VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-53866High· 8.1
3mo ago

OpenClaw: Shell inline-command parsing could miss an allowlist check

OpenClaw: Shell inline-command parsing could miss an allowlist check

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53842High· 7.1
3mo ago

OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution

▾ Twilightopenclaw · openclawEPSS 0.20%via GHSA
CVE-2026-53863Medium
3mo ago

OpenClaw: Tool group policy callers could accept unvalidated group IDs

OpenClaw: Tool group policy callers could accept unvalidated group IDs

▾ Sunlitopenclaw · openclawEPSS 0.29%via GHSA
CVE-2026-55886Medium
3mo ago

jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()

jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()

▾ Sunlitjodit · joditEPSS 0.53%via GHSA
CVE-2026-55388High· 8.1
3mo ago

piscina: Prototype Pollution Gadget → RCE via inherited options.filename

piscina: Prototype Pollution Gadget → RCE via inherited options.filename

▾ Twilightpiscina · piscinaEPSS 0.45%via GHSA
CVE-2026-55602Medium
3mo ago

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

▾ Sunlithttp-proxy-middleware · http-proxy-middlewareEPSS 0.38%via GHSA
CVE-2026-55603High· 7.5
3mo ago

http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`

http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`

▾ Twilighthttp-proxy-middleware · http-proxy-middlewareEPSS 0.29%via GHSA
CVE-2026-55661Medium
3mo ago

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes

▾ Sunlittinacms · tinacmsEPSS 0.40%via GHSA
CVE-2026-22551Medium
3mo ago

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat

[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat

▾ Sunlittheia · @theia/ai-chat-uiEPSS 0.31%via GHSA
CVE-2026-44688High
3mo ago

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat

▾ Twilighttheia · @theia/ai-chat-uiEPSS 0.51%via GHSA
CVE-2026-44691High
3mo ago

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions

▾ Twilighttheia · @theia/debugEPSS 0.41%via GHSA
CVE-2026-46580High
3mo ago

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat

▾ Twilighttheia · @theia/ai-chat-uiEPSS 0.51%via GHSA
GHSA-4qq2-2j2x-x62cHigh· 8.2
3mo ago

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-vmmj-pfw7-fjwpCritical· 9.9
3mo ago

npm PraisonAI codeMode sandbox escape via Function constructor

npm PraisonAI codeMode sandbox escape via Function constructor

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-gqmf-56h7-rrpfHigh· 7.6
3mo ago

npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-vjv9-7m7j-h833High· 8.8
3mo ago

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-p69m-4f92-2v84Critical· 9.8
3mo ago

PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool

PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-9752-mhqh-h34fCritical· 9.4
3mo ago

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-j4f3-55x4-r6q2Critical· 9.8
3mo ago

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-h2w2-v7j6-xqm4High· 8.8
3mo ago

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-5jv7-2mjm-h6qjHigh· 8.8
3mo ago

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-cmwh-pvxp-8882Medium
3mo ago

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-p6gq-j5cr-w38fHigh· 7.1
3mo ago

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

▾ Twilightnodemailer · nodemailervia GHSA
CVE-2026-9675High· 7.5
3mo ago

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

▾ Twilightundici · undiciEPSS 0.49%via GHSA
CVE-2026-9678Medium· 5.9
3mo ago

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

▾ Sunlitundici · undiciEPSS 0.42%via GHSA
GHSA-j99q-93c9-h869Medium
3mo ago

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

▾ Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
CVE-2026-53861Medium· 6.6
3mo ago

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

▾ Sunlitopenclaw · openclawEPSS 0.45%via GHSA
GHSA-hjwc-26pj-v3pmHigh
3mo ago

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

▾ Twilightagenticmail · @agenticmail/apivia GHSA
GHSA-fq4x-789w-jg5hHigh
3mo ago

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)

▾ Twilightagenticmail · @agenticmail/corevia GHSA
GHSA-gfj5-979r-92pwCritical
3mo ago

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

▾ Midnightacastellon · @acastellon/authvia GHSA
CVEs tagged “npm” — page 27 · VulnSea