Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
GHSA-qqf5-x7mj-v43pHigh· 8.4budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
CVE-2026-53848Low· 4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
CVE-2026-53859Medium· 6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
CVE-2026-53862Low· 4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
OpenClaw: Bootstrap token replay could widen pending pairing scopes
CVE-2026-53851Medium· 5.3OpenClaw: Slack reaction events could ignore reaction notification settings
OpenClaw: Slack reaction events could ignore reaction notification settings
CVE-2026-53841Medium· 6.1OpenClaw: Exported session HTML could keep unsafe markdown links
OpenClaw: Exported session HTML could keep unsafe markdown links
CVE-2026-53847MediumOpenClaw: Active Memory write scope could mutate global config
OpenClaw: Active Memory write scope could mutate global config
CVE-2026-53845Low· 4.3OpenClaw: Skill-command dispatch could skip before-tool-call hooks
OpenClaw: Skill-command dispatch could skip before-tool-call hooks
CVE-2026-53857High· 8.1OpenClaw: Zalo allowFrom could bind to mutable display names
OpenClaw: Zalo allowFrom could bind to mutable display names
CVE-2026-53856Medium· 5.5OpenClaw: Config recovery could restore openclaw.json with broad file permissions
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
CVE-2026-53844Medium· 6.5OpenClaw: memory-wiki shared search could miss session visibility checks
OpenClaw: memory-wiki shared search could miss session visibility checks
CVE-2026-53860Low· 4.2OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers
CVE-2026-53853High· 7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
CVE-2026-53846High· 7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
CVE-2026-53850MediumOpenClaw: Focus command could miss controlScope enforcement
OpenClaw: Focus command could miss controlScope enforcement
CVE-2026-53858High· 7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
CVE-2026-53849High· 8.1OpenClaw: Discord allowFrom could bind to mutable display names
OpenClaw: Discord allowFrom could bind to mutable display names
CVE-2026-53865High· 7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
OpenClaw: Workspace-derived service PATH could influence trash command selection
CVE-2026-53852Low· 5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
CVE-2026-53854MediumOpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
CVE-2026-0755Critical· 9.80daygemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
CVE-2026-54327Low· 2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
CVE-2026-54328High· 7.3Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
CVE-2026-54325Medium· 4.4Pi Agent: Pi loads project-local extensions without approval
Pi Agent: Pi loads project-local extensions without approval
GHSA-664h-gpgq-h6xxMedium· 5.4n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-53765Medium· 6.1Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
CVE-2026-53927MediumNocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
CVE-2026-53928MediumNocoDB: Refresh Tokens Persist Through Password Recovery
NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-53929MediumNocoDB: Stored Cross-Site Scripting via Secure Attachment
NocoDB: Stored Cross-Site Scripting via Secure Attachment