Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
GHSA-cgxm-vr2f-6fj8Highparse-server: Denial of service via exponential-time processing of deeply nested query operators
parse-server: Denial of service via exponential-time processing of deeply nested query operators
GHSA-vcv2-r9jh-99m5High· 8.8Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
GHSA-9wxg-vf3r-56hcLow· 3.3OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
GHSA-9ggv-8w38-r7pmMedium· 5.9TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)
TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)
CVE-2026-50008Mediumparse-server: Server option routeAllowList is bypassable through batch sub-requests
parse-server: Server option routeAllowList is bypassable through batch sub-requests
CVE-2026-53724Lowparse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
CVE-2026-53725Mediumparse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied
parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied
CVE-2026-53726Mediumparse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
CVE-2026-55778Lowparse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
GHSA-v52w-28xh-v562HighKozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
CVE-2026-55849High@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
CVE-2026-54074High· 7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
CVE-2026-55660HighTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
GHSA-h5jc-78hr-3pc9LowSveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
GHSA-9c83-rr99-vfwjMediumMCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
GHSA-2fmp-9rvw-hc96High· 7.1Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
GHSA-jvcm-f35g-w78pMedium· 6.5Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
GHSA-mxjx-28vx-xjjjMedium· 5.9Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
GHSA-6x2m-p4xp-wg22Medium· 5.5Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
GHSA-48x2-6pr9-2jjfMedium· 6.1Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
GHSA-xcqx-9jf5-w339High· 7.5SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
GHSA-mrvx-jmjw-vggcHigh· 7.1SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
GHSA-97pr-9hgg-3p8rLowparse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
GHSA-v3f4-w7r7-v3hmHighUni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
GHSA-x975-rgx4-5fh4High· 8.2appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
GHSA-h5x8-xp6m-x6q4High· 7.1@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
GHSA-g2gw-q38m-vjfcHighLokka: Azure Resource Manager URL path validation issue
Lokka: Azure Resource Manager URL path validation issue
CVE-2026-58399Critical@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
CVE-2026-53864High· 8.1OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
CVE-2026-53843High· 8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
OpenClaw: Pairing-scoped device session could restore revoked node token authority