Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-45822High· 7.5decode-uri-component: decode-uri-component: Denial of Service via crafted input (CVE-2026-45822)
A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…
CVE-2026-13149High· 7.5brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time c…
CVE-2026-48795High· 8.6@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
CVE-2026-13676High· 7.5fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its…
GHSA-fr4h-3cph-29xvHigh· 7.1pnpm: Hoisted install imports lockfile alias outside node_modules
pnpm: Hoisted install imports lockfile alias outside node_modules
GHSA-72r4-9c5j-mj57High· 7.1pnpm: `patch-remove` could delete project-selected files outside the patches directory
pnpm: `patch-remove` could delete project-selected files outside the patches directory
GHSA-qrv3-253h-g69cHigh· 8.2pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
CVE-2026-48758Medium· 5.4@sigstore/core has DSSE payloadType type-binding failure
@sigstore/core has DSSE payloadType type-binding failure
GHSA-5vwr-qchf-q4pfMedium@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths
@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths
GHSA-fhp4-pr5j-46m5High· 7.5Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key
Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key
GHSA-3p34-w4f6-5xh2High· 7.5better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
CVE-2026-49252Critical· 9.9deepstream is vulnerable to prototype pollution
deepstream is vulnerable to prototype pollution
GHSA-rp72-5v5q-2446Low@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
CVE-2026-48995Mediumpnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
CVE-2026-49357HighStreamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
CVE-2026-49293High· 7.5js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
CVE-2026-49336Medium@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
CVE-2026-50573Medium· 6.8pnpm: Unsafe default behavior breaks integrity check
pnpm: Unsafe default behavior breaks integrity check
CVE-2026-50021Medium· 6.8pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
CVE-2026-50014Medium· 6.4pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
CVE-2026-50016High· 8.8pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
CVE-2026-50017Mediumpnpm binds unscoped user-level npm auth credentials to a repository-selected registry
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVE-2026-50015High· 7.3pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
CVE-2026-55180Medium· 6.5pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVE-2026-55487High· 7.5pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVE-2026-55697High· 7.5pnpm: Repository-controlled configDependencies can select a pacquet native install engine
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVE-2026-55698High· 8.8pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
CVE-2026-55699Medium· 6.5pnpm: Reserved bin name deletes PNPM_HOME during global remove
pnpm: Reserved bin name deletes PNPM_HOME during global remove
CVE-2026-55700High· 7.1pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
CVE-2026-46406Medium@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write