VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-48714Critical· 9.1
3mo ago

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names

▾ Midnighti18next-http-middleware · i18next-http-middlewareEPSS 0.66%via GHSA
CVE-2026-48713Critical· 9.1
3mo ago

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string

▾ Midnighti18next-fs-backend · i18next-fs-backendEPSS 0.66%via GHSA
GHSA-wrr4-782v-jhwhLow
3mo ago

neotoma has tenant isolation gap in relationship query endpoints

neotoma has tenant isolation gap in relationship query endpoints

▾ Sunlitneotoma · neotomavia GHSA
CVE-2026-12537High· 7.8⚖ disputed
3mo ago

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

▾ Twilightgoogle · gemini-cliEPSS 0.21%via NVD
GHSA-55cm-p4ww-685gMedium· 5.3
3mo ago

Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()

Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()

▾ Sunlithono · honovia GHSA
GHSA-w4hm-rrxg-pxcfMedium· 7.1
3mo ago

Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability

Duplicate Advisory: Flowise Execute Flow function has an SSRF vulnerability

▾ Sunlitflowise · flowisevia GHSA
GHSA-2x6f-57hp-86fxMedium· 5.5
3mo ago

Duplicate Advisory: Nuxt dev server vite-node IPC socket is world-connectable on Linux

Duplicate Advisory: Nuxt dev server vite-node IPC socket is world-connectable on Linux

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-12866Critical· 9.8
3mo ago

expr-eval vulnerable to Code Execution

expr-eval vulnerable to Code Execution

▾ Midnightexpr-eval · expr-evalEPSS 0.87%via GHSA
CVE-2026-54350Critical· 10.0PoC
3mo ago

Budibase has nonymous NoSQL operator injection via published-app query templates

Budibase has nonymous NoSQL operator injection via published-app query templates

▾ Abyssalbudibase · @budibase/serverEPSS 0.54%via GHSA
CVE-2026-53550Medium· 5.3
3mo ago

js-yaml: js-yaml: Denial of Service via crafted YAML merge keys (CVE-2026-53550)

A flaw was found in js-yaml, a JavaScript YAML parser and dumper. A remote attacker can exploit this vulnerability by providing a specially crafted YAML document that repeatedly uses the same alias in a merge sequence. This can lead to alg…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.18EPSS 0.41%via CSAF
CVE-2026-46672Medium· 4.6
3mo ago

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper

▾ Sunlitactual-app · @actual-app/cliEPSS 0.19%via GHSA
CVE-2026-46700Medium· 4.3
3mo ago

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

▾ Sunlitactual-app · @actual-app/sync-serverEPSS 0.34%via GHSA
CVE-2026-48153High· 8.5
3mo ago

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

▾ Twilightbudibase · @budibase/serverEPSS 0.29%via GHSA
GHSA-hvqh-jw65-wcpqMedium· 5.4
3mo ago

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs

devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs

▾ Sunlitdevbridge-autocomplete · devbridge-autocompletevia GHSA
CVE-2026-50132High· 7.3
3mo ago

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

▾ Twilightbudibase · @budibase/serverEPSS 0.19%via GHSA
CVE-2026-50136High· 7.4
3mo ago

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials

▾ Twilightbudibase · @budibase/serverEPSS 0.29%via GHSA
CVE-2026-50137High
3mo ago

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

▾ Twilightbudibase · @budibase/serverEPSS 0.41%via GHSA
CVE-2026-49229High· 8.3
3mo ago

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

▾ Twilightactual-app · @actual-app/sync-serverEPSS 0.44%via GHSA
CVE-2026-54351High· 8.2
3mo ago

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

▾ Twilightbudibase · @budibase/serverEPSS 0.46%via GHSA
CVE-2026-54352Critical· 9.6
3mo ago

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload

▾ Midnightbudibase · @budibase/serverEPSS 0.49%via GHSA
CVE-2026-54353High· 8.5
3mo ago

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

▾ Twilightbudibase · @budibase/backend-coreEPSS 0.21%via GHSA
CVE-2026-50179Medium· 4.2
3mo ago

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

▾ Sunlitactual-app · @actual-app/webEPSS 0.29%via GHSA
GHSA-5w6g-rc45-wvv9Critical· 9.8
3mo ago

Duplicate Advisory: Flowise OverrideConfig security vulnerability

Duplicate Advisory: Flowise OverrideConfig security vulnerability

▾ Midnightflowise · flowisevia GHSA
GHSA-xppm-jmw6-fhmfLow
3mo ago

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-12644Medium· 5.3
3mo ago

ts-deepmerge: Prototype Method Override leads to DoS

ts-deepmerge: Prototype Method Override leads to DoS

▾ Sunlitts-deepmerge · ts-deepmergeEPSS 0.51%via GHSA
CVE-2026-48814Critical· 9.1
3mo ago

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

▾ Midnightnetwork-ai · network-aiEPSS 0.52%via GHSA
CVE-2026-54051Critical· 9.9
3mo ago

Network-AI: Improper Neutralization of Special Elements used in an OS Command

Network-AI: Improper Neutralization of Special Elements used in an OS Command

▾ Midnightnetwork-ai · network-aiEPSS 0.67%via GHSA
CVE-2026-6733Low· 3.7
3mo ago

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

▾ Sunlitundici · undiciEPSS 0.27%via GHSA
CVE-2026-9679Medium· 5.9
3mo ago

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

▾ Sunlitundici · undiciEPSS 0.33%via GHSA
CVE-2026-11525Low· 3.7
3mo ago

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

▾ Sunlitundici · undiciEPSS 0.24%via GHSA
CVEs tagged “npm” — page 25 · VulnSea