VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-54269Medium· 5.3
3mo ago

protobufjs : Schema-derived names can shadow runtime-significant properties

protobufjs : Schema-derived names can shadow runtime-significant properties

▾ Sunlitprotobufjs · protobufjsEPSS 0.40%via GHSA
CVE-2026-48712High· 7.5
3mo ago

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

▾ Twilightprotobufjs · protobufjsEPSS 0.46%via GHSA
GHSA-r7g4-qg5f-qqm2Medium· 6.5
3mo ago

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-wqvq-jvpq-h66fMedium· 5.4
3mo ago

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-268h-hp4c-crq3Medium· 5.4
3mo ago

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

▾ Sunlitnodemailer · nodemailervia GHSA
CVE-2026-49459Medium· 6.1
3mo ago

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

▾ Sunlitdompurify · dompurifyEPSS 0.36%via GHSA
CVE-2026-49458Medium· 6.1
3mo ago

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

▾ Sunlitdompurify · dompurifyEPSS 0.40%via GHSA
GHSA-76mc-f452-cxcmMedium· 6.1
3mo ago

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-x4vx-rjvf-j5p4Low
3mo ago

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-gvmj-g25r-r7wrLow
3mo ago

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

▾ Sunlitdompurify · dompurifyvia GHSA
CVE-2026-53633Critical· 9.8
3mo ago

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

▾ Midnightvitest · @vitest/browserEPSS 0.90%via GHSA
CVE-2026-53663Low· 3.1
3mo ago

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

▾ Sunlitreact-router · react-routerEPSS 0.15%via GHSA
GHSA-vxr8-fq34-vvx9Low
3mo ago

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

▾ Sunlitdompurify · dompurifyvia GHSA
CVE-2026-54270Medium· 5.3
3mo ago

protobufjs: Memory amplification from preserved unknown fields in binary decode

protobufjs: Memory amplification from preserved unknown fields in binary decode

▾ Sunlitprotobufjs · protobufjsEPSS 0.40%via GHSA
CVE-2026-54271High· 8.2
3mo ago

protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names

protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names

▾ Twilightprotobufjs-cli · protobufjs-cliEPSS 0.30%via GHSA
CVE-2026-48125Medium· 5.3
3mo ago

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

▾ Sunlitua-parser-js · ua-parser-jsEPSS 0.52%via GHSA
CVE-2026-54257Critical
3mo ago

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

▾ Midnightelectron · electronEPSS 0.43%via GHSA
CVE-2026-54281High
3mo ago

Nest: Middleware Bypass on Fastify via Trailing Slash

Nest: Middleware Bypass on Fastify via Trailing Slash

▾ Twilightnestjs · @nestjs/platform-fastifyEPSS 0.50%via GHSA
CVE-2026-54285Medium· 5.3
3mo ago

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

▾ Sunlitopentelemetry · @opentelemetry/coreEPSS 0.40%via GHSA
CVE-2026-48988Medium· 5.3
3mo ago

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

▾ Sunlitmarkdown-it · markdown-itEPSS 0.43%via GHSA
CVE-2026-11417High· 7.3PoC
3mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

▾ Midnightaws-cdk-lib · aws-cdk-libEPSS 0.99%via GHSA
GHSA-rq7w-g337-39qqLow
3mo ago

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-30120Critical· 9.8
3mo ago

Remotion: remote code execution (RCE) vulnerability

Remotion: remote code execution (RCE) vulnerability

▾ Midnightremotion · remotionEPSS 0.87%via GHSA
CVE-2026-30121Critical· 9.1
3mo ago

Remotion: arbitrary file write vulnerability

Remotion: arbitrary file write vulnerability

▾ Midnightremotion · remotionEPSS 0.48%via GHSA
CVE-2026-5038High· 7.5⚖ disputed
3mo ago

multer: Multer: Denial of Service via aborted or malformed multipart uploads (CVE-2026-5038)

A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, whi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-5079High· 7.5
3mo ago

multer: Multer: Denial of Service via deeply nested field names in multipart form data (CVE-2026-5079)

A flaw was found in Multer. A remote attacker can exploit this vulnerability by sending a single HTTP request with crafted multipart form data containing deeply nested field names. This can force the allocation of deeply nested object stru…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-48128Medium
3mo ago

Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step

Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step

▾ Sunlitbudibase · budibaseEPSS 0.48%via GHSA
CVE-2026-48146High· 7.7
3mo ago

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection

▾ Twilightbudibase · @budibase/serverEPSS 0.34%via GHSA
CVE-2026-48147Medium· 6.5
3mo ago

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

▾ Sunlitbudibase · @budibase/backend-coreEPSS 0.17%via GHSA
CVE-2026-48148Medium
3mo ago

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

▾ Sunlitbudibase · @budibase/serverEPSS 0.35%via GHSA
CVEs tagged “npm” — page 32 · VulnSea