Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-54306Medium· 5.4n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54311Medium· 6.3n8n: Merge Node SQL Mode Prototype Pollution
n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-54157Critical· 9.0PoCLobeHub: Unauthenticated SSRF in `/webapi/proxy`
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
GHSA-6xcg-6q43-rj2vLow· 6.1Duplicate Advisory: Exported session HTML could keep unsafe markdown links
Duplicate Advisory: Exported session HTML could keep unsafe markdown links
GHSA-6jm4-83g2-35gvMedium· 6.5Duplicate Advisory: memory-wiki shared search could miss session visibility checks
Duplicate Advisory: memory-wiki shared search could miss session visibility checks
GHSA-wrmq-9fc4-gwwjHigh· 8.8Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
GHSA-58wc-8wrv-xp9jMedium· 5.4Duplicate Advisory: Active Memory write scope could mutate global config
Duplicate Advisory: Active Memory write scope could mutate global config
GHSA-wrr6-p5r6-474mLow· 4.3Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers
GHSA-gw2c-6hcg-5g52Medium· 5.5Duplicate Advisory: Focus command could miss controlScope enforcement
Duplicate Advisory: Focus command could miss controlScope enforcement
GHSA-p44v-rx83-vjp4High· 8.1Duplicate Advisory: Discord allowFrom could bind to mutable display names
Duplicate Advisory: Discord allowFrom could bind to mutable display names
GHSA-c8w7-9w9h-x69qMedium· 5.3Duplicate Advisory: Slack reaction events could ignore reaction notification settings
Duplicate Advisory: Slack reaction events could ignore reaction notification settings
GHSA-r7vv-6763-m739Low· 4.3Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks
Duplicate Advisory: Skill-command dispatch could skip before-tool-call hooks
GHSA-qp5j-jr73-m2pwHigh· 7.1Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install
Duplicate Advisory: Workspace .env npm_execpath could influence bundled runtime dependency install
GHSA-27pq-2ph8-8x25High· 8.1Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks
GHSA-w7m7-3xcf-mp48High· 8.1Duplicate Advisory: Zalo allowFrom could bind to mutable display names
Duplicate Advisory: Zalo allowFrom could bind to mutable display names
GHSA-vqj9-vhg4-27mgMedium· 5.5Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions
Duplicate Advisory: Config recovery could restore openclaw.json with broad file permissions
GHSA-4qgr-57jq-93vhHigh· 7.1Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
Duplicate Advisory: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
GHSA-hc4w-hm59-9w88Low· 5.4Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment
Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope containment
GHSA-3v3j-737j-7g74High· 8.3Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns
Duplicate Advisory: Linux and macOS exec allowlists skipped configured argument patterns
GHSA-r2fx-hp6p-pgrmMedium· 6.5Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
Duplicate Advisory: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
GHSA-vqx6-6j84-2794Medium· 6.5Duplicate Advisory: Hostname checks could treat trailing-dot hosts inconsistently
Duplicate Advisory: Hostname checks could treat trailing-dot hosts inconsistently
GHSA-v383-2wgg-v483High· 8.1Duplicate Advisory: Shell inline-command parsing could miss an allowlist check
Duplicate Advisory: Shell inline-command parsing could miss an allowlist check
GHSA-8hj2-w4c9-fjfqLow· 4.2Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers
Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers
GHSA-g796-jqmx-wf9qMedium· 6.6Duplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags
Duplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags
GHSA-h9h6-pwqv-j9hvLow· 4.2Duplicate Advisory: Bootstrap token replay could widen pending pairing scopes
Duplicate Advisory: Bootstrap token replay could widen pending pairing scopes
GHSA-vr6h-vxqj-3pjxHigh· 8.1Duplicate Advisory: Host environment sanitizer missed two Node.js control variables
Duplicate Advisory: Host environment sanitizer missed two Node.js control variables
GHSA-8wmm-344f-mpjgMedium· 7.1Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs
Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs
GHSA-2w22-3f6x-3hf4High· 7.1Duplicate Advisory: Workspace-derived service PATH could influence trash command selection
Duplicate Advisory: Workspace-derived service PATH could influence trash command selection
CVE-2026-54312High· 8.5n8n: Microsoft SQL Node Prototype Pollution
n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-54303Medium· 7.6n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints