VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-48150Critical· 9.0
3mo ago

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

▾ Midnightbudibase · @budibase/serverEPSS 0.47%via GHSA
CVE-2026-48151High· 7.5
3mo ago

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

▾ Twilightbudibase · @budibase/serverEPSS 0.38%via GHSA
CVE-2026-48152High· 8.1
3mo ago

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

▾ Twilightbudibase · @budibase/serverEPSS 0.44%via GHSA
GHSA-g7r4-m6w7-qqqrLow· 2.5
3mo ago

esbuild allows arbitrary file read when running the development server on Windows

esbuild allows arbitrary file read when running the development server on Windows

▾ Sunlitesbuild · esbuildvia GHSA
GHSA-gv7w-rqvm-qjhrHigh· 8.1
3mo ago

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

▾ Twilightesbuild · esbuildvia GHSA
CVE-2026-44311Medium· 5.4
3mo ago

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

▾ Sunlitfabric · fabricEPSS 0.27%via GHSA
CVE-2026-12143High· 7.5PoC
3mo ago

form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…

▾ Midnightform-data · form-dataEPSS 0.67%via CVEORG
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

▾ Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-48038Medium· 5.3
3mo ago

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

▾ Sunlitjoi · joiEPSS 0.52%via GHSA
CVE-2026-48069High· 7.5
3mo ago

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-48068High· 7.5
3mo ago

@grpc/grpc-js: A malformed request can cause a server crash

@grpc/grpc-js: A malformed request can cause a server crash

▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-48049Medium· 5.3
3mo ago

@hapi/inert has a static-file confinement bypass via sibling-prefix path

@hapi/inert has a static-file confinement bypass via sibling-prefix path

▾ Sunlithapi · @hapi/inertEPSS 0.59%via GHSA
CVE-2025-71330High· 7.5
3mo ago

image-size: ICNS parser allows denial of service through an infinite loop

image-size: ICNS parser allows denial of service through an infinite loop

▾ Twilightimage-size · image-sizeEPSS 0.43%via GHSA
CVE-2025-71329High· 7.5PoC
3mo ago

image-size: JXL and HEIF parsers allow denial of service through infinite loops

image-size: JXL and HEIF parsers allow denial of service through infinite loops

▾ Midnightimage-size · image-sizeEPSS 0.43%via GHSA
CVE-2026-48032High
3mo ago

@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers

@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers

▾ Twilighthulumi · @hulumi/policiesEPSS 0.54%via GHSA
CVE-2026-48033High
3mo ago

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

▾ Twilighthulumi · @hulumi/policiesEPSS 0.48%via GHSA
CVE-2026-48034High
3mo ago

@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

▾ Twilighthulumi · @hulumi/policiesEPSS 0.45%via GHSA
CVE-2026-48035High
3mo ago

@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened

@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened

▾ Twilighthulumi · @hulumi/baselineEPSS 0.45%via GHSA
CVE-2026-48036High
3mo ago

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

▾ Twilighthulumi · @hulumi/driftEPSS 0.51%via GHSA
CVE-2026-48037Medium
3mo ago

@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

▾ Sunlithulumi · @hulumi/baselineEPSS 0.45%via GHSA
CVE-2026-48051Low· 3.5
3mo ago

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

▾ Sunlitpapra · @papra/webhooksEPSS 0.26%via GHSA
CVE-2026-47430Critical
3mo ago

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

▾ Midnightcordova-plugin-inappbrowser · cordova-plugin-inappbrowserEPSS 0.77%via GHSA
CVE-2026-42890Medium
3mo ago

actual Allows Electron to Run As Node

actual Allows Electron to Run As Node

▾ Sunlitactual · actualEPSS 0.18%via GHSA
CVE-2026-33244Medium· 5.4
3mo ago

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

▾ Sunlitreact-router · react-routerEPSS 0.14%via GHSA
CVE-2026-35630High· 8.0
4mo ago

OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin…

▾ TwilightOpenClaw · OpenClawEPSS 0.36%via CVEORG
CVE-2026-8769Low· 4.3
4mo ago

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

▾ Sunlitai-sdk · @ai-sdk/provider-utilsEPSS 0.73%via GHSA
CVE-2026-44721High· 7.3
4mo ago

open-webui Vulnerable to Stored XSS via Model Description

open-webui Vulnerable to Stored XSS via Model Description

▾ Twilightopen-webui · open-webuiEPSS 0.37%via OSV
CVE-2026-40171High· 8.8
5mo ago

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

▾ Twilightjupyter-notebook · @jupyter-notebook/help-extensionEPSS 0.66%via OSV
CVE-2026-56275Medium· 7.1
5mo ago

Flowise Execute Flow function has an SSRF vulnerability

Flowise Execute Flow function has an SSRF vulnerability

▾ Sunlitflowise · flowiseEPSS 0.32%via GHSA
CVE-2026-41182Medium· 5.3
5mo ago

LangSmith SDK: Streaming token events bypass output redaction

LangSmith SDK: Streaming token events bypass output redaction

▾ Sunlitlangsmith · langsmithEPSS 0.36%via OSV
CVEs tagged “npm” — page 33 · VulnSea