VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-71868Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod …

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71867Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71871Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emit…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71869Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted b…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-72717Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-61556High
1mo ago

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/html.ts can enter an infinite loop when an input string contains <, includes at least on…

▾ Twilightliquidjs · liquidjsEPSS 0.52%via NVD
CVE-2026-71866Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema w…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-72716Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitt…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-62680High· 7.1
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. P…

▾ Twilightorval · orvalEPSS 0.40%via NVD
CVE-2026-59992Medium· 5.4
1mo ago

Tina is a headless content management system

Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled obj…

▾ Sunlitnext-tinacms-s3 · next-tinacms-s3EPSS 0.38%via NVD
CVE-2026-63123Medium· 6.5
1mo ago

Tina is a headless content management system

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, an…

▾ Sunlittinacms · @tinacms/cliEPSS 0.26%via NVD
CVE-2026-63188High
1mo ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static as…

▾ Twilightlogto · @logto/tunnelEPSS 0.54%via NVD
GHSA-cc2g-gq8c-r332High· 7.5
1mo ago

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

▾ Twilightgrok-faf-mcp · grok-faf-mcpvia GHSA
GHSA-j4r7-8ph4-43g3High· 7.5
1mo ago

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightfaf-mcp · faf-mcpvia GHSA
GHSA-rr55-jp92-8wp2High· 7.5
1mo ago

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightclaude-faf-mcp · claude-faf-mcpvia GHSA
GHSA-hjwh-xvfw-qrwjMedium· 5.5
1mo ago

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

▾ Sunlitmcp-searxng · mcp-searxngvia GHSA
CVE-2026-55090High
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute esc…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.55%via NVD
CVE-2026-55086Medium· 4.2
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared wo…

▾ Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.14%via NVD
CVE-2026-55088Medium· 6.8
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTra…

▾ Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.44%via NVD
CVE-2026-55087Medium· 6.1PoC
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admi…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.58%via NVD
CVE-2026-49253High· 7.1
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/z…

▾ Twilightelecterm · electermEPSS 0.44%via NVD
CVE-2026-49255High· 8.8
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), a…

▾ Twilightelecterm · electermEPSS 0.79%via NVD
CVE-2026-16732Medium· 6.1
1mo ago

fastify: fastify: Request spoofing via numeric trustProxy configuration (CVE-2026-16732)

A flaw was found in fastify. When configured with a numeric `trustProxy` value, an attacker who can directly access the Fastify origin, bypassing the front-facing proxy, can spoof forwarded request fields. This vulnerability allows for hos…

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.16%via CSAF
GHSA-c7hr-448w-65pxHigh· 8.3
1mo ago

MeshCentral has unsanitized data fields

MeshCentral has unsanitized data fields

▾ Twilightmeshcentral · meshcentralvia GHSA
CVE-2026-63641Low
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equival…

▾ Sunlitmagicmirror · magicmirrorEPSS 0.43%via NVD
CVE-2026-63642MediumPoC
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed…

▾ Twilightmagicmirror · magicmirrorEPSS 0.50%via NVD
CVE-2026-63643Medium
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through…

▾ Sunlitmagicmirror · magicmirrorEPSS 0.66%via NVD
CVE-2026-63640Medium· 4.3
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder i…

▾ Sunlitmagicmirror · magicmirrorEPSS 0.30%via NVD
GHSA-2mf3-mr2r-r4vfHigh· 7.5
1mo ago

@rhinostone/swig: arbitrary local file read via include/extends path traversal

@rhinostone/swig: arbitrary local file read via include/extends path traversal

▾ Twilightrhinostone · @rhinostone/swigvia GHSA
CVE-2026-59940Critical· 9.8
1mo ago

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general…

▾ Midnightseroval · serovalEPSS 0.81%via NVD
CVEs tagged “npm” — page 8 · VulnSea