude-codeEPSS 0.15%via GHSA
CVEs tagged “npm” — page 24 · VulnSea