VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-59160High· 8.8PoC
1w ago

Yeger is a monorepo for npm packages maintained under the yeger scope

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by defaul…

▾ MidnightDerYeger · yegerEPSS 0.49%via NVD
CVE-2026-53957High· 7.7PoC
1w ago

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-…

▾ Midnightcontentful · contentful-mcp-serverEPSS 0.41%via NVD
CVE-2026-54688Medium· 6.5PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllow…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.50%via NVD
CVE-2026-54689Medium· 6.3PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is en…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.19%via NVD
CVE-2026-55178High· 7.5
1w ago

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a…

▾ Twilightgeolens-io · geolensEPSS 0.65%via NVD
CVE-2026-54561Medium· 6.2PoC
1w ago

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path …

▾ Twilightmkreyman · mcp-memory-keeperEPSS 0.25%via NVD
CVE-2026-55617Medium· 6.9
1w ago

Hydro is a next-generation high-performance online judge platform

Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous tok…

▾ Sunlithydro-dev · HydroEPSS 0.47%via NVD
CVE-2026-55650Medium· 4.4PoC
1w ago

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangero…

▾ Twilightouterbase · studioEPSS 0.19%via NVD
CVE-2026-55591Medium· 5.8PoC
1w ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalK…

▾ TwilightSignalK · signalk-serverEPSS 0.30%via NVD
CVE-2026-61534Critical· 9.1PoC
1w ago

Yayson is a library for serializing and reading JSON API data in JavaScript

Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/stor…

▾ Abyssalyayson · yaysonEPSS 0.84%via NVD
CVE-2026-59960High· 7.5
1w ago

Argos JavaScript provides official Argos SDKs for JavaScript

Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseComm…

▾ Twilightargos-ci · argos-javascriptEPSS 0.64%via NVD
CVE-2026-55451High· 8.3PoC
1w ago

gettext-converter provides gettext resource conversion utilities for JavaScript

gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number sign…

▾ Midnightlocize · gettext-converterEPSS 0.57%via NVD
CVE-2026-54150Medium· 6.9
1w ago

next-video is a library for adding video to Next.js applications

next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/…

▾ Sunlitmuxinc · next-videoEPSS 0.42%via NVD
CVE-2026-54155High· 7.7
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not ve…

▾ Twilightnode-opcua · node-opcuaEPSS 0.42%via NVD
CVE-2026-54156High· 7.5
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer…

▾ Twilightnode-opcua · node-opcuaEPSS 0.78%via NVD
CVE-2026-55102Medium· 5.8
1w ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosEr…

▾ Sunlitkyndryl-open-source · hashi-vault-jsEPSS 0.16%via NVD
CVE-2026-53496Medium· 5.3PoC
1w ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where f…

▾ Twilightmattiasw · ExifReaderEPSS 0.51%via NVD
CVE-2026-49250High· 8.7
1w ago

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or U…

▾ Twilightedmundhung · conformEPSS 0.51%via NVD
CVE-2026-55091High· 7.5
1w ago

flat-to-nested converts a hierarchy from a flat representation to a nested representation

flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp…

▾ Twilightjoaonuno · flat-to-nested-jsEPSS 0.50%via NVD
CVE-2026-59149Medium· 6.5
2w ago

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

▾ Sunlitmockoon · @mockoon/commons-serverEPSS 0.48%via GHSA
GHSA-w47m-jpv2-qfw5Critical· 9.8
2w ago

Duplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

Duplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

▾ Midnightknowns · knownsvia GHSA
GHSA-x7m8-jrm8-hpvxHigh· 8.1
2w ago

@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

▾ Twilighteigenpal · @eigenpal/docx-editor-corevia GHSA
CVE-2026-59179High· 8.3
2w ago

@openhop/server: Path Traversal in Flow ID File Operations

@openhop/server: Path Traversal in Flow ID File Operations

▾ Twilightopenhop · @openhop/servervia GHSA
CVE-2026-59176High· 7.8
2w ago

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

▾ Twilightfunctype-mcp-server · functype-mcp-servervia GHSA
CVE-2026-59158High· 7.5
2w ago

Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

▾ Twilightnuxt-ollama · nuxt-ollamavia GHSA
GHSA-qjrq-cvv4-3g9wHigh· 8.8
2w ago

Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools

Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools

▾ Twilightknowns · knownsvia GHSA
CVE-2026-86994Medium· 4.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, de…

▾ Sunlitn8n · n8nEPSS 0.34%via NVD
CVE-2026-86085Medium· 4.9
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …

▾ Sunlitn8n · n8nEPSS 0.44%via NVD
CVE-2026-86084Medium· 5.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterpri…

▾ Sunlitn8n · n8nEPSS 0.46%via NVD
CVE-2026-86083High· 8.8
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and inter…

▾ Twilightn8n · n8nEPSS 0.66%via NVD
CVEs tagged “npm” — page 3 · VulnSea