Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-53866High· 8.1OpenClaw: Shell inline-command parsing could miss an allowlist check
OpenClaw: Shell inline-command parsing could miss an allowlist check
CVE-2026-53842High· 7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
CVE-2026-53863MediumOpenClaw: Tool group policy callers could accept unvalidated group IDs
OpenClaw: Tool group policy callers could accept unvalidated group IDs
CVE-2026-55886Mediumjodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
CVE-2026-55388High· 8.1piscina: Prototype Pollution Gadget → RCE via inherited options.filename
piscina: Prototype Pollution Gadget → RCE via inherited options.filename
CVE-2026-55602Mediumhttp-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
CVE-2026-55603High· 7.5http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
CVE-2026-55661MediumTinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
CVE-2026-22551Medium[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
CVE-2026-44688High[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
CVE-2026-44691High[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
CVE-2026-46580High[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
GHSA-4qq2-2j2x-x62cHigh· 8.2npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
GHSA-vmmj-pfw7-fjwpCritical· 9.9npm PraisonAI codeMode sandbox escape via Function constructor
npm PraisonAI codeMode sandbox escape via Function constructor
GHSA-gqmf-56h7-rrpfHigh· 7.6npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
GHSA-vjv9-7m7j-h833High· 8.8npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
GHSA-p69m-4f92-2v84Critical· 9.8PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
GHSA-9752-mhqh-h34fCritical· 9.4npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
GHSA-j4f3-55x4-r6q2Critical· 9.8npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
GHSA-h2w2-v7j6-xqm4High· 8.8npm PraisonAI AgentLoop onToolCall approval runs after tool execution
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
GHSA-5jv7-2mjm-h6qjHigh· 8.8npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
GHSA-cmwh-pvxp-8882MediumDOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
GHSA-p6gq-j5cr-w38fHigh· 7.1Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
CVE-2026-9675High· 7.5undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVE-2026-9678Medium· 5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
GHSA-j99q-93c9-h869MediumMCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
CVE-2026-53861Medium· 6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
GHSA-hjwc-26pj-v3pmHighAgenticMail: Cross-agent task authorization bypass in AgenticMail API
AgenticMail: Cross-agent task authorization bypass in AgenticMail API
GHSA-fq4x-789w-jg5hHighAgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
GHSA-gfj5-979r-92pwCritical@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
@acastellon/auth: Authentication bypass via spoofable headers in validateToken()