Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-48150Critical· 9.0Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
CVE-2026-48151High· 7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
CVE-2026-48152High· 8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
GHSA-g7r4-m6w7-qqqrLow· 2.5esbuild allows arbitrary file read when running the development server on Windows
esbuild allows arbitrary file read when running the development server on Windows
GHSA-gv7w-rqvm-qjhrHigh· 8.1Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
CVE-2026-44311Medium· 5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
CVE-2026-12143High· 7.5PoCform-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
CVE-2026-48022Medium· 6.5@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVE-2026-48038Medium· 5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
CVE-2026-48069High· 7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-48068High· 7.5@grpc/grpc-js: A malformed request can cause a server crash
@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-48049Medium· 5.3@hapi/inert has a static-file confinement bypass via sibling-prefix path
@hapi/inert has a static-file confinement bypass via sibling-prefix path
CVE-2025-71330High· 7.5image-size: ICNS parser allows denial of service through an infinite loop
image-size: ICNS parser allows denial of service through an infinite loop
CVE-2025-71329High· 7.5PoCimage-size: JXL and HEIF parsers allow denial of service through infinite loops
image-size: JXL and HEIF parsers allow denial of service through infinite loops
CVE-2026-48032High@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
CVE-2026-48033High@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
CVE-2026-48034High@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
CVE-2026-48035High@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
CVE-2026-48036High@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
CVE-2026-48037Medium@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
CVE-2026-48051Low· 3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
CVE-2026-47430CriticalCordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
CVE-2026-42890Mediumactual Allows Electron to Run As Node
actual Allows Electron to Run As Node
CVE-2026-33244Medium· 5.4React Router has stored XSS via unescaped Location header in prerendered redirect HTML
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
CVE-2026-35630High· 8.0OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin…
CVE-2026-8769Low· 4.3@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
CVE-2026-44721High· 7.3open-webui Vulnerable to Stored XSS via Model Description
open-webui Vulnerable to Stored XSS via Model Description
CVE-2026-40171High· 8.8Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
CVE-2026-56275Medium· 7.1Flowise Execute Flow function has an SSRF vulnerability
Flowise Execute Flow function has an SSRF vulnerability
CVE-2026-41182Medium· 5.3LangSmith SDK: Streaming token events bypass output redaction
LangSmith SDK: Streaming token events bypass output redaction