Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-53930MediumNocoDB: Server-Side Request Forgery via Base Migration URL
NocoDB: Server-Side Request Forgery via Base Migration URL
CVE-2026-53931MediumNocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-53840High· 7.1OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
CVE-2026-54316MediumPoCClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
CVE-2026-9595Medium· 5.3webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
CVE-2026-6734High· 7.5undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
A flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one dest…
CVE-2026-12151High· 7.5undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client …
CVE-2026-9697High· 7.4undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
A flaw was found in undici. When undici's ProxyAgent is configured with a SOCKS5 proxy Uniform Resource Identifier (URI), it silently ignores Transport Layer Security (TLS) options, such as custom Certificate Authorities (CAs). This allows…
CVE-2026-56301Medium· 5.5Nuxt dev server vite-node IPC socket is world-connectable on Linux
Nuxt dev server vite-node IPC socket is world-connectable on Linux
CVE-2026-56317LowCross-site scripting via <NoScript> slot content in Nuxt's head components
Cross-site scripting via <NoScript> slot content in Nuxt's head components
CVE-2026-56326Medium· 6.1Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-53721HighNuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
GHSA-534h-c3cw-v3h9Medium· 5.5Nuxt dev server vite-node IPC socket is world-connectable on Linux
Nuxt dev server vite-node IPC socket is world-connectable on Linux
CVE-2026-53722MediumNuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
CVE-2026-50146High· 7.1Astro: Reflected XSS via unescaped slot name
Astro: Reflected XSS via unescaped slot name
CVE-2026-54287Medium· 5.3hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVE-2026-54286Medium· 5.9hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-54290High· 7.1hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVE-2026-54289Medium· 4.8hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
CVE-2026-54288Medium· 6.5hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
CVE-2026-54300Medium· 5.3@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
CVE-2026-54299High· 7.5Astro: Host header SSRF in prerendered error page fetch
Astro: Host header SSRF in prerendered error page fetch
CVE-2026-54298Medium· 4.2Astro: XSS via Unescaped Attribute Names in Spread Props
Astro: XSS via Unescaped Attribute Names in Spread Props
CVE-2026-49444High· 8.5n8n: Python sandbox escape
n8n: Python sandbox escape
CVE-2026-49465Medium· 7.7n8n: Git Node Clone and Push Operations Bypass File Sandbox
n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-54310Medium· 9.9n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2026-54313Medium· 7.7n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
GHSA-hv7x-3x78-gx53Medium· 7.4n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-54308Medium· 7.2n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
n8n: Same-Origin XSS in Respond to Webhook Node