VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-47719High· 8.2
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-contro…

▾ Twilightfuxa-server · fuxa-serverEPSS 0.59%via NVD
CVE-2026-47720Medium· 5.3
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape …

▾ Sunlitfuxa-server · fuxa-serverEPSS 0.64%via NVD
CVE-2026-47721Medium· 6.3
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api/scheduler/index.js do not consistently enforce authJwt.haveAdminPermission for schedule…

▾ Sunlitfuxa-server · fuxa-serverEPSS 0.43%via NVD
CVE-2026-50143High· 8.1
1mo ago

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the tru…

▾ Twilightapify · @apify/actors-mcp-serverEPSS 0.49%via NVD
CVE-2026-19693High· 8.1
1mo ago

extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)

A flaw was found in extract-zip. This vulnerability allows a remote attacker to perform an arbitrary file write outside the intended destination directory. By crafting a malicious zip archive containing a symbolic link (symlink) and a regu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.28%via CSAF
CVE-2026-63669Medium· 6.5
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the chec…

▾ Sunlitapostrophe · apostropheEPSS 0.31%via NVD
CVE-2026-63670Medium· 6.1
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a li…

▾ Sunlitsanitize-html · sanitize-htmlEPSS 0.33%via NVD
CVE-2026-63667Medium· 6.5
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and ex…

▾ Sunlitapostrophecms · @apostrophecms/import-exportEPSS 0.46%via NVD
CVE-2026-54356High· 7.1PoC
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-…

▾ Midnightbudibase · @budibase/serverEPSS 0.35%via NVD
CVE-2026-53766Medium· 6.1
1mo ago

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.12%via GHSA
CVE-2026-56677High· 8.6
1mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js with…

▾ Twilight9router · 9routerEPSS 0.38%via NVD
CVE-2026-69146Medium· 6.5
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any a…

▾ Sunlitmlflow · mlflowEPSS 0.39%via NVD
CVE-2026-69148High· 7.1
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in…

▾ Twilightmlflow · mlflowEPSS 0.37%via NVD
CVE-2026-47683High· 7.5
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowin…

▾ Twilightvm2 · vm2EPSS 0.54%via NVD
CVE-2026-47686Critical· 9.9
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing s…

▾ Midnightvm2 · vm2EPSS 0.58%via NVD
CVE-2026-47698Critical· 9.8
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing …

▾ Midnightvm2 · vm2EPSS 0.97%via NVD
GHSA-m5w8-4gq2-6f8xCritical· 10.0
1mo ago

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

▾ Midnightvm2 · vm2via GHSA
GHSA-v836-6xw4-9cx3High· 7.5
1mo ago

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

▾ Twilightvm2 · vm2via GHSA
GHSA-92hr-gmr6-h8cpMedium
1mo ago

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

▾ Sunlitep_etherpad-lite · ep_etherpad-litevia GHSA
CVE-2026-35219High
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, p…

▾ Twilightbudibase · @budibase/serverEPSS 0.46%via NVD
CVE-2026-73844Low· 3.7
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.36%via NVD
CVE-2026-73846Medium· 6.5
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing differen…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.19%via NVD
CVE-2026-73845Medium· 5.3
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a pre…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.38%via NVD
CVE-2026-55157High· 8.4
1mo ago

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

▾ Twilightooples · @ooples/token-optimizer-mcpvia GHSA
CVE-2026-55156Medium· 5.3
1mo ago

Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

▾ Sunlitooples · @ooples/token-optimizer-mcpvia GHSA
CVE-2026-50029Medium· 5.3
1mo ago

js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`

js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy pri…

▾ Sunlitjs-toml · js-tomlEPSS 0.40%via NVD
CVE-2026-45819High· 7.5
1mo ago

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.51%via NVD
CVE-2026-73654High· 8.5
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operati…

▾ Twilighttrigger.dev · @trigger.dev/coreEPSS 0.62%via NVD
CVE-2026-49856Medium· 4.3
1mo ago

@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research

@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reser…

▾ Sunlitjshookmcp · @jshookmcp/jshookEPSS 0.28%via NVD
CVE-2026-49857High· 7.4
1mo ago

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests to private and loopback addresses. Ho…

▾ Twilightauth-fetch-mcp · auth-fetch-mcpEPSS 0.49%via NVD
CVEs tagged “npm” — page 9 · VulnSea