VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

GHSA-cgxm-vr2f-6fj8High
3mo ago

parse-server: Denial of service via exponential-time processing of deeply nested query operators

parse-server: Denial of service via exponential-time processing of deeply nested query operators

▾ Twilightparse-server · parse-servervia GHSA
GHSA-vcv2-r9jh-99m5High· 8.8
3mo ago

Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync

Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync

▾ Twilightagentic-flow · agentic-flowvia GHSA
GHSA-9wxg-vf3r-56hcLow· 3.3
3mo ago

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

▾ Sunlitopenzeppelin · @openzeppelin/wizardvia GHSA
GHSA-9ggv-8w38-r7pmMedium· 5.9
3mo ago

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

▾ Sunlittypeorm · typeormvia GHSA
CVE-2026-50008Medium
3mo ago

parse-server: Server option routeAllowList is bypassable through batch sub-requests

parse-server: Server option routeAllowList is bypassable through batch sub-requests

▾ Sunlitparse-server · parse-serverEPSS 0.60%via GHSA
CVE-2026-53724Low
3mo ago

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

▾ Sunlitparse-server · parse-serverEPSS 0.49%via GHSA
CVE-2026-53725Medium
3mo ago

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied

▾ Sunlitparse-server · parse-serverEPSS 0.43%via GHSA
CVE-2026-53726Medium
3mo ago

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

▾ Sunlitparse-server · parse-serverEPSS 0.48%via GHSA
CVE-2026-55778Low
3mo ago

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

▾ Sunlitparse-server · parse-serverEPSS 0.55%via GHSA
GHSA-v52w-28xh-v562High
3mo ago

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

▾ Twilightkozou · kozouvia GHSA
CVE-2026-55849High
3mo ago

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

▾ Twilightcyclonedx · @cyclonedx/cyclonedx-npmEPSS 0.24%via GHSA
CVE-2026-54074High· 7.8
3mo ago

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

▾ Twilighttinacms · @tinacms/cliEPSS 0.25%via GHSA
CVE-2026-55660High
3mo ago

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

▾ Twilighttinacms · tinacmsEPSS 0.28%via GHSA
GHSA-h5jc-78hr-3pc9Low
3mo ago

Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe

Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe

▾ Sunlitsveltia · @sveltia/cmsvia GHSA
GHSA-9c83-rr99-vfwjMedium
3mo ago

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

▾ Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
GHSA-2fmp-9rvw-hc96High· 7.1
3mo ago

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

▾ Twilightnetwork-ai · network-aivia GHSA
GHSA-jvcm-f35g-w78pMedium· 6.5
3mo ago

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-mxjx-28vx-xjjjMedium· 5.9
3mo ago

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-6x2m-p4xp-wg22Medium· 5.5
3mo ago

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-48x2-6pr9-2jjfMedium· 6.1
3mo ago

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-xcqx-9jf5-w339High· 7.5
3mo ago

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

▾ Twilightmcp-searxng · mcp-searxngvia GHSA
GHSA-mrvx-jmjw-vggcHigh· 7.1
3mo ago

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

▾ Twilightmcp-searxng · mcp-searxngvia GHSA
GHSA-97pr-9hgg-3p8rLow
3mo ago

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

▾ Sunlitparse-server · parse-servervia GHSA
GHSA-v3f4-w7r7-v3hmHigh
3mo ago

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

▾ Twilightzenalexa · @zenalexa/uniclivia GHSA
GHSA-x975-rgx4-5fh4High· 8.2
3mo ago

appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)

appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)

▾ Twilightappium-mcp · appium-mcpvia GHSA
GHSA-h5x8-xp6m-x6q4High· 7.1
3mo ago

@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing

@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing

▾ Twilightjhb.software · @jhb.software/payload-cloudinary-pluginvia GHSA
GHSA-g2gw-q38m-vjfcHigh
3mo ago

Lokka: Azure Resource Manager URL path validation issue

Lokka: Azure Resource Manager URL path validation issue

▾ Twilightmerill · @merill/lokkavia GHSA
CVE-2026-58399Critical
3mo ago

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

▾ Midnightacastellon · @acastellon/authEPSS 0.97%via GHSA
CVE-2026-53864High· 8.1
3mo ago

OpenClaw: Host environment sanitizer missed two Node.js control variables

OpenClaw: Host environment sanitizer missed two Node.js control variables

▾ Twilightopenclaw · openclawEPSS 0.43%via GHSA
CVE-2026-53843High· 8.8
3mo ago

OpenClaw: Pairing-scoped device session could restore revoked node token authority

OpenClaw: Pairing-scoped device session could restore revoked node token authority

▾ Twilightopenclaw · openclawEPSS 0.49%via GHSA
CVEs tagged “npm” — page 26 · VulnSea