VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

GHSA-qqf5-x7mj-v43pHigh· 8.4
3mo ago

budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL

budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL

▾ Twilightbudibase · budibasevia GHSA
CVE-2026-53848Low· 4.3
3mo ago

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

▾ Sunlitopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-53859Medium· 6.5
3mo ago

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

▾ Sunlitopenclaw · openclawEPSS 0.36%via GHSA
CVE-2026-53855High· 8.1
3mo ago

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53862Low· 4.2
3mo ago

OpenClaw: Bootstrap token replay could widen pending pairing scopes

OpenClaw: Bootstrap token replay could widen pending pairing scopes

▾ Sunlitopenclaw · openclawEPSS 0.13%via GHSA
CVE-2026-53851Medium· 5.3
3mo ago

OpenClaw: Slack reaction events could ignore reaction notification settings

OpenClaw: Slack reaction events could ignore reaction notification settings

▾ Sunlitopenclaw · openclawEPSS 0.32%via GHSA
CVE-2026-53841Medium· 6.1
3mo ago

OpenClaw: Exported session HTML could keep unsafe markdown links

OpenClaw: Exported session HTML could keep unsafe markdown links

▾ Sunlitopenclaw · openclawEPSS 0.27%via GHSA
CVE-2026-53847Medium
3mo ago

OpenClaw: Active Memory write scope could mutate global config

OpenClaw: Active Memory write scope could mutate global config

▾ Sunlitopenclaw · openclawEPSS 0.30%via GHSA
CVE-2026-53845Low· 4.3
3mo ago

OpenClaw: Skill-command dispatch could skip before-tool-call hooks

OpenClaw: Skill-command dispatch could skip before-tool-call hooks

▾ Sunlitopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-53857High· 8.1
3mo ago

OpenClaw: Zalo allowFrom could bind to mutable display names

OpenClaw: Zalo allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.37%via GHSA
CVE-2026-53856Medium· 5.5
3mo ago

OpenClaw: Config recovery could restore openclaw.json with broad file permissions

OpenClaw: Config recovery could restore openclaw.json with broad file permissions

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-53844Medium· 6.5
3mo ago

OpenClaw: memory-wiki shared search could miss session visibility checks

OpenClaw: memory-wiki shared search could miss session visibility checks

▾ Sunlitopenclaw · openclawEPSS 0.36%via GHSA
CVE-2026-53860Low· 4.2
3mo ago

OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

▾ Sunlitopenclaw · openclawEPSS 0.23%via GHSA
CVE-2026-53853High· 7.1
3mo ago

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

▾ Twilightopenclaw · openclawEPSS 0.60%via GHSA
CVE-2026-53846High· 7.1
3mo ago

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

▾ Twilightopenclaw · openclawEPSS 0.17%via GHSA
CVE-2026-53850Medium
3mo ago

OpenClaw: Focus command could miss controlScope enforcement

OpenClaw: Focus command could miss controlScope enforcement

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-53858High· 7.1
3mo ago

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

▾ Twilightopenclaw · openclawEPSS 0.18%via GHSA
CVE-2026-53849High· 8.1
3mo ago

OpenClaw: Discord allowFrom could bind to mutable display names

OpenClaw: Discord allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.37%via GHSA
CVE-2026-53865High· 7.1
3mo ago

OpenClaw: Workspace-derived service PATH could influence trash command selection

OpenClaw: Workspace-derived service PATH could influence trash command selection

▾ Twilightopenclaw · openclawEPSS 0.18%via GHSA
CVE-2026-53852Low· 5.4
3mo ago

OpenClaw: Empty-scope device re-pairing could confuse caller scope containment

OpenClaw: Empty-scope device re-pairing could confuse caller scope containment

▾ Sunlitopenclaw · openclawEPSS 0.28%via GHSA
CVE-2026-53854Medium
3mo ago

OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

▾ Sunlitopenclaw · openclawEPSS 0.41%via GHSA
CVE-2026-0755Critical· 9.80day
3mo ago

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

▾ Hadalgemini-mcp-tool · gemini-mcp-toolEPSS 3.5%via GHSA
CVE-2026-54327Low· 2.2
3mo ago

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

▾ Sunlitmariozechner · @mariozechner/pi-coding-agentEPSS 0.09%via GHSA
CVE-2026-54328High· 7.3
3mo ago

Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts

Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts

▾ Twilightearendil-works · @earendil-works/pi-coding-agentEPSS 0.16%via GHSA
CVE-2026-54325Medium· 4.4
3mo ago

Pi Agent: Pi loads project-local extensions without approval

Pi Agent: Pi loads project-local extensions without approval

▾ Sunlitearendil-works · @earendil-works/pi-coding-agentEPSS 0.17%via GHSA
GHSA-664h-gpgq-h6xxMedium· 5.4
3mo ago

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-53765Medium· 6.1
3mo ago

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.10%via GHSA
CVE-2026-53927Medium
3mo ago

NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL

NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL

▾ Sunlitnocodb · nocodbEPSS 0.39%via GHSA
CVE-2026-53928Medium
3mo ago

NocoDB: Refresh Tokens Persist Through Password Recovery

NocoDB: Refresh Tokens Persist Through Password Recovery

▾ Sunlitnocodb · nocodbEPSS 0.31%via GHSA
CVE-2026-53929Medium
3mo ago

NocoDB: Stored Cross-Site Scripting via Secure Attachment

NocoDB: Stored Cross-Site Scripting via Secure Attachment

▾ Sunlitnocodb · nocodbEPSS 0.40%via GHSA
CVEs tagged “npm” — page 28 · VulnSea