VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-55605Medium· 5.3
1mo ago

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

▾ Sunlitarikusi · @arikusi/deepseek-mcp-serverEPSS 0.60%via GHSA
CVE-2026-55663Medium· 5.6
1mo ago

mediasoup is a WebRTC video conferencing system

mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded m…

▾ Sunlitmediasoup · mediasoupEPSS 0.19%via NVD
CVE-2026-55557High
1mo ago

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the caller-controlled save_dir, while bro…

▾ Twilightbrowse-mcp · browse-mcpEPSS 0.24%via NVD
CVE-2026-55596High· 8.7
1mo ago

Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

▾ Twilightplatejs · @platejs/mediaEPSS 0.43%via GHSA
GHSA-8qx3-8gm5-9cj2High
1mo ago

pickem vulnerable to terminal escape-sequence injection via unsanitized item text

pickem vulnerable to terminal escape-sequence injection via unsanitized item text

▾ Twilightpickem · pickemvia GHSA
CVE-2026-55553High· 7.5
1mo ago

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across orig…

▾ Twilighturllib · urllibEPSS 0.66%via NVD
CVE-2026-76845Medium· 6.5
1mo ago

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and U…

▾ Sunlitadm-zip · adm-zipEPSS 0.17%via NVD
CVE-2026-76172High· 7.5
1mo ago

fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)

A flaw was found in fast-uri, a software component used for parsing Uniform Resource Identifiers (URIs) in Node.js applications. This vulnerability arises from an issue in how fast-uri processes the scheme part of a URI, specifically when …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2026-75899High· 7.5
1mo ago

fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)

A flaw was found in fast-uri, a URI parser for Node.js. The component incorrectly decodes percent escapes in a hostname twice during URI parsing and authority recomposition. This double decoding can allow a remote attacker to manipulate a …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-75975High· 7.5
1mo ago

fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)

A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a mal…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-75931High· 7.5
1mo ago

fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931)

A flaw was found in fast-uri, a URI parser for Node.js. This vulnerability arises because the parser fails to consistently convert internationalized domain names (IDN) to their standard ASCII form when processing scheme-relative references…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2026-61824High· 8.2
1mo ago

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

▾ Twilightdefuddle · defuddleEPSS 0.41%via GHSA
CVE-2026-63421High· 7.5
1mo ago

Keystone is a content management system for Node.js

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthentica…

▾ Twilightkeystone-6 · @keystone-6/coreEPSS 0.67%via NVD
CVE-2026-77413Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An…

▾ Midnightjsonata · jsonataEPSS 0.72%via NVD
CVE-2026-77414Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, protot…

▾ Midnightjsonata · jsonataEPSS 0.57%via NVD
CVE-2026-77415Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects thro…

▾ Midnightjsonata · jsonataEPSS 0.89%via NVD
CVE-2026-63462High· 7.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericE…

▾ Twilightunleash-server · unleash-serverEPSS 0.70%via NVD
CVE-2026-63004Medium· 5.5
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts and the Slack, Microsoft Team…

▾ Sunlitunleash-server · unleash-serverEPSS 0.39%via NVD
CVE-2026-63466Medium· 4.1
1mo ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templa…

▾ Sunlitunleash-server · unleash-serverEPSS 0.32%via NVD
CVE-2026-53509Medium· 5.7
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to a…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.38%via NVD
CVE-2026-65842High· 8.2
1mo ago

Plate is a rich-text editor with AI and shadcn/ui

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can…

▾ Twilightplatejs · @platejs/docx-ioEPSS 0.52%via NVD
CVE-2026-68921Medium· 4.7
1mo ago

DiceBear is an avatar library for designers and developers

DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, whil…

▾ Sunlitdicebear · @dicebear/coreEPSS 0.29%via NVD
CVE-2026-61704High· 7.5
1mo ago

Link Preview JS extracts web links information

Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public …

▾ Twilightlink-preview-js · link-preview-jsEPSS 0.55%via NVD
GHSA-ghvf-qf6h-g8x5High
1mo ago

NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution

NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution

▾ Twilightnocobase · @nocobase/servervia GHSA
CVE-2026-40345HighPoC
1mo ago

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs …

▾ Midnightdeepmerge-ts · deepmerge-tsEPSS 0.52%via NVD
CVE-2026-69222High· 7.5
1mo ago

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in src/filters/array.ts computes complexity from array.length and separator length instead of the total string length p…

▾ Twilightliquidjs · liquidjsEPSS 0.63%via NVD
CVE-2026-62682Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUr…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-62681Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch,…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71864Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schem…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71865Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a query parameter name is emitted into the generated request-validation zod.object({...}) schema…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVEs tagged “npm” — page 7 · VulnSea