Modern Frontend CVEs

最新の脆弱性情報

React, Next.js, Vue, Node.js エコシステムに関連する最新のセキュリティアドバイザリ(CVE)を収集しています。

よく探す:
深刻度:
全 1224 件中 1224 件を表示
GHSA-gv7w-rqvm-qjhrhighCVSS: 8.1
2026-06-12

esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

esbuild>= 0.17.0, < 0.28.10.28.1
CVE-2026-48151highCVSS: 7.5
2026-06-12

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

@budibase/server< 3.39.03.39.0
CVE-2026-48150criticalCVSS: 9
2026-06-12

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

@budibase/server< 3.39.03.39.0
CVE-2026-48147mediumCVSS: 6.5
2026-06-12

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

@budibase/backend-core< 3.35.43.35.4
CVE-2026-48049mediumCVSS: 5.3
2026-06-11

@hapi/inert has a static-file confinement bypass via sibling-prefix path

@hapi/inert>= 4.0.0, <= 7.1.07.1.1
Advertisement
CVE-2026-42890medium
2026-06-08

actual Allows Electron to Run As Node

actual< 26.5.026.5.0
CVE-2026-48017highCVSS: 8.8
2026-06-05

DbGate: Remote Code Execution via functionName injection in loadReader endpoint

dbgate-api<= 7.1.87.1.9
CVE-2026-47684highCVSS: 7.7
2026-06-05

Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP

@sync-in/server<= 2.2.12.3.0
CVE-2026-47668criticalCVSS: 10
2026-06-05

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

dbgate-serve<= 7.1.87.1.9
CVE-2026-47250mediumCVSS: 6.1
2026-06-05

MCP Server Kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration

mcp-server-kubernetes<= 3.6.23.7.0
Advertisement
CVE-2026-34077highCVSS: 7.5
2026-06-04

React Router vulnerable to Denial of Service via reflected user input in single-fetch

react-router>= 7.0.0, < 7.14.07.14.0
turbo-stream< 3.0.03.0.0
CVE-2026-44496highCVSS: 7.5
2026-06-04

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

axios>= 1.0.0, < 1.16.01.16.0
axios<= 0.31.10.32.0
CVE-2026-44488highCVSS: 7.5
2026-06-04

Allocation of Resources Without Limits or Throttling in Axios

axios>= 1.7.0, < 1.16.01.16.0
CVE-2026-44487high
2026-06-04

Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

axios>= 1.0.0, < 1.16.01.16.0
axios<= 0.31.10.32.0
CVE-2026-44486highCVSS: 7.5
2026-06-04

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

axios>= 1.0.0, < 1.16.01.16.0
axios<= 0.31.10.32.0
Advertisement
CVE-2026-49143highCVSS: 8.8
2026-06-03

browserstack-runner vulnerable to Remote Code Execution via vm sandbox escape in _log HTTP handler

browserstack-runner<= 0.9.5
CVE-2026-49144highCVSS: 6.5
2026-06-03

browserstack-runner has an unauthenticated arbitrary file read via path traversal in HTTP server

browserstack-runner<= 0.9.5
CVE-2026-42342highCVSS: 7.5
2026-06-03

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

react-router>= 7.0.0, < 7.15.07.15.0
@remix-run/server-runtime>= 2.10.0, < 2.17.52.17.5
CVE-2026-42211highCVSS: 8.1
2026-06-03

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

react-router>= 7.0.0, <= 7.14.17.14.2
CVE-2026-40181medium
2026-06-03

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

react-router>= 7.0.0, < 7.14.17.14.1
react-router>= 6.7.0, < 6.30.46.30.4
Advertisement
CVE-2026-33245highCVSS: 8
2026-06-03

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

react-router>= 7.7.0, < 7.13.27.13.2
CVE-2026-33244mediumCVSS: 5.4
2026-06-03

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

react-router>= 7.5.1, < 7.13.27.13.2
CVE-2026-47428criticalCVSS: 9.6
2026-06-01

Vitest browser mode serves unsanitized otelCarrier query parameter as inline script

@vitest/browser>= 4.0.17, < 4.1.64.1.6
@vitest/browser>= 5.0.0-beta.0, < 5.0.0-beta.35.0.0-beta.3
CVE-2026-47429criticalCVSS: 9.8
2026-06-01

When Vitest UI server is listening, arbitrary file can be read and executed

vitest>= 4.0.0, < 4.1.04.1.0
vitest< 3.2.63.2.6
CVE-2026-50287high
2026-06-01

@agenticmail/mcp Missing Authentication for Critical Function

@agenticmail/mcp< 0.9.270.9.27
Advertisement
CVE-2026-47141medium
2026-05-29

NodeVM observability builtins leak host process and HTTP request data

vm2<= 3.11.33.11.4
CVE-2026-47139highCVSS: 8.6
2026-05-29

NodeVM network builtin exclusions bypass via internal _http_client and _http_server

vm2<= 3.11.33.11.4
CVE-2026-47140criticalCVSS: 10
2026-05-29

NodeVM builtin denylist bypass via process and inspector/promises allows host code execution

vm2<= 3.11.33.11.4
CVE-2026-47210criticalCVSS: 9.8
2026-05-29

vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass

vm2<= 3.11.33.11.4
CVE-2026-47135highCVSS: 8.7
2026-05-29

vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks

vm2<= 3.11.33.11.4
Advertisement
GHSA-q3fm-4wcw-g57xlow
2026-05-29

vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter

vm2<= 3.11.33.11.4
CVE-2026-47131criticalCVSS: 10
2026-05-29

vm2 has a Sandbox Escape issue

vm2<= 3.11.33.11.4
CVE-2026-47200medium
2026-05-29

Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`

nuxt>= 3.11.0, <= 3.21.53.21.6
@nuxt/nitro-server>= 3.20.0, <= 3.21.53.21.6
@nuxt/nitro-server>= 4.2.0, <= 4.4.54.4.6
nuxt>= 4.0.0-alpha.1, <= 4.4.54.4.6
CVE-2026-44495highCVSS: 7
2026-05-29

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

axios>= 1.0.0, < 1.15.21.15.2
axios>= 0.19.0, < 0.31.10.31.1
CVE-2026-44492highCVSS: 8.6
2026-05-29

axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

axios>= 1.0.0, < 1.16.01.16.0
axios<= 0.31.10.32.0
Advertisement
CVE-2026-44489lowCVSS: 3.7
2026-05-29

Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

axios= 1.15.21.16.0
CVE-2026-48527highCVSS: 8.7
2026-05-29

HaxCMS has a stored Cross-Site Scripting (XSS) bypass in its saveNode endpoint

@haxtheweb/haxcms-nodejs<= 26.0.026.0.1
CVE-2026-47144mediumCVSS: 5.5
2026-05-28

Shamefile has an arbitrary file read via shamefile.yaml in shame next

shamefile<= 0.1.60.1.7
shamefile<= 0.1.60.1.7
shamefile<= 0.1.60.1.7
CVE-2026-45617highCVSS: 7.5
2026-05-27

LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex

liquidjs< 10.26.010.26.0
CVE-2026-45357highCVSS: 7.5
2026-05-27

LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)

liquidjs<= 10.25.7
Advertisement
CVE-2026-44705high
2026-05-27

tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

tmp< 0.2.60.2.6
CVE-2026-44646mediumCVSS: 5.3
2026-05-27

LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`

liquidjs<= 10.25.7
CVE-2026-44645mediumCVSS: 6.5
2026-05-27

LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body

liquidjs<= 10.25.7
CVE-2026-44644mediumCVSS: 6.1
2026-05-27

LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS

liquidjs<= 10.25.7
CVE-2026-43947high
2026-05-26

FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass

fuxa-server= 1.3.01.3.1
Advertisement
CVE-2026-43946high
2026-05-26

FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue

fuxa-server= 1.3.01.3.1
CVE-2026-43945high
2026-05-26

FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

@frangoteam/fuxa>= 1.2.11, < 1.3.11.3.1
CVE-2026-42462highCVSS: 7
2026-05-26

Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring

@fedify/fedify>= 2.2.0, < 2.2.32.2.3
@fedify/fedify>= 2.1.0, < 2.1.142.1.14
@fedify/fedify>= 2.0.0, < 2.0.182.0.18
@fedify/fedify>= 1.10.0, < 1.10.101.10.10
@fedify/fedify< 1.9.111.9.11
CVE-2026-28445highCVSS: 8.7
2026-05-26

Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview

@typebot.io/js< 0.10.10.10.1
CVE-2026-47138high
2026-05-23

Parse Server: Pre-authentication denial of service via client version header regex backtracking

parse-server>= 9.0.0, < 9.9.1-alpha.19.9.1-alpha.1
parse-server< 8.6.778.6.77
Advertisement
CVE-2026-8723mediumCVSS: 5.3
2026-05-22

qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

qs>= 6.11.1, <= 6.15.16.15.2
CVE-2026-46703criticalCVSS: 9.6
2026-05-21

Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host

boxlite< 0.9.00.9.0
boxlite-cli< 0.9.00.9.0
boxlite< 0.9.00.9.0
@boxlite-ai/boxlite< 0.9.00.9.0
github.com/boxlite-ai/boxlite/sdks/go< 0.9.00.9.0
CVE-2026-46679highCVSS: 7.5
2026-05-21

js-libp2p: Memory DoS via subscription flood of unique topics

@libp2p/gossipsub<= 15.0.2215.0.23
CVE-2026-46625highCVSS: 7.5
2026-05-21

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

js-cookie<= 3.0.53.0.7
CVE-2026-46547mediumCVSS: 6.1
2026-05-21

NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL

nocodb<= 0.301.3
Advertisement
CVE-2026-46490high
2026-05-21

samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions

samlify< 2.13.02.13.0
CVE-2026-30691mediumCVSS: 6.1
2026-05-20

@cyntler/react-doc-viewer's TXTRenderer fails to sanitize file content and explicitly casts raw data as a ReactNode

@cyntler/react-doc-viewer<= 1.17.1
GHSA-c2c9-mfw7-p8hwmedium
2026-05-20

Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows

flowise<= 3.1.13.1.2
CVE-2026-46417high
2026-05-19

@angular/platform-server: SSRF via Hostname Hijacking

@angular/platform-server>= 22.0.0-next.0, < 22.0.0-next.1222.0.0-next.12
@angular/platform-server>= 21.0.0-next.0, < 21.2.1321.2.13
@angular/platform-server>= 20.0.0-next.0, < 20.3.2120.3.21
@angular/platform-server>= 19.0.0-next.0, < 19.2.2219.2.22
@angular/platform-server<= 18.2.14
CVE-2026-46412criticalCVSS: 10
2026-05-19

Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm

@beproduct/nestjs-auth>= 0.1.2, <= 0.1.19
Advertisement
CVE-2026-46372highCVSS: 8.5
2026-05-19

SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

sillytavern<= 1.17.01.18.0
CVE-2026-45783highCVSS: 7.5
2026-05-19

@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes

@libp2p/kad-dht< 16.2.616.2.6
CVE-2026-46342low
2026-05-19

Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning

nuxt>= 3.1.0, <= 3.21.53.21.6
nuxt>= 4.0.0-alpha.1, <= 4.4.54.4.6
@nuxt/nitro-server>= 3.20.0, <= 3.21.53.21.6
@nuxt/nitro-server>= 4.2.0, <= 4.4.54.4.6
CVE-2026-45805highCVSS: 8.8
2026-05-19

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

@penpot/mcp< 2.15.02.15.0
CVE-2026-46357mediumCVSS: 6.5
2026-05-19

HAX CMS: Denial of Service using Malicious Import Request

@haxtheweb/haxcms-nodejs< 26.0.026.0.0
Advertisement
CVE-2026-46339criticalCVSS: 10
2026-05-19

9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

9router>= 0.4.30, < 0.4.370.4.37
CVE-2026-46341mediumCVSS: 6.1
2026-05-19

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching

@apify/actors-mcp-server< 0.9.210.9.21
GHSA-3875-8gcx-7v46mediumCVSS: 9.1
2026-05-19

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

n8n< 2.20.02.20.0
GHSA-2vx9-7wpg-88jqmediumCVSS: 6.4
2026-05-19

n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

n8n< 2.19.32.19.3
CVE-2026-45669medium
2026-05-19

Nuxt: Reflected XSS in `navigateTo()` external redirect

nuxt>= 3.4.3, <= 3.21.53.21.6
nuxt>= 4.0.0-alpha.1, <= 4.4.54.4.6
Advertisement
GHSA-hv85-774v-26fghighCVSS: 8.2
2026-05-19

auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs

auth-fetch-mcp<= 3.0.03.0.1
CVE-2026-46395critical
2026-05-19

HAXcms: Private Key Disclosure via Broken HMAC Implementation

@haxtheweb/haxcms-nodejs<= 25.0.026.0.0
CVE-2026-45736mediumCVSS: 4.4
2026-05-18

ws: Uninitialized memory disclosure

ws>= 8.0.0, < 8.20.18.20.1
CVE-2026-45707highCVSS: 8.1
2026-05-18

n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete

n8n-mcp<= 2.51.12.51.2
CVE-2026-45302highCVSS: 8.2
2026-05-18

parse-nested-form-data has Prototype Pollution via `__proto__` in FormData field names

parse-nested-form-data<= 1.0.01.0.1
Advertisement
CVE-2026-45577medium
2026-05-18

Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass

neotoma>= 0.6.0, < 0.11.10.11.1
CVE-2026-46510highCVSS: 8.2
2026-05-18

form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys

form-data-objectizer<= 1.0.01.0.1
CVE-2026-45582mediumCVSS: 6.5
2026-05-18

n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters

n8n-mcp< 2.51.32.51.3
CVE-2026-45411criticalCVSS: 9.8
2026-05-14

vm2 Has a Sandbox Breakout Using Async Generator

vm2<= 3.11.23.11.3
GHSA-wf8q-wvv8-p8jfcriticalCVSS: 9.1
2026-05-14

@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation

@samanhappy/mcphub< 0.12.150.12.15
Advertisement
CVE-2026-44990criticalCVSS: 9.3
2026-05-14

Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

sanitize-html= 2.17.32.17.4
GHSA-9m65-766c-r333medium
2026-05-14

TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function

@tanstack/start-server-core< 1.167.301.167.30
CVE-2026-44791critical
2026-05-14

n8n Has an XML Node Prototype Pollution Patch Bypass

n8n< 1.123.431.123.43
n8n>= 2.21.0, < 2.22.12.22.1
n8n>= 2.0.0-rc.0, < 2.20.72.20.7
CVE-2026-44790critical
2026-05-14

n8n Has an Arbitrary File Read via Git Node

n8n< 1.123.431.123.43
n8n>= 2.21.0, < 2.22.12.22.1
n8n>= 2.0.0-rc.0, < 2.20.72.20.7
CVE-2026-44789critical
2026-05-14

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

n8n< 1.123.431.123.43
n8n>= 2.21.0, < 2.22.12.22.1
n8n>= 2.0.0-rc.0, < 2.20.72.20.7
Advertisement
CVE-2026-42853mediumCVSS: 6.5
2026-05-14

@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input

@apostrophecms/cli<= 3.6.0
CVE-2026-46442critical
2026-05-14

FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape

flowise<= 3.1.13.1.2
GHSA-m99r-2hxc-cp3qhigh
2026-05-14

Flowise has an MCP Security Bypass that Enables RCE

flowise<= 3.1.13.1.2
flowise-components<= 3.1.13.1.2
CVE-2026-22599critical
2026-05-13

Strapi Vulnerable to SQL Injection in Content Type Builder

@strapi/content-type-builder>= 5.0.0, < 5.33.25.33.2
@strapi/plugin-content-type-builder>= 4.0.0, < 4.26.14.26.1
CVE-2026-44724highCVSS: 7.8
2026-05-13

Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name

systeminformation>= 4.17.0, <= 5.31.55.31.6
Advertisement
CVE-2026-42074criticalCVSS: 9.8
2026-05-12

OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input

openclaude< 0.5.10.5.1
CVE-2026-42073mediumCVSS: 6.5
2026-05-12

OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS

@gitlawb/openclaude< 0.5.10.5.1
CVE-2026-44288mediumCVSS: 5.3
2026-05-12

protobufjs has overlong UTF-8 decoding

protobufjs<= 7.5.57.5.6
protobufjs>= 8.0.0, <= 8.0.18.0.2
@protobufjs/utf8<= 1.1.01.1.1
CVE-2026-45321criticalCVSS: 9.6
2026-05-12

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

@tanstack/arktype-adapter= 1.166.121.166.16
@tanstack/eslint-plugin-router= 1.161.91.161.13
@tanstack/eslint-plugin-start= 0.0.40.0.8
@tanstack/history= 1.161.91.161.13
@tanstack/nitro-v2-vite-plugin= 1.154.121.154.16
@tanstack/react-router= 1.169.51.169.9
@tanstack/react-router-devtools= 1.166.161.166.20
@tanstack/react-router-ssr-query= 1.166.151.166.19
@tanstack/react-start= 1.167.681.167.72
@tanstack/react-start-client= 1.166.511.166.55
@tanstack/react-start-rsc= 0.0.470.0.51
@tanstack/react-start-server= 1.166.551.166.59
@tanstack/router-cli= 1.166.461.166.50
@tanstack/router-core= 1.169.51.169.9
@tanstack/router-devtools= 1.166.161.166.20
@tanstack/router-devtools-core= 1.167.61.167.10
@tanstack/router-generator= 1.166.451.166.49
@tanstack/router-plugin= 1.167.381.167.42
@tanstack/router-ssr-query-core= 1.168.31.168.7
@tanstack/router-utils= 1.161.111.161.15
@tanstack/router-vite-plugin= 1.166.531.166.57
@tanstack/solid-router= 1.169.51.169.9
@tanstack/solid-router-devtools= 1.166.161.166.20
@tanstack/solid-router-ssr-query= 1.166.151.166.19
@tanstack/solid-start= 1.167.651.167.69
@tanstack/solid-start-client= 1.166.501.166.54
@tanstack/solid-start-server= 1.166.541.166.58
@tanstack/start-client-core= 1.168.51.168.9
@tanstack/start-fn-stubs= 1.161.91.161.13
@tanstack/start-plugin-core= 1.169.231.169.27
@tanstack/start-server-core= 1.167.331.167.37
@tanstack/start-static-server-functions= 1.166.441.166.48
@tanstack/start-storage-context= 1.166.381.166.42
@tanstack/valibot-adapter= 1.166.121.166.16
@tanstack/virtual-file-routes= 1.161.101.161.14
@tanstack/vue-router= 1.169.51.169.9
@tanstack/vue-router-devtools= 1.166.161.166.20
@tanstack/vue-router-ssr-query= 1.166.151.166.19
@tanstack/vue-start= 1.167.611.167.65
@tanstack/vue-start-client= 1.166.461.166.50
@tanstack/vue-start-server= 1.166.501.166.54
@tanstack/zod-adapter= 1.166.121.166.16
@tanstack/arktype-adapter= 1.166.151.166.16
@tanstack/eslint-plugin-router= 1.161.121.161.13
@tanstack/eslint-plugin-start= 0.0.70.0.8
@tanstack/history= 1.161.121.161.13
@tanstack/nitro-v2-vite-plugin= 1.154.151.154.16
@tanstack/react-router= 1.169.81.169.9
@tanstack/react-router-devtools= 1.166.191.166.20
@tanstack/react-router-ssr-query= 1.166.181.166.19
@tanstack/react-start= 1.167.711.167.72
@tanstack/react-start-client= 1.166.541.166.55
@tanstack/react-start-rsc= 0.0.500.0.51
@tanstack/react-start-server= 1.166.581.166.59
@tanstack/router-cli= 1.166.491.166.50
@tanstack/router-core= 1.169.81.169.9
@tanstack/router-devtools= 1.166.191.166.20
@tanstack/router-devtools-core= 1.167.91.167.10
@tanstack/router-generator= 1.166.481.166.49
@tanstack/router-plugin= 1.167.411.167.42
@tanstack/router-ssr-query-core= 1.168.61.168.7
@tanstack/router-utils= 1.161.141.161.15
@tanstack/router-vite-plugin= 1.166.561.166.57
@tanstack/solid-router= 1.169.81.169.9
@tanstack/solid-router-devtools= 1.166.191.166.20
@tanstack/solid-router-ssr-query= 1.166.181.166.19
@tanstack/solid-start= 1.167.681.167.69
@tanstack/solid-start-client= 1.166.531.166.54
@tanstack/solid-start-server= 1.166.571.166.58
@tanstack/start-client-core= 1.168.81.168.9
@tanstack/start-fn-stubs= 1.161.121.161.13
@tanstack/start-plugin-core= 1.169.261.169.27
@tanstack/start-server-core= 1.167.361.167.37
@tanstack/start-static-server-functions= 1.166.471.166.48
@tanstack/start-storage-context= 1.166.411.166.42
@tanstack/valibot-adapter= 1.166.151.166.16
@tanstack/virtual-file-routes= 1.161.131.161.14
@tanstack/vue-router= 1.169.81.169.9
@tanstack/vue-router-devtools= 1.166.191.166.20
@tanstack/vue-router-ssr-query= 1.166.181.166.19
@tanstack/vue-start= 1.167.641.167.65
@tanstack/vue-start-client= 1.166.491.166.50
@tanstack/vue-start-server= 1.166.531.166.54
@tanstack/zod-adapter= 1.166.151.166.16
CVE-2026-44635highCVSS: 7.5
2026-05-11

Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`

kysely>= 0.26.0, < 0.28.170.28.17
Advertisement
CVE-2026-45109highCVSS: 7.5
2026-05-11

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

next>= 15.2.0, < 15.5.1815.5.18
next>= 16.0.0, < 16.2.616.2.6
CVE-2026-45061highCVSS: 7.7
2026-05-11

Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)

budibase<= 3.34.113.35.10
CVE-2026-44572lowCVSS: 3.7
2026-05-11

Next.js's Middleware / Proxy redirects can be cache-poisoned

next>= 12.2.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
GHSA-mhwj-73qx-jqxmhighCVSS: 7.5
2026-05-11

@theecryptochad/merge-guard has Prototype Pollution in its deepMerge() function

@theecryptochad/merge-guard< 1.0.11.0.1
CVE-2026-44483highCVSS: 8.2
2026-05-11

@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data)

@rvf/set-get>= 7.0.0, < 7.0.27.0.2
@rvf/set-get>= 6.0.0, < 6.0.46.0.4
Advertisement
CVE-2026-44581mediumCVSS: 4.7
2026-05-11

Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces

next>= 13.4.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44582lowCVSS: 3.7
2026-05-11

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

next>= 13.4.6, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44580mediumCVSS: 6.1
2026-05-11

Next.js has cross-site scripting in beforeInteractive scripts with untrusted input

next>= 13.0.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44579highCVSS: 7.5
2026-05-11

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

next>= 15.0.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44577mediumCVSS: 5.9
2026-05-11

Next.js has a Denial of Service in the Image Optimization API

next>= 10.0.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
Advertisement
CVE-2026-44578highCVSS: 8.6
2026-05-11

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

next>= 13.4.13, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44576mediumCVSS: 5.4
2026-05-11

Next.js vulnerable to cache poisoning in React Server Component responses

next>= 14.2.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44575highCVSS: 7.5
2026-05-11

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes

next>= 15.2.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44574highCVSS: 8.1
2026-05-11

Next.js has a Middleware / Proxy bypass through dynamic route parameter injection

next>= 15.4.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-44573highCVSS: 7.5
2026-05-11

Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n

next>= 12.2.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
Advertisement
GHSA-w94c-4vhp-22gxhighCVSS: 7.5
2026-05-11

@vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components

@vitejs/plugin-rsc<= 0.5.250.5.26
GHSA-8h8q-6873-q5fjhighCVSS: 7.5
2026-05-11

Next.js Vulnerable to Denial of Service with Server Components

next>= 13.0.0, < 15.5.1615.5.16
next>= 16.0.0, < 16.2.516.2.5
CVE-2026-23870highCVSS: 7.5
2026-05-11

Facebook React has a Denial of Service Vulnerability in React Server Components

react-server-dom-parcel>= 19.0.0, < 19.0.619.0.6
react-server-dom-turbopack>= 19.0.0, < 19.0.619.0.6
react-server-dom-webpack>= 19.0.0, < 19.0.619.0.6
react-server-dom-parcel>= 19.1.0, < 19.1.719.1.7
react-server-dom-turbopack>= 19.1.0, < 19.1.719.1.7
react-server-dom-webpack>= 19.1.0, < 19.1.719.1.7
react-server-dom-parcel>= 19.2.0, < 19.2.619.2.6
react-server-dom-turbopack>= 19.2.0, < 19.2.619.2.6
react-server-dom-webpack>= 19.2.0, < 19.2.619.2.6
CVE-2026-44902highCVSS: 7.5
2026-05-11

Prometheus exporter process crash via malformed HTTP request

@opentelemetry/exporter-prometheus< 0.217.00.217.0
@opentelemetry/sdk-node< 0.217.00.217.0
@opentelemetry/auto-instrumentations-node< 0.75.00.75.0
CVE-2026-44895high
2026-05-09

@yoda.digital/gitlab-mcp-server's SSE transport has no authentication and wildcard CORS, exposing all 86 GitLab tools

@yoda.digital/gitlab-mcp-server< 0.6.00.6.0
Advertisement
CVE-2026-44211criticalCVSS: 9.6
2026-05-08

Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability

cline<= 2.13.0
GHSA-qhh4-458h-xwh2medium
2026-05-08

@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry

@cyclonedx/cdxgen>= 9.9.5, < 12.3.312.3.3
CVE-2026-7768highCVSS: 7.5
2026-05-08

@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth

@fastify/accepts-serializer<= 6.0.36.0.4
GHSA-8g7g-hmwm-6rv2highCVSS: 8.3
2026-05-08

n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure

n8n-mcp< 2.50.12.50.1
CVE-2026-44589lowCVSS: 3.7
2026-05-07

nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)

nuxt-og-image>= 6.2.5, < 6.4.96.4.9
Advertisement
CVE-2025-63706criticalCVSS: 9.8
2026-05-07

next-npm-version is vulnerable to Command injection

@jswork/next-npm-version= 1.0.1
CVE-2025-63705highCVSS: 8.8
2026-05-07

node-ts-ocr is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js

node-ts-ocr= 1.0.15
CVE-2026-44007criticalCVSS: 9.1
2026-05-07

vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution

vm2<= 3.11.03.11.1
CVE-2026-43998highCVSS: 8.5
2026-05-07

vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape

vm2= 3.10.53.11.0
CVE-2026-44003mediumCVSS: 5.3
2026-05-07

vm2's Transformer Fast-Path Bypass Exposes Internal State Variable

vm2<= 3.10.53.11.0
Advertisement
CVE-2026-44002mediumCVSS: 5.8
2026-05-07

vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak

vm2<= 3.10.53.11.0
CVE-2026-44004highCVSS: 7.5
2026-05-07

vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion

vm2<= 3.10.53.11.0
CVE-2026-44001highCVSS: 8.6
2026-05-07

vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)

vm2<= 3.10.53.11.0
CVE-2026-43999criticalCVSS: 9.9
2026-05-07

vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape

vm2= 3.10.53.11.0
CVE-2026-44456mediumCVSS: 6.5
2026-05-06

Hono: bodyLimit() can be bypassed for chunked / unknown-length requests

hono< 4.12.164.12.16
Advertisement
CVE-2026-44437medium
2026-05-06

Angular SSR has Open Redirect and Request Steering via Encoded X-Forwarded-Prefix

@angular/ssr>= 22.0.0-next.0, < 22.0.0-next.722.0.0-next.7
@angular/ssr>= 21.0.0-next.0, < 21.2.921.2.9
@angular/ssr>= 20.0.0-next.0, < 20.3.2520.3.25
@angular/ssr>= 19.0.0-next.0, < 19.2.2519.2.25
CVE-2026-44351criticalCVSS: 9.1
2026-05-06

fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver

fast-jwt<= 6.2.36.2.4
CVE-2026-44240highCVSS: 7.5
2026-05-06

basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering

basic-ftp<= 5.3.05.3.1
CVE-2026-44232high
2026-05-06

dssrf: every IPv6 category bypasses is_url_safe

dssrf< 1.3.01.3.0
GHSA-4c35-wcg5-mm9hmediumCVSS: 4.2
2026-05-06

next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys

next-intl<= 4.9.14.9.2
Advertisement
GHSA-r27j-894h-3w3plowCVSS: 3.7
2026-05-06

mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile: true`

icu-minify<= 4.9.14.9.2
GHSA-jxh8-jh77-xh6ghighCVSS: 8.1
2026-05-05

@evomap/evolver's validator sandbox allowlist permits `npm`/`npx`, yielding RCE from Hub-delivered validation tasks via lifecycle scripts

@evomap/evolver<= 1.70.0-beta.41.70.0-beta.5
GHSA-7xp7-m392-h92cmediumCVSS: 6.2
2026-05-05

@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS

@evomap/evolver<= 1.70.0-beta.41.70.0-beta.5
GHSA-cfcj-hqpf-hccfhighCVSS: 8.8
2026-05-05

@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)

@evomap/evolver<= 1.70.0-beta.41.70.0-beta.5
CVE-2026-42260highCVSS: 8.2
2026-05-05

open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`

open-websearch<= 2.1.62.1.7
Advertisement
CVE-2026-43929highCVSS: 8.2
2026-05-05

ssrfcheck Vulnerable to Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs

ssrfcheck<= 1.3.0
CVE-2026-42047highCVSS: 8.6
2026-05-05

Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods

inngest>= 3.22.0, < 3.54.03.54.0
CVE-2026-42045mediumCVSS: 6.2
2026-05-05

LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution

@lobehub/lobehub<= 2.1.26
CVE-2026-42856high
2026-05-05

Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls

network-ai<= 5.1.25.1.3
CVE-2026-26956criticalCVSS: 9.8
2026-05-05

VM2 Has a WASM Sandbox Escape

vm2<= 3.10.43.10.5
Advertisement
CVE-2026-26332criticalCVSS: 9.8
2026-05-05

VM2 Has a Sandbox Escape Issue via SuppressedError

vm2<= 3.10.43.11.0
CVE-2026-24781criticalCVSS: 9.8
2026-05-05

VM2 Has Sandbox Breakout Through Inspect Function

vm2<= 3.10.33.11.0
CVE-2026-42037mediumCVSS: 5.3
2026-05-05

Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

axios>= 1.0.0, < 1.15.11.15.1
CVE-2026-42039mediumCVSS: 7.5
2026-05-05

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

axios>= 1.0.0, < 1.15.11.15.1
axios<= 0.31.00.31.1
CVE-2026-42034mediumCVSS: 5.3
2026-05-05

Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

axios>= 1.0.0, < 1.15.11.15.1
axios<= 0.31.00.31.1
Advertisement
CVE-2026-42036mediumCVSS: 5.3
2026-05-05

Axios: HTTP adapter streamed responses bypass maxContentLength

axios>= 1.0.0, < 1.15.11.15.1
axios<= 0.31.00.31.1
CVE-2026-42033highCVSS: 7.4
2026-05-05

Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

axios>= 1.0.0, < 1.15.11.15.1
axios<= 0.31.00.31.1
CVE-2026-42043highCVSS: 7.2
2026-05-05

Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

axios>= 1.0.0, < 1.15.11.15.1
axios<= 0.31.00.31.1
CVE-2026-42264highCVSS: 7.4
2026-05-05

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

axios>= 1.0.0, < 1.15.21.15.2
CVE-2026-42349highCVSS: 8.1
2026-04-30

Clerk has an authorization bypass when combining organization, billing, or reverification checks

@clerk/shared>= 3.0.0, <= 3.47.43.47.5
@clerk/shared>= 4.0.0, <= 4.8.24.8.3
@clerk/backend>= 2.0.0, <= 2.33.22.33.3
@clerk/backend>= 3.0.0, <= 3.2.133.2.14
@clerk/nextjs>= 6.0.0, <= 6.39.26.39.3
@clerk/nextjs>= 7.0.0, <= 7.2.37.2.4
@clerk/clerk-js>= 5.22.0, <= 5.125.95.125.10
@clerk/clerk-js>= 6.0.0, <= 6.7.46.7.5
@clerk/clerk-react>= 5.9.0, <= 5.61.55.61.6
@clerk/react>= 6.0.0, <= 6.4.26.4.3
@clerk/vue>= 1.0.0, <= 1.17.201.17.21
@clerk/vue>= 2.0.0, <= 2.0.152.0.16
@clerk/astro>= 2.0.0, <= 2.17.102.17.11
@clerk/astro>= 3.0.0, <= 3.0.173.0.18
@clerk/nuxt>= 1.0.0, <= 1.13.281.13.29
@clerk/nuxt>= 2.0.0, <= 2.2.42.2.5
@clerk/clerk-expo>= 2.2.11, <= 2.19.352.19.36
@clerk/expo>= 3.0.0, <= 3.2.13.2.2
@clerk/react-router>= 0.0.1, <= 2.4.122.4.13
@clerk/react-router>= 3.0.0, <= 3.1.33.1.4
@clerk/tanstack-react-start>= 0.0.1, <= 0.29.100.29.11
@clerk/tanstack-react-start>= 1.0.0, <= 1.1.31.1.4
@clerk/chrome-extension>= 1.3.5, <= 2.9.142.9.15
@clerk/chrome-extension>= 3.0.0, <= 3.1.143.1.15
@clerk/fastify>= 1.0.42, <= 2.6.302.6.31
@clerk/fastify>= 3.0.0, <= 3.1.153.1.16
@clerk/express>= 0.1.0, <= 1.7.781.7.79
@clerk/express>= 2.0.0, <= 2.1.52.1.6
@clerk/hono>= 0.0.2, <= 0.1.150.1.16
Advertisement
CVE-2026-41686medium
2026-04-29

Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool

@anthropic-ai/sdk>= 0.79.0, < 0.91.10.91.1
CVE-2026-42353highCVSS: 8.2
2026-04-29

i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters

i18next-http-middleware< 3.9.33.9.3
CVE-2026-41680highCVSS: 7.5
2026-04-29

Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer

marked>= 18.0.0, <= 18.0.118.0.2
CVE-2026-42232criticalCVSS: 9.9
2026-04-29

n8n has XML Node Prototype Pollution that to RCE

n8n>= 2.18.0, < 2.18.12.18.1
n8n>= 2.17.0, < 2.17.42.17.4
n8n< 1.123.321.123.32
CVE-2026-42231criticalCVSS: 10
2026-04-29

n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE

n8n< 1.123.321.123.32
n8n>= 2.18.0, < 2.18.12.18.1
n8n>= 2.17.0, < 2.17.42.17.4
Advertisement
CVE-2026-42226highCVSS: 8.5
2026-04-29

n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay

n8n>= 2.17.0, < 2.17.52.17.5
n8n< 1.123.331.123.33
CVE-2026-42234highCVSS: 7.5
2026-04-29

n8n has a Python Task Runner Sandbox Escape Vulnerability

n8n< 1.123.321.123.32
n8n>= 2.18.0, < 2.18.12.18.1
n8n>= 2.17.0, < 2.17.42.17.4
CVE-2026-42228mediumCVSS: 5.4
2026-04-29

n8n Vulnerable to Hijacking of Unauthenticated Chat Execution

n8n< 1.123.321.123.32
n8n>= 2.18.0, < 2.18.12.18.1
n8n>= 2.0.0, < 2.17.42.17.4
CVE-2026-42229mediumCVSS: 6.8
2026-04-29

n8n has SQL Injection in SeaTable Node

n8n< 1.123.321.123.32
n8n>= 2.18.0, < 2.18.12.18.1
n8n>= 2.0.0, < 2.17.42.17.4
CVE-2026-42233mediumCVSS: 9.8
2026-04-29

n8n has SQL Injection in Oracle Database Node via Limit Field

n8n< 1.123.321.123.32
n8n>= 2.18.0, < 2.18.12.18.1
n8n>= 2.0.0, < 2.17.42.17.4
Advertisement
CVE-2026-42237mediumCVSS: 8.2
2026-04-29

n8n has SQL Injection in Snowflake and MySQL Nodes

n8n< 1.123.321.123.32
n8n>= 2.18.0, < 2.18.12.18.1
n8n>= 2.0.0, < 2.17.42.17.4
CVE-2026-41636high
2026-04-28

Apache Thrift Node.js bindings vulnerable to Uncontrolled Recursion

thrift< 0.23.00.23.0
GHSA-39h7-pwv7-rc3xmedium
2026-04-24

Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)

@excalidraw/excalidraw= 0.18.00.18.1
@excalidraw/mermaid-to-excalidraw>= 0.3.0, < 1.1.31.1.3
CVE-2026-41311highCVSS: 7.5
2026-04-24

liquidjs has a Denial of Service via circular block reference in layout

liquidjs< 10.25.710.25.7
CVE-2026-41305mediumCVSS: 6.1
2026-04-24

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

postcss< 8.5.108.5.10
Advertisement
GHSA-7vq9-42cc-33j4highCVSS: 8.8
2026-04-24

Duplicate Advisory: OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md

openclaw< 2026.3.312026.3.31
CVE-2026-41321lowCVSS: 2.2
2026-04-23

Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)

@astrojs/cloudflare< 13.1.1013.1.10
CVE-2026-41322mediumCVSS: 5.3
2026-04-23

Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed

@astrojs/node< 10.0.510.0.5
CVE-2026-42075highCVSS: 8.1
2026-04-22

Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write

@evomap/evolver< 1.69.31.69.3
CVE-2026-42076criticalCVSS: 9.8
2026-04-22

Evolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code Execution

@evomap/evolver< 1.69.31.69.3
Advertisement
CVE-2026-42077mediumCVSS: 5.2
2026-04-22

Evolver has Prototype Pollution via `Object.assign()` in its mailbox store operations

@evomap/evolver< 1.69.31.69.3
CVE-2026-41907mediumCVSS: 7.5
2026-04-22

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

uuid>= 12.0.0, < 12.0.112.0.1
uuid>= 13.0.0, < 13.0.113.0.1
uuid< 11.1.111.1.1
GHSA-p3h2-2j4p-p83ghigh
2026-04-22

MCPHub has Path Traversal via Malicious MCPB Manifest Name

@samanhappy/mcphub< 0.12.130.12.13
CVE-2026-41886highCVSS: 7.5
2026-04-22

locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext Editor

locize< 4.0.214.0.21
CVE-2026-41683highCVSS: 8.6
2026-04-22

i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header

i18next-http-middleware< 3.9.33.9.3
Advertisement
CVE-2026-41673high
2026-04-22

xmldom: Uncontrolled recursion in XML serialization leads to DoS

@xmldom/xmldom< 0.8.130.8.13
@xmldom/xmldom>= 0.9.0, < 0.9.100.9.10
xmldom<= 0.6.0
CVE-2026-41674high
2026-04-22

xmldom has XML injection through unvalidated DocumentType serialization

@xmldom/xmldom< 0.8.130.8.13
@xmldom/xmldom>= 0.9.0, < 0.9.100.9.10
xmldom<= 0.6.0
CVE-2026-41675high
2026-04-22

xmldom has XML node injection through unvalidated processing instruction serialization

@xmldom/xmldom< 0.8.130.8.13
@xmldom/xmldom>= 0.9.0, < 0.9.100.9.10
xmldom<= 0.6.0
CVE-2026-41672high
2026-04-22

xmldom has XML node injection through unvalidated comment serialization

@xmldom/xmldom< 0.8.130.8.13
@xmldom/xmldom>= 0.9.0, < 0.9.100.9.10
xmldom<= 0.6.0
CVE-2026-41640highCVSS: 7.5
2026-04-22

@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading

@nocobase/database< 2.0.392.0.39
Advertisement
CVE-2026-41641highCVSS: 7.2
2026-04-22

@nocobase/plugin-collection-sql: SQL Validation Bypass Through Missing `checkSQL` Call

@nocobase/plugin-collection-sql< 2.0.392.0.39
CVE-2026-41650mediumCVSS: 6.1
2026-04-22

fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters

fast-xml-parser< 5.7.05.7.0
CVE-2026-41691mediumCVSS: 6.5
2026-04-22

i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns

i18next-http-backend< 3.0.53.0.5
CVE-2026-41690highCVSS: 8.6
2026-04-22

i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters

i18next-http-middleware< 3.9.33.9.3
CVE-2026-41240medium
2026-04-22

DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)

dompurify< 3.4.03.4.0
Advertisement
CVE-2026-41239mediumCVSS: 6.8
2026-04-22

DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode

dompurify>= 1.0.10, < 3.4.03.4.0
CVE-2026-41067mediumCVSS: 6.1
2026-04-21

Astro: XSS in define:vars via incomplete </script> tag sanitization

astro< 6.1.66.1.6
CVE-2026-41264criticalCVSS: 9.8
2026-04-21

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-39320highCVSS: 7.5
2026-04-21

Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths

signalk-server< 2.25.02.25.0
CVE-2026-40155mediumCVSS: 5.4
2026-04-21

Auth0 Next.js SDK has Improper Proxy Cache Lookup

@auth0/nextjs-auth0>= 4.12.0, <= 4.17.04.18.0
Advertisement
CVE-2026-41265criticalCVSS: 9.8
2026-04-18

Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-41507criticalCVSS: 9.8
2026-04-17

Remote Code Execution (RCE) via String Literal Injection into math-codegen

math-codegen< 0.4.30.4.3
CVE-2026-42434highCVSS: 8.8
2026-04-17

OpenClaw: Sandboxed agents could escape exec routing via host=node override

openclaw>= 2026.4.5, < 2026.4.102026.4.10
CVE-2026-43567medium
2026-04-17

OpenClaw: screen_record outPath bypassed workspace-only filesystem guard

openclaw< 2026.4.102026.4.10
CVE-2026-41278highCVSS: 7.5
2026-04-17

Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs

flowise<= 3.0.133.1.0
Advertisement
CVE-2026-40931highCVSS: 8.4
2026-04-17

Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

compressing>= 2.0.0, <= 2.1.02.1.1
compressing<= 1.10.41.10.5
GHSA-fpw4-p57j-hqmqmediumCVSS: 5.4
2026-04-16

Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization

@paperclipai/ui< 2026.416.02026.416.0
GHSA-vr7g-88fq-vhq3criticalCVSS: 9.8
2026-04-16

Paperclip: OS Command Injection via Execution Workspace cleanupCommand

@paperclipai/server< 2026.416.02026.416.0
GHSA-xfqj-r5qw-8g4jhighCVSS: 8.3
2026-04-16

Paperclip: Unauthenticated Access to Multiple API Endpoints in Authenticated Mode

@paperclipai/server< 2026.416.02026.416.0
CVE-2026-41428criticalCVSS: 9.1
2026-04-16

Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints

@budibase/backend-core<= 3.35.3
Advertisement
CVE-2026-41423high
2026-04-16

Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server

@angular/platform-server>= 22.0.0-next.0, < 22.0.0-next.822.0.0-next.8
@angular/platform-server>= 21.0.0-next.0, < 21.2.921.2.9
@angular/platform-server>= 20.0.0-next.0, < 20.3.1920.3.19
@angular/platform-server>= 19.0.0-next.0, < 19.2.2119.2.21
@angular/platform-server<= 18.2.14
CVE-2026-6410mediumCVSS: 5.3
2026-04-16

@fastify/static vulnerable to path traversal in directory listing

@fastify/static>= 8.0.0, <= 9.1.09.1.1
CVE-2026-41274high
2026-04-16

Flowise: Cypher Injection in GraphCypherQAChain

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-41273highCVSS: 8.2
2026-04-16

Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise

flowise<= 3.0.133.1.0
CVE-2026-41272highCVSS: 7.1
2026-04-16

Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
Advertisement
CVE-2026-41270highCVSS: 7.1
2026-04-16

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-41269highCVSS: 7.1
2026-04-16

Flowise: File Upload Validation Bypass in createAttachment

flowise<= 3.0.133.1.0
CVE-2026-41268highCVSS: 7.7
2026-04-16

Flowise: Parameter Override Bypass Remote Command Execution

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-41266highCVSS: 7.5
2026-04-16

Flowise: Sensitive Data Leak in public-chatbotConfig

flowise<= 3.0.133.1.0
CVE-2026-41137criticalCVSS: 8.8
2026-04-16

Flowise: Code Injection in CSVAgent leads to Authenticated RCE

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
Advertisement
CVE-2026-41138highCVSS: 8.3
2026-04-16

Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-41248criticalCVSS: 9.1
2026-04-16

Official Clerk JavaScript SDKs: Middleware-based route protection bypass

@clerk/nextjs>= 5.0.0, < 5.7.65.7.6
@clerk/nuxt>= 1.1.0, < 1.13.281.13.28
@clerk/astro>= 0.0.1, < 1.5.71.5.7
@clerk/shared>= 2.20.17, < 2.22.12.22.1
@clerk/nextjs>= 6.0.0-snapshot.vb87a27f, < 6.39.26.39.2
@clerk/nextjs>= 7.0.0, < 7.2.17.2.1
@clerk/nuxt>= 2.0.0, < 2.2.22.2.2
@clerk/astro>= 2.0.0-snapshot.v20241206174604, <= 2.17.92.17.10
@clerk/astro>= 3.0.0, < 3.0.153.0.15
@clerk/shared>= 3.0.0-canary.v20250225091530, < 3.47.43.47.4
@clerk/shared>= 4.0.0, < 4.8.14.8.1
GHSA-9hrv-gvrv-6gf2medium
2026-04-16

Flowise Execute Flow function has an SSRF vulnerability

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-43995medium
2026-04-16

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)

flowise<= 3.0.133.1.0
flowise-components<= 3.0.133.1.0
CVE-2026-41180highCVSS: 7.5
2026-04-16

PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart

psitransfer< 2.4.32.4.3
Advertisement
CVE-2026-41244mediumCVSS: 4.7
2026-04-16

Mojic: Observable Timing Discrepancy in HMAC Verification

mojic<= 2.1.32.1.4
CVE-2026-41213mediumCVSS: 5.9
2026-04-16

@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codes

@node-oauth/oauth2-server<= 5.2.15.3.0
CVE-2026-33889mediumCVSS: 5.4
2026-04-16

ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context

apostrophe< 4.29.04.29.0
CVE-2026-33808criticalCVSS: 9.1
2026-04-16

@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)

@fastify/express<= 4.0.44.0.5
CVE-2026-33807criticalCVSS: 9.1
2026-04-16

@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes

@fastify/express<= 4.0.44.0.5
Advertisement
CVE-2026-41211highCVSS: 10
2026-04-16

Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME

vite-plus<= 0.1.160.1.17
CVE-2026-40346mediumCVSS: 6.5
2026-04-15

NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins

@nocobase/plugin-workflow-request< 2.0.372.0.37
GHSA-26wg-9xf2-q495highCVSS: 8.1
2026-04-14

Novu has a XSS sanitization bypass

novu/api< 3.15.03.15.0
GHSA-r4q5-vmmm-2653medium
2026-04-14

follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets

follow-redirects<= 1.15.111.16.0
CVE-2026-28291highCVSS: 8.1
2026-04-13

simple-git Affected by Command Execution via Option-Parsing Bypass

simple-git< 3.32.03.32.0
Advertisement
GHSA-x7mm-9vvv-64w8low
2026-04-10

unhead: Streaming SSR `streamKey` injected into inline script without identifier validation

unhead>= 3.0.0-beta.5, <= 3.0.03.0.1
CVE-2026-41679criticalCVSS: 10
2026-04-10

paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass

paperclipai< 2026.410.02026.410.0
@paperclipai/server< 2026.410.02026.410.0
CVE-2026-40299medium
2026-04-10

next-intl has an open redirect vulnerability

next-intl< 4.9.14.9.1
CVE-2026-40190mediumCVSS: 5.6
2026-04-10

LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`

langsmith<= 0.5.170.5.18
CVE-2026-40163highCVSS: 8.2
2026-04-10

Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read

@saltcorn/server< 1.4.51.4.5
@saltcorn/server>= 1.5.0-beta.0, < 1.5.51.5.5
@saltcorn/server>= 1.6.0-alpha.0, < 1.6.0-beta.41.6.0-beta.4
Advertisement
CVE-2026-40073high
2026-04-10

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

@sveltejs/kit<= 2.57.02.57.1
GHSA-v457-wxvj-p9w9highCVSS: 7.5
2026-04-10

@vitejs/plugin-rsc has a Denial of Service with React Server Components

@vitejs/plugin-rsc<= 0.5.220.5.23
GHSA-q4gf-8mx6-v5v3highCVSS: 7.5
2026-04-10

Next.js has a Denial of Service with Server Components

next>= 13.0.0, < 15.5.1515.5.15
next>= 16.0.0-beta.0, < 16.2.316.2.3
CVE-2026-23869highCVSS: 7.5
2026-04-10

React Server Components have a Denial of Service Vulnerability

react-server-dom-parcel>= 19.0.0, < 19.0.519.0.5
react-server-dom-parcel>= 19.1.0, < 19.1.619.1.6
react-server-dom-parcel>= 19.2.0, < 19.2.519.2.5
react-server-dom-turbopack>= 19.0.0, < 19.0.519.0.5
react-server-dom-turbopack>= 19.1.0, < 19.1.619.1.6
react-server-dom-turbopack>= 19.2.0, < 19.2.519.2.5
react-server-dom-webpack>= 19.0.0, < 19.0.519.0.5
react-server-dom-webpack>= 19.1.0, < 19.1.619.1.6
react-server-dom-webpack>= 19.2.0, < 19.2.519.2.5
GHSA-r3v5-2grc-429hhighCVSS: 8.8
2026-04-10

Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

openclaw< 2026.3.222026.3.22
Advertisement
CVE-2026-39315mediumCVSS: 6.1
2026-04-09

Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

unhead< 2.1.132.1.13
CVE-2026-42426mediumCVSS: 8.8
2026-04-09

OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval

openclaw< 2026.4.82026.4.8
CVE-2026-42432highCVSS: 7.8
2026-04-09

OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement

openclaw< 2026.4.82026.4.8
CVE-2026-42431mediumCVSS: 8.1
2026-04-09

OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard

openclaw< 2026.4.82026.4.8
CVE-2026-42423mediumCVSS: 7.5
2026-04-09

OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts

openclaw< 2026.4.82026.4.8
Advertisement
CVE-2026-35041mediumCVSS: 4.2
2026-04-09

fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verification

fast-jwt>= 5.0.0, <= 6.2.06.2.1
CVE-2026-35040mediumCVSS: 5.3
2026-04-09

fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)

fast-jwt< 6.2.16.2.1
GHSA-5478-66c3-rhxrhigh
2026-04-08

Pretext: Algorithmic Complexity (DoS) in the text analysis phase

@chenglou/pretext<= 0.0.40.0.5
CVE-2026-39983highCVSS: 8.6
2026-04-08

basic-ftp has FTP Command Injection via CRLF

basic-ftp= 5.2.05.2.1
CVE-2026-39865mediumCVSS: 5.9
2026-04-08

Axios HTTP/2 Session Cleanup State Corruption Vulnerability

axios>= 1.13.0, < 1.13.21.13.2
Advertisement
CVE-2026-39859medium
2026-04-08

LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read

liquidjs<= 10.25.410.25.5
CVE-2026-34166lowCVSS: 3.7
2026-04-08

LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter

liquidjs<= 10.25.210.25.3
CVE-2026-39409mediumCVSS: 5.3
2026-04-08

Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

hono< 4.12.124.12.12
GHSA-26pp-8wgv-hjvmmediumCVSS: 5.3
2026-04-08

Hono missing validation of cookie name on write path in setCookie()

hono< 4.12.124.12.12
CVE-2026-39406mediumCVSS: 5.3
2026-04-08

@hono/node-server: Middleware bypass via repeated slashes in serveStatic

@hono/node-server< 1.19.131.19.13
Advertisement
CVE-2026-39397criticalCVSS: 9.4
2026-04-08

@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections

@delmaredigital/payload-puck< 0.6.230.6.23
GHSA-w6wx-jq6j-6mcjmedium
2026-04-07

OpenClaw: pnpm dlx approvals did not bind local script operands

openclaw<= 2026.4.12026.4.2
CVE-2026-41398medium
2026-04-07

OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch

openclaw<= 2026.4.12026.4.2
CVE-2026-34148highCVSS: 7.5
2026-04-07

Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution

@fedify/fedify< 1.9.61.9.6
@fedify/vocab-runtime< 2.0.82.0.8
@fedify/vocab-runtime= 2.1.02.1.1
@fedify/fedify>= 1.10.0, < 1.10.51.10.5
@fedify/fedify>= 2.0.0, < 2.0.82.0.8
@fedify/fedify= 2.1.02.1.1
CVE-2026-35214highCVSS: 8.7
2026-04-04

Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write

@budibase/server< 3.33.43.33.4
Advertisement
CVE-2026-35213highCVSS: 7.5
2026-04-04

@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing

@hapi/content<= 6.0.06.0.1
CVE-2026-34217medium
2026-04-03

SandboxJS: Sandbox Escape via Prop Object Leak in New Handler

@nyariv/sandboxjs<= 0.8.350.8.36
CVE-2026-34211medium
2026-04-03

SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser

@nyariv/sandboxjs<= 0.8.350.8.36
CVE-2026-34208criticalCVSS: 10
2026-04-03

SandboxJS: Sandbox integrity escape

@nyariv/sandboxjs< 0.8.360.8.36
CVE-2026-35039criticalCVSS: 9.1
2026-04-03

fast-jwt: Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)

fast-jwt>= 0.0.1, < 6.2.06.2.0
Advertisement
CVE-2026-35038low
2026-04-03

Signal K Server: Arbitrary Prototype Read via `from` Field Bypass

signalk-server< 2.24.02.24.0
GHSA-h5hg-h7rr-gpf3high
2026-04-03

OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection

openclaw<= 2026.3.13-12026.3.22
CVE-2026-41378highCVSS: 8.8
2026-04-03

OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch

openclaw<= 2026.3.282026.3.31
CVE-2026-41352highCVSS: 8.8
2026-04-03

OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md

openclaw<= 2026.3.282026.3.31
CVE-2026-34780highCVSS: 8.3
2026-04-03

Electron: Context Isolation bypass via contextBridge VideoFrame transfer

electron>= 39.0.0-alpha.1, < 39.8.039.8.0
electron>= 40.0.0-alpha.1, < 40.7.040.7.0
electron>= 41.0.0-alpha.1, < 41.0.0-beta.841.0.0-beta.8
Advertisement
CVE-2026-34775mediumCVSS: 6.8
2026-04-03

Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

electron< 38.8.638.8.6
electron>= 39.0.0-alpha.1, < 39.8.439.8.4
electron>= 40.0.0-alpha.1, < 40.8.440.8.4
electron>= 41.0.0-alpha.1, < 41.0.041.0.0
CVE-2026-34950criticalCVSS: 9.1
2026-04-02

fast-jwt: Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key

fast-jwt<= 6.1.06.2.0
CVE-2026-34825highCVSS: 6.5
2026-04-01

NocoBase Has SQL Injection via template variable substitution in workflow SQL node

@nocobase/plugin-workflow-sql<= 2.0.292.0.30
CVE-2026-34725highCVSS: 8.2
2026-04-01

dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration

dbgate-web>= 7.0.0, < 7.1.57.1.5
GHSA-x3ff-w252-2g7jmediumCVSS: 5.3
2026-04-01

StableLib Ed25519 Signature Malleability via Missing S < L Check

@stablelib/ed25519<= 2.0.2
Advertisement
CVE-2026-34748highCVSS: 8.7
2026-04-01

@payloadcms/next has Stored XSS in Admin Panel

@payloadcms/next< 3.78.03.78.0
CVE-2026-2265mediumCVSS: 6.5
2026-04-01

Replicator deserializes untrusted user input

replicator<= 1.0.5
CVE-2026-34603highCVSS: 7.1
2026-04-01

@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions

@tinacms/graphql<= 2.2.12.2.2
CVE-2026-34601highCVSS: 7.5
2026-04-01

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

xmldom<= 0.6.0
@xmldom/xmldom< 0.8.120.8.12
@xmldom/xmldom>= 0.9.0, < 0.9.90.9.9
CVE-2026-33577mediumCVSS: 9.8
2026-04-01

OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes

openclaw<= 2026.3.242026.3.28
Advertisement
CVE-2026-41387highCVSS: 9.6
2026-03-31

OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides

openclaw< 2026.3.222026.3.22
CVE-2026-34573high
2026-03-31

parse-server has GraphQL complexity validator exponential fragment traversal DoS

parse-server>= 9.0.0, < 9.7.0-alpha.129.7.0-alpha.12
parse-server< 8.6.688.6.68
CVE-2026-34532critical
2026-03-31

parse-server has cloud function validator bypass via prototype chain traversal

parse-server>= 9.0.0, < 9.7.0-alpha.119.7.0-alpha.11
parse-server< 8.6.678.6.67
GHSA-w8rf-7qf8-65wwhighCVSS: 7.1
2026-03-31

Duplicate Advisory: OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv

openclaw< 2026.3.112026.3.11
CVE-2026-35653highCVSS: 8.1
2026-03-30

OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface

openclaw< 2026.3.242026.3.24
Advertisement
CVE-2026-35665mediumCVSS: 5.3
2026-03-30

OpenClaw has incomplete Fix for CVE-2026-32011: Feishu Webhook Pre-Auth Body Parsing DoS (Slow-Body / Slowloris Variant)

openclaw< 2026.3.242026.3.24
CVE-2026-34156criticalCVSS: 9.9
2026-03-30

NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node

@nocobase/plugin-workflow-javascript<= 2.0.272.0.28
GHSA-wmgj-hrx3-23gjhighCVSS: 7.3
2026-03-29

Duplicate Advisory: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity

openclaw< 2026.3.112026.3.11
CVE-2026-34226highCVSS: 7.5
2026-03-29

Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies

happy-dom< 20.8.920.8.9
CVE-2026-35628mediumCVSS: 4.8
2026-03-27

OpenClaw: Telegram Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Secret

openclaw<= 2026.3.24
Advertisement
GHSA-fqw4-mph7-2vr8critical
2026-03-27

OpenClaw: Silent privilege escalation via gateway shared-auth reconnect

openclaw<= 2026.3.24
GHSA-h8r8-wccr-v5f2medium
2026-03-27

DOMPurify is vulnerable to mutation-XSS via Re-Contextualization

dompurify< 3.3.23.3.2
CVE-2026-33989highCVSS: 8.1
2026-03-27

@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools

@mobilenext/mobile-mcp< 0.0.490.0.49
CVE-2026-33941highCVSS: 8.2
2026-03-27

Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

handlebars>= 4.0.0, <= 4.7.84.7.9
CVE-2026-33939highCVSS: 7.5
2026-03-27

Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation

handlebars>= 4.0.0, <= 4.7.84.7.9
Advertisement
CVE-2026-33937criticalCVSS: 9.8
2026-03-27

Handlebars.js has JavaScript Injection via AST Type Confusion

handlebars>= 4.0.0, <= 4.7.84.7.9
GHSA-3c7f-5hgj-h279mediumCVSS: 5.4
2026-03-27

n8n has XSS in Chat Trigger Node through Custom CSS

n8n< 1.123.271.123.27
n8n= 2.14.02.14.1
n8n>= 2.0.0-rc.0, < 2.13.32.13.3
GHSA-w673-8fjw-457cmediumCVSS: 4.1
2026-03-27

n8n: Authenticated XSS and Open Redirect via Form Node

n8n>= 2.11.0, < 2.12.02.12.0
n8n>= 2.0.0-rc.0, < 2.10.42.10.4
n8n< 1.123.241.123.24
GHSA-q4fm-pjq6-m63gmediumCVSS: 5.4
2026-03-27

n8n has a Stored XSS Vulnerability in its Form Trigger

n8n>= 2.0.0-rc.0, < 2.11.22.11.2
n8n< 1.123.251.123.25
CVE-2026-33994medium
2026-03-27

Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521

locutus>= 2.0.39, < 3.0.253.0.25
Advertisement
GHSA-vj2p-7pgw-g2wfhighCVSS: 7.5
2026-03-27

Postiz App has a High-Severity SSRF Vulnerability via Next.js

postiz<= 2.0.12
GHSA-c7w3-x93f-qmm8low
2026-03-26

Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter

nodemailer< 8.0.48.0.4
CVE-2026-33943highCVSS: 8.8
2026-03-26

Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code

happy-dom>= 15.10.0, <= 20.8.720.8.8
CVE-2026-33896highCVSS: 7.4
2026-03-26

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

node-forge<= 1.3.31.4.0
CVE-2026-33895highCVSS: 7.5
2026-03-26

Forge has signature forgery in Ed25519 due to missing S > L check

node-forge< 1.4.01.4.0
Advertisement
CVE-2026-33894highCVSS: 7.5
2026-03-26

Forge has signature forgery in RSA-PKCS due to ASN.1 extra field

node-forge< 1.4.01.4.0
CVE-2026-33891highCVSS: 7.5
2026-03-26

Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

node-forge< 1.4.01.4.0
GHSA-9q82-xgwf-vj6hmedium
2026-03-26

Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention

@apollo/server< 5.5.05.5.0
apollo-server-core<= 3.13.0
CVE-2026-35648lowCVSS: 3.7
2026-03-26

OpenClaw may have stale policy enforcement for queued node actions

openclaw< 2026.3.222026.3.22
CVE-2026-35650highCVSS: 7.5
2026-03-26

OpenClaw has Inconsistent Host Exec Environment Override Sanitization

openclaw< 2026.3.222026.3.22
Advertisement
CVE-2026-35643highCVSS: 8.8
2026-03-26

OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface

openclaw< 2026.3.222026.3.22
CVE-2026-35634medium
2026-03-26

OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication

openclaw< 2026.3.232026.3.23
CVE-2026-33864critical
2026-03-26

Convict has Prototype Pollution via startsWith() function

convict<= 6.2.46.2.5
CVE-2026-33863critical
2026-03-26

Convict has prototype pollution via load(), loadFile(), and schema initialization

convict<= 6.2.46.2.5
CVE-2026-33769lowCVSS: 5.3
2026-03-26

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

astro>= 2.10.10, < 5.18.15.18.1
Advertisement
CVE-2026-33768mediumCVSS: 6.5
2026-03-26

Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

@astrojs/vercel< 10.0.210.0.2
CVE-2026-33751mediumCVSS: 4.8
2026-03-26

n8n Vulnerable to LDAP Filter Injection in LDAP Node

n8n< 1.123.271.123.27
n8n= 2.14.02.14.1
n8n>= 2.0.0-rc.0, < 2.13.32.13.3
CVE-2026-33732mediumCVSS: 4.8
2026-03-26

srvx is vulnerable to middleware bypass via absolute URI in request line

srvx< 0.11.130.11.13
CVE-2026-33713highCVSS: 9.9
2026-03-26

n8n has SQL Injection in Data Table Node via orderByColumn Expression

n8n< 1.123.261.123.26
n8n= 2.14.02.14.1
n8n>= 2.0.0-rc.0, < 2.13.32.13.3
CVE-2026-33696criticalCVSS: 9.9
2026-03-26

n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE

n8n= 2.14.02.14.1
n8n>= 2.0.0-rc.0, < 2.13.32.13.3
n8n< 1.123.271.123.27
Advertisement
CVE-2026-33671highCVSS: 7.5
2026-03-25

Picomatch has a ReDoS vulnerability via extglob quantifiers

picomatch>= 4.0.0, < 4.0.44.0.4
picomatch>= 3.0.0, < 3.0.23.0.2
picomatch< 2.3.22.3.2
CVE-2026-33660criticalCVSS: 9.9
2026-03-25

n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode

n8n= 2.14.02.14.1
n8n>= 2.0.0-rc.0, < 2.13.32.13.3
n8n< 1.123.271.123.27
CVE-2026-33532mediumCVSS: 4.3
2026-03-25

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

yaml>= 2.0.0, < 2.8.32.8.3
yaml>= 1.0.0, < 1.10.31.10.3
CVE-2026-26832criticalCVSS: 9.8
2026-03-25

node-tesseract-ocr is vulnerable to OS Command Injection through unsanitized recognize() function parameter

node-tesseract-ocr<= 2.2.1
CVE-2026-33287highCVSS: 7.5
2026-03-25

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

liquidjs<= 10.24.0
Advertisement
CVE-2026-33285highCVSS: 7.5
2026-03-25

LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash

liquidjs<= 10.24.0
GHSA-3mjm-x6gw-2x42medium
2026-03-25

@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers

@grackle-ai/server<= 0.70.30.70.4
CVE-2026-27496highCVSS: 6.5
2026-03-25

n8n has In-Process Memory Disclosure in its Task Runner

n8n< 1.123.221.123.22
n8n>= 2.10.0, < 2.10.12.10.1
n8n>= 2.0.0-rc.0, < 2.9.32.9.3
CVE-2026-29772mediumCVSS: 5.9
2026-03-24

Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

@astrojs/node< 10.0.010.0.0
GHSA-g3qj-j598-cxmqhighCVSS: 7.5
2026-03-24

fido2-lib is vulnerable to DoS via cbor-extract heap buffer over-read in CBOR attestation parsing

fido2-lib<= 3.5.73.5.8
Advertisement
GHSA-fp4x-ggrf-wmc6mediumCVSS: 5.4
2026-03-23

H3 has an Open Redirect via Protocol-Relative Path in redirectBack() Referer Validation

h3= 2.0.1-rc.172.0.1-rc.18
GHSA-q5pr-72pq-83v3mediumCVSS: 5.3
2026-03-23

H3: Unbounded Chunked Cookie Count in Session Cleanup Loop may Lead to Denial of Service

h3>= 2.0.0-beta.4, < 2.0.1-rc.182.0.1-rc.18
GHSA-cjq8-m7wj-xmq9lowCVSS: 2.6
2026-03-21

Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

openclaw< 2026.2.26
GHSA-xh9j-mpc9-2m9pmediumCVSS: 5.9
2026-03-21

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

openclaw<= 2026.2.24
GHSA-3p2x-hjxj-c7rvmediumCVSS: 6.5
2026-03-21

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

openclaw<= 2026.2.24
Advertisement
CVE-2026-33490lowCVSS: 3.7
2026-03-20

h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes

h3>= 2.0.1-alpha.0, <= 2.0.1-rc.162.0.1-rc.17
CVE-2026-33468highCVSS: 8.1
2026-03-20

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

kysely<= 0.28.130.28.14
CVE-2026-33442highCVSS: 8.1
2026-03-20

Kysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.

kysely>= 0.28.12, <= 0.28.130.28.14
GHSA-pgx6-7jcq-2qffmediumCVSS: 6.8
2026-03-20

PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled

@pdfme/common<= 5.5.95.5.10
GHSA-vrqm-gvq7-rrwhmediumCVSS: 6.5
2026-03-20

PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS

@pdfme/pdf-lib<= 5.5.95.5.10
Advertisement
CVE-2026-33418highCVSS: 7.5
2026-03-20

SVG Dimension Capping Bypass via XML Comment Injection in @dicebear/converter ensureSize()

@dicebear/converter<= 9.4.19.4.2
CVE-2026-32887highCVSS: 7.4
2026-03-20

Effect `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC

effect< 3.20.03.20.0
CVE-2026-33397mediumCVSS: 6.1
2026-03-19

Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR

@angular/ssr>= 22.0.0-next.0, < 22.0.0-next.222.0.0-next.2
@angular/ssr>= 21.0.0-next.0, < 21.2.321.2.3
@angular/ssr>= 20.0.0-next.0, < 20.3.2120.3.21
GHSA-wvr4-3wq4-gpc5criticalCVSS: 9.8
2026-03-19

MCP Connect has unauthenticated remote OS command execution via /bridge endpoint

mcp-bridge<= 2.0.0
GHSA-g87j-gm7p-6vw2mediumCVSS: 6.7
2026-03-19

Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

openclaw= 2026.3.1
Advertisement
GHSA-5326-6f73-m96wmediumCVSS: 4.8
2026-03-19

Duplicate Advisory: OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains

openclaw< 2026.2.22
GHSA-pfv5-rpcw-x34xhighCVSS: 6.4
2026-03-19

Duplicate Advisory: OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

openclaw< 2026.2.22
CVE-2026-33226highCVSS: 8.7
2026-03-18

Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview

budibase<= 3.30.6
CVE-2026-32731criticalCVSS: 9.9
2026-03-18

ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

@apostrophecms/import-export<= 3.5.23.5.3
CVE-2026-32730highCVSS: 8.1
2026-03-18

ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

apostrophe<= 4.27.14.28.0
Advertisement
CVE-2026-33143high
2026-03-18

OneUptime WhatsApp Webhook Missing Signature Verification

oneuptime< 10.0.3410.0.34
GHSA-wr4h-v87w-p3r7mediumCVSS: 5.9
2026-03-18

h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read

h3>= 2.0.0, <= 2.0.1-rc.142.0.1-rc.15
h3< 1.15.61.15.6
CVE-2026-33131highCVSS: 7.4
2026-03-18

h3 has a middleware bypass with one gadget

h3>= 2.0.0-0, < 2.0.1-rc.152.0.1-rc.15
CVE-2026-33128highCVSS: 7.5
2026-03-18

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

h3>= 2.0.0, <= 2.0.1-rc.142.0.1-rc.15
h3< 1.15.61.15.6
CVE-2026-32763highCVSS: 8.2
2026-03-18

SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.

kysely>= 0.26.0, <= 0.28.110.28.12
Advertisement
CVE-2026-29057medium
2026-03-17

Next.js: HTTP request smuggling in rewrites

next>= 16.0.0-beta.0, < 16.1.716.1.7
next>= 9.5.0, < 15.5.1315.5.13
CVE-2026-27980medium
2026-03-17

Next.js: Unbounded next/image disk cache growth can exhaust storage

next>= 16.0.0-beta.0, < 16.1.716.1.7
next>= 10.0.0, < 15.5.1415.5.14
CVE-2026-27979medium
2026-03-17

Next.js: Unbounded postponed resume buffering can lead to DoS

next>= 16.0.1, < 16.1.716.1.7
CVE-2026-27978medium
2026-03-17

Next.js: null origin can bypass Server Actions CSRF checks

next>= 16.0.1, < 16.1.716.1.7
CVE-2026-27977low
2026-03-17

Next.js: null origin can bypass dev HMR websocket CSRF checks

next>= 16.0.1, < 16.1.716.1.7
Advertisement
CVE-2026-32723medium
2026-03-16

SandboxJS has an execution-quota bypass (cross-sandbox currentTicks race) in SandboxJS timers

@nyariv/sandboxjs<= 0.8.340.8.35
CVE-2026-32635highCVSS: 9
2026-03-13

Angular vulnerable to XSS in i18n attribute bindings

@angular/core>= 22.0.0-next.0, < 22.0.0-next.322.0.0-next.3
@angular/core>= 21.0.0-next.0, < 21.2.421.2.4
@angular/core>= 20.0.0-next.0.0.0, < 20.3.1820.3.18
@angular/compiler>= 22.0.0-next.0, < 22.0.0-next.322.0.0-next.3
@angular/compiler>= 21.0.0-next.0, < 21.2.421.2.4
@angular/compiler>= 20.0.0-next.0.0.0, < 20.3.1820.3.18
@angular/core>= 19.0.0-next.0, < 19.2.2019.2.20
@angular/core>= 17.0.0-next.0, <= 18.2.14
@angular/compiler>= 19.0.0-next.0, < 19.2.2019.2.20
@angular/compiler>= 17.0.0-next.0, <= 18.2.14
CVE-2026-32630mediumCVSS: 5.3
2026-03-13

file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry

file-type>= 20.0.0, <= 21.3.121.3.2
CVE-2026-32621criticalCVSS: 9.9
2026-03-13

Apollo Federation vulnerable to prototype pollution via incomplete key sanitization

@apollo/federation-internals< 2.9.62.9.6
@apollo/federation-internals>= 2.10.0, < 2.10.52.10.5
@apollo/federation-internals>= 2.11.0, < 2.11.62.11.6
@apollo/federation-internals>= 2.12.0, < 2.12.32.12.3
@apollo/federation-internals>= 2.13.0, < 2.13.22.13.2
@apollo/gateway< 2.9.62.9.6
@apollo/gateway>= 2.10.0, < 2.10.52.10.5
@apollo/gateway>= 2.11.0, < 2.11.62.11.6
@apollo/gateway>= 2.12.0, < 2.12.32.12.3
@apollo/gateway>= 2.13.0, < 2.13.22.13.2
@apollo/query-planner< 2.9.62.9.6
@apollo/query-planner>= 2.10.0, < 2.10.52.10.5
@apollo/query-planner>= 2.11.0, < 2.11.62.11.6
@apollo/query-planner>= 2.12.0, < 2.12.32.12.3
@apollo/query-planner>= 2.13.0, < 2.13.22.13.2
CVE-2026-1526highCVSS: 7.5
2026-03-13

Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

undici< 6.24.06.24.0
undici>= 7.0.0, < 7.24.07.24.0
Advertisement
CVE-2026-2229highCVSS: 7.5
2026-03-13

Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation

undici< 6.24.06.24.0
undici>= 7.0.0, < 7.24.07.24.0
CVE-2026-2581mediumCVSS: 5.9
2026-03-13

Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS

undici>= 7.17.0, < 7.24.07.24.0
CVE-2026-32304criticalCVSS: 9.8
2026-03-13

Locutus vulnerable to RCE via unsanitized input in create_function()

locutus<= 3.0.133.0.14
CVE-2026-32978highCVSS: 8
2026-03-13

OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity

openclaw< 2026.3.112026.3.11
CVE-2026-32971highCVSS: 7.1
2026-03-13

OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv

openclaw< 2026.3.112026.3.11
Advertisement
CVE-2026-32979highCVSS: 7.3
2026-03-13

OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity

openclaw< 2026.3.112026.3.11
GHSA-4jpw-hj22-2xmccriticalCVSS: 9.9
2026-03-13

OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE

openclaw< 2026.3.112026.3.11
CVE-2026-32141highCVSS: 7.5
2026-03-13

flatted vulnerable to unbounded recursion DoS in parse() revive phase

flatted< 3.4.03.4.0
CVE-2026-31882highCVSS: 7.5
2026-03-13

Dagu: SSE Authentication Bypass in Basic Auth Mode

dagu< 2.2.42.2.4
CVE-2026-29066mediumCVSS: 6.2
2026-03-12

TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction

@tinacms/cli< 2.1.82.1.8
Advertisement
CVE-2026-28792criticalCVSS: 9.6
2026-03-12

TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

@tinacms/cli< 2.1.82.1.8
CVE-2026-28791highCVSS: 7.4
2026-03-12

Tina: Path Traversal in Media Upload Handle

tinacms< 2.1.72.1.7
CVE-2026-24125mediumCVSS: 6.3
2026-03-12

@tinacms/graphql has a Path Traversal issue

@tinacms/graphql<= 2.1.12.1.2
GHSA-qcc4-p59m-p54mhighCVSS: 7
2026-03-12

OpenClaw: Sandbox dangling-symlink alias handling could bypass workspace-only write boundary

openclaw<= 2026.2.252026.2.26
CVE-2026-32055highCVSS: 7.6
2026-03-12

OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

openclaw<= 2026.2.252026.2.26
Advertisement
GHSA-gp3q-wpq4-5c5hhighCVSS: 7.1
2026-03-12

OpenClaw: LINE group allowlist scope mismatch with DM pairing-store entries

openclaw<= 2026.2.252026.2.26
CVE-2026-31873low
2026-03-12

Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity

unhead<= 2.1.102.1.11
CVE-2026-31860medium
2026-03-12

Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check

unhead<= 2.1.102.1.11
CVE-2026-31988mediumCVSS: 5.3
2026-03-12

yauzl contains an off-by-one error

yauzl= 3.2.03.2.1
CVE-2026-32094medium
2026-03-11

Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash

shescape< 2.1.102.1.10
Advertisement
CVE-2026-31975high
2026-03-11

@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection

@siteboon/claude-code-ui<= 1.24.01.25.0
CVE-2026-31862criticalCVSS: 9.1
2026-03-11

@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters

@siteboon/claudecodeui<= 1.23.01.24.0
CVE-2026-31829highCVSS: 7.1
2026-03-11

Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access

flowise<= 3.0.123.0.13
flowise-components<= 3.0.123.0.13
CVE-2026-30973mediumCVSS: 6.5
2026-03-11

@appium/support has a Zip Slip arbitrary file write in its ZIP extraction

@appium/support<= 7.0.57.0.6
CVE-2026-31861high
2026-03-10

@siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes

@siteboon/claude-code-ui<= 1.23.01.24.0
Advertisement
CVE-2026-31808mediumCVSS: 5.3
2026-03-10

file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header

file-type>= 13.0.0, < 21.3.121.3.1
CVE-2026-31802high
2026-03-10

node-tar Symlink Path Traversal via Drive-Relative Linkpath

tar<= 7.5.107.5.11
CVE-2026-28292criticalCVSS: 9.8
2026-03-10

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

simple-git>= 3.15.0, < 3.32.33.32.3
CVE-2026-30959medium
2026-03-10

OneUptime has WhatsApp Resend Verification Authorization Bypass

@oneuptime/common< 10.0.2110.0.21
CVE-2026-30957criticalCVSS: 9.9
2026-03-10

OneUptime has Synthetic Monitor RCE via exposed Playwright browser object

@oneuptime/common< 10.0.2110.0.21
Advertisement
CVE-2026-30952high
2026-03-10

liquidjs has a path traversal fallback vulnerability

liquidjs< 10.25.010.25.0
CVE-2026-30925high
2026-03-10

Parse Server has Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery

parse-server>= 9.0.0-alpha.1, < 9.5.0-alpha.149.5.0-alpha.14
parse-server< 8.6.118.6.11
CVE-2026-30921criticalCVSS: 9.9
2026-03-07

OneUptime: Synthetic Monitor RCE via exposed Playwright browser object

@oneuptime/common< 10.0.2010.0.20
CVE-2026-30916low
2026-03-07

Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains

shescape<= 2.1.82.1.9
CVE-2026-30887criticalCVSS: 9.9
2026-03-07

OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE

@oneuptime/common< 10.0.1810.0.18
Advertisement
CVE-2026-30822highCVSS: 7.7
2026-03-06

Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint

flowise<= 3.0.123.0.13
CVE-2026-30821high
2026-03-06

Flowise has Arbitrary File Upload via MIME Spoofing

flowise<= 3.0.123.0.13
CVE-2026-30820high
2026-03-06

Flowise has Authorization Bypass via Spoofed x-request-from Header

flowise<= 3.0.123.0.13
CVE-2026-30827highCVSS: 7.5
2026-03-06

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

express-rate-limit>= 8.2.0, < 8.2.28.2.2
express-rate-limit= 8.1.08.1.1
express-rate-limit>= 8.0.0, < 8.0.28.0.2
CVE-2024-43035mediumCVSS: 5.8
2026-03-05

Fonoster is vulnerable to directory traversal

@fonoster/voice>= 0.5.5, < 0.6.10.6.1
Advertisement
CVE-2026-3125high
2026-03-05

opennextjs-cloudflare has SSRF vulnerability via /cdn-cgi/ path normalization bypass

@opennextjs/cloudflare< 1.17.11.17.1
CVE-2026-29786high
2026-03-05

tar has Hardlink Path Traversal via Drive-Relative Linkpath

tar<= 7.5.97.5.10
CVE-2026-29186highCVSS: 7.7
2026-03-05

TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution

@backstage/plugin-techdocs-node<= 1.14.21.14.3
CVE-2026-29074highCVSS: 7.5
2026-03-04

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

svgo>= 2.1.0, < 2.8.12.8.1
svgo>= 3.0.0, < 3.3.33.3.3
svgo= 4.0.04.0.1
CVE-2026-29063highCVSS: 9.8
2026-03-04

Immutable is vulnerable to Prototype Pollution

immutable>= 5.0.0, < 5.1.55.1.5
immutable>= 4.0.0-rc.1, < 4.3.84.3.8
immutable< 3.8.33.8.3
Advertisement
CVE-2026-29091highCVSS: 8.1
2026-03-04

locutus call_user_func_array vulnerable to Remote Code Execution (RCE) due to Code Injection

locutus<= 2.0.393.0.0
CVE-2026-29087highCVSS: 7.5
2026-03-04

@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware

@hono/node-server< 1.19.101.19.10
GHSA-jjgj-cpp9-cvpvmedium
2026-03-04

OpenClaw Vulnerable to Local File Exfiltration via MCP Tool Result MEDIA: Directive Injection

openclaw< 2026.2.212026.2.21
GHSA-f6h3-846h-2r8wmedium
2026-03-04

OpenClaw's elevated allowFrom accepted broader identity signals than specified within sender-scoped authorization

openclaw< 2026.2.222026.2.22
CVE-2026-32067lowCVSS: 3.7
2026-03-04

OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access

openclaw<= 2026.2.252026.2.26
Advertisement
CVE-2026-32005highCVSS: 6.8
2026-03-04

OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows

openclaw<= 2026.2.242026.2.25
CVE-2026-32001mediumCVSS: 5.4
2026-03-03

OpenClaw's Node role device-identity bypass allows unauthorized node.event injection

openclaw< 2026.2.222026.2.22
CVE-2026-31995medium
2026-03-03

OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path

openclaw>= 2026.1.21, <= 2026.2.172026.2.19
GHSA-cjv3-m589-v3rxmedium
2026-03-03

OpenClaw has Canvas route hardening for mixed-trust deployments

openclaw< 2026.2.212026.2.21
CVE-2026-27566high
2026-03-03

OpenClaw's exec allowlist wrapper analysis did not unwrap env/shell dispatch chains

openclaw< 2026.2.222026.2.22
Advertisement
CVE-2026-32039mediumCVSS: 5.9
2026-03-03

OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass

openclaw< 2026.2.222026.2.22
CVE-2026-27523high
2026-03-03

OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf paths

openclaw<= 2026.2.232026.2.24
GHSA-jxrq-8fm4-9p58high
2026-03-03

OpenClaw: Zip extraction symlink traversal could write outside destination

openclaw< 2026.2.222026.2.22
GHSA-8mf7-vv8w-hjr2low
2026-03-03

OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode

openclaw< 2026.2.222026.2.22
CVE-2026-31998medium
2026-03-03

OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch

openclaw>= 2026.2.22, <= 2026.2.232026.2.24
Advertisement
CVE-2026-32897low
2026-03-03

OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback

openclaw<= 2026.2.21-22026.2.22
GHSA-659f-22xc-98f2high
2026-03-03

OpenClaw hook transform path containment missed symlink-resolved escapes

openclaw<= 2026.2.21-22026.2.22
CVE-2026-32010mediumCVSS: 8.8
2026-03-03

In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program

openclaw<= 2026.2.21-22026.2.22
CVE-2026-32006mediumCVSS: 4.3
2026-03-03

OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback

openclaw<= 2026.2.252026.2.26
GHSA-gcj7-r3hg-m7w6lowCVSS: 3.7
2026-03-03

OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity

openclaw<= 2026.2.252026.2.26
Advertisement
GHSA-w7j5-j98m-w679high
2026-03-03

OpenClaw has multiple E2E/test Dockerfiles that run all processes as root

openclaw< 2026.2.212026.2.21
GHSA-796m-2973-wc5qmedium
2026-03-03

OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation

openclaw< 2026.2.232026.2.23
GHSA-7qf6-h84j-8fq4low
2026-03-03

OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model

openclaw<= 2026.2.252026.2.26
CVE-2026-32025mediumCVSS: 7.5
2026-03-03

OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains

openclaw<= 2026.2.242026.2.25
CVE-2026-32029mediumCVSS: 5.3
2026-03-03

OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

openclaw<= 2026.2.19-22026.2.21
Advertisement
CVE-2026-32056highCVSS: 7.5
2026-03-03

OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

openclaw< 2026.2.222026.2.22
CVE-2026-27524low
2026-03-03

OpenClaw's runtime /debug override path accepted prototype-reserved keys

openclaw< 2026.2.212026.2.21
GHSA-w9cg-v44m-4qv8high
2026-03-03

OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands

openclaw< 2026.2.212026.2.21
CVE-2026-32057mediumCVSS: 7.1
2026-03-03

OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

openclaw<= 2026.2.242026.2.25
GHSA-h97f-6pqj-q452medium
2026-03-03

OpenClaw has a IPv6 multicast SSRF classifier bypass

openclaw<= 2026.2.242026.2.25
Advertisement
CVE-2026-32021mediumCVSS: 6.5
2026-03-03

OpenClaw has a Feishu allowFrom authorization bypass via display-name collision

openclaw< 2026.2.222026.2.22
CVE-2026-22179high
2026-03-03

OpenClaw has macOS `system.run` allowlist bypass via quoted command substitution

openclaw< 2026.2.222026.2.22
GHSA-5h2c-8v84-qpvrmediumCVSS: 5.3
2026-03-03

OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell paths

openclaw< 2026.2.222026.2.22
GHSA-ff98-w8hj-qrxfmedium
2026-03-03

OpenClaw plugin runtime command execution is part of trusted plugin boundary

openclaw< 2026.2.192026.2.19
CVE-2026-32008mediumCVSS: 6.5
2026-03-03

OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files

openclaw< 2026.2.212026.2.21
Advertisement
CVE-2026-31994high
2026-03-03

OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

openclaw< 2026.2.192026.2.19
CVE-2026-32896mediumCVSS: 4.8
2026-03-03

OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)

openclaw< 2026.2.212026.2.21
GHSA-2mc2-g238-722jmedium
2026-03-03

OpenClaw affected by iMessage remote attachment SCP hardening (strict host-key checks and remoteHost validation)

openclaw<= 2026.2.172026.2.19
CVE-2026-32009highCVSS: 5.7
2026-03-03

OpenClaw: safeBins static default trusted dirs allow writable-dir binary hijack (`jq`)

openclaw<= 2026.2.232026.2.24
CVE-2026-32028mediumCVSS: 3.7
2026-03-03

OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups

openclaw<= 2026.2.242026.2.25
Advertisement
CVE-2026-29608mediumCVSS: 6.7
2026-03-03

OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

openclaw= 2026.3.12026.3.2
GHSA-2858-xg23-26fpmediumCVSS: 5.5
2026-03-03

OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots

openclaw>= 2026.2.13, <= 2026.3.12026.3.2
CVE-2026-28401medium
2026-03-03

NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells

nocodb<= 0.301.20.301.3
CVE-2026-28397medium
2026-03-03

NocoDB Vulnerable to Stored Cross-site Scripting via Comments

nocodb<= 0.301.20.301.3
CVE-2026-28399medium
2026-03-03

NocoDB Vulnerable to SQL Injection via DATEADD Formula

nocodb<= 0.301.20.301.3
Advertisement
CVE-2026-28398medium
2026-03-03

NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells

nocodb<= 0.301.20.301.3
CVE-2026-32030highCVSS: 7.5
2026-03-03

OpenClaw vulnerable to sensitive file disclosure via stageSandboxMedia

openclaw< 2026.2.192026.2.19
CVE-2026-28460medium
2026-03-03

OpenClaw's system.run allowlist bypass via shell line-continuation command substitution

openclaw< 2026.2.222026.2.22
CVE-2026-22177mediumCVSS: 8.8
2026-03-03

OpenClaw's config env vars allowed startup env injection into service runtime

openclaw< 2026.2.212026.2.21
CVE-2026-32032highCVSS: 7.8
2026-03-03

OpenClaw's shell env fallback trusts unvalidated SHELL path from host environment

openclaw< 2026.2.222026.2.22
Advertisement
GHSA-qhrr-grqp-6x2gmedium
2026-03-03

OpenClaw's tools.exec.safeBins trusted PATH directories allowed binary shadowing in allowlist mode

openclaw< 2026.2.222026.2.22
CVE-2026-32052medium
2026-03-03

OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text

openclaw<= 2026.2.232026.2.24
CVE-2026-32043medium
2026-03-03

OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

openclaw<= 2026.2.242026.2.25
CVE-2026-32064highCVSS: 7.7
2026-03-03

OpenClaw's andbox browser noVNC observer lacked VNC authentication

openclaw< 2026.2.212026.2.21
CVE-2026-32027highCVSS: 6.5
2026-03-03

OpenClaw DM pairing-store identities could satisfy group allowlist authorization

openclaw<= 2026.2.252026.2.26
Advertisement
CVE-2026-32023mediumCVSS: 8.8
2026-03-03

OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode

openclaw<= 2026.2.232026.2.24
CVE-2026-32022mediumCVSS: 6.5
2026-03-03

OpenClaw safeBins grep -e File Read Bypass (stdin-only policy bypass)

openclaw< 2026.2.212026.2.21
GHSA-h656-5vcf-cm23medium
2026-03-03

OpenClaw: Unauthorized Telegram Senders Trigger Media Download and Disk Write Before Access Check

openclaw<= 2026.2.232026.2.24
GHSA-9f72-qcpw-2hxchigh
2026-03-03

OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs

openclaw<= 2026.2.232026.2.24
CVE-2026-22169mediumCVSS: 6.4
2026-03-03

OpenClaw's non-default safeBins sort configuration can bypass intended allowlist approval constraints

openclaw< 2026.2.222026.2.22
Advertisement
CVE-2026-32036highCVSS: 6.5
2026-03-03

OpenClaw has gateway plugin auth bypass via encoded dot-segment traversal in protected /api/channels paths

openclaw<= 2026.2.252026.2.26
CVE-2026-32045medium
2026-03-03

OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes

openclaw< 2026.2.212026.2.21
CVE-2026-32026mediumCVSS: 6.5
2026-03-03

Temporary path handling could write outside OpenClaw temp boundary

openclaw<= 2026.2.232026.2.24
CVE-2026-32046medium
2026-03-03

OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser container

openclaw< 2026.2.212026.2.21
CVE-2026-32037highCVSS: 6
2026-03-03

OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists

openclaw< 2026.2.222026.2.22
Advertisement
CVE-2026-32016mediumCVSS: 7.8
2026-03-03

OpenClaw: macOS optional allowlist basename matching could bypass path-based policy

openclaw< 2026.2.222026.2.22
CVE-2026-32003highCVSS: 6.6
2026-03-03

OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)

openclaw< 2026.2.222026.2.22
CVE-2026-32014highCVSS: 8
2026-03-03

OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy

openclaw<= 2026.2.252026.2.26
GHSA-5847-rm3g-23mwmedium
2026-03-03

OpenClaw has hook auth rate limiter bypass via IPv4-mapped IPv6 client key variants

openclaw< 2026.2.222026.2.22
CVE-2026-27545high
2026-03-02

OpenClaw: Node system.run approval bypass via parent-symlink cwd rebind

openclaw<= 2026.2.252026.2.26
Advertisement
CVE-2026-27522high
2026-03-02

OpenClaw: Message action attachment hydration bypasses local media root checks when sandboxRoot is unset

openclaw<= 2026.2.232026.2.24
CVE-2026-28466criticalCVSS: 9.9
2026-03-02

OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway

openclaw< 2026.2.142026.2.14
CVE-2026-32058lowCVSS: 2.6
2026-03-02

OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

openclaw< 2026.2.262026.2.26
CVE-2026-32049high
2026-03-02

OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

openclaw< 2026.2.222026.2.22
GHSA-jq4x-98m3-ggq6high
2026-03-02

OpenClaw Canvas Path Traversal Information Disclosure Vulnerability

openclaw< 2026.2.212026.2.21
Advertisement
GHSA-6x2m-hqfw-hvpjmedium
2026-03-02

OpenClaw: Node exec approvals could be replayed across nodes

openclaw< 2026.2.232026.2.23
CVE-2026-29607mediumCVSS: 6.4
2026-03-02

OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

openclaw< 2026.2.222026.2.22
CVE-2026-32020lowCVSS: 3.3
2026-03-02

OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read

openclaw< 2026.2.222026.2.22
CVE-2026-31993low
2026-03-02

OpenClaw macOS companion app (beta): allowlist parsing mismatch for system.run shell chains

openclaw< 2026.2.222026.2.22
CVE-2026-22168high
2026-03-02

OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing arguments

openclaw< 2026.2.212026.2.21
Advertisement
CVE-2026-31991lowCVSS: 3.7
2026-03-02

OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage

openclaw< 2026.2.262026.2.26
CVE-2026-31997high
2026-03-02

OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind

openclaw< 2026.3.12026.3.1
CVE-2026-31999critical
2026-03-02

CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific paths

openclaw>= 2026.2.26, < 2026.3.12026.3.1
GHSA-392f-ggf5-fp3cmedium
2026-03-02

OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

openclaw< 2026.3.12026.3.1
CVE-2026-28794critical
2026-03-02

`@orpc/client` has Prototype Pollution via `StandardRPCJsonSerializer` Deserialization

@orpc/client<= 1.13.51.13.6
Advertisement
CVE-2026-28359medium
2026-03-02

NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field

nocodb<= 0.301.20.301.3
CVE-2026-2293high
2026-03-02

Nest has a Fastify URL Encoding Middleware Bypass

@nestjs/platform-fastify<= 11.1.1311.1.14
GHSA-5c6j-r48x-rmvqhighCVSS: 8.1
2026-02-28

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

serialize-javascript<= 7.0.27.0.3
GHSA-38c7-23hj-2wgqmediumCVSS: 4
2026-02-26

n8n has Webhook Forgery on Zendesk Trigger Node

n8n< 1.123.181.123.18
n8n>= 2.0.0, < 2.6.22.6.2
GHSA-fvfv-ppw4-7h2wmediumCVSS: 3.7
2026-02-26

n8n has a Guardrail Node Bypass

n8n< 2.10.02.10.0
Advertisement
GHSA-jh8h-6c9q-7gmwmediumCVSS: 4.8
2026-02-26

n8n has an Authentication Bypass in its Chat Trigger Node

n8n< 1.123.221.123.22
n8n>= 2.0.0, < 2.9.32.9.3
n8n>= 2.10.0, < 2.10.12.10.1
CVE-2026-27903highCVSS: 7.5
2026-02-26

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

minimatch>= 10.0.0, < 10.2.310.2.3
minimatch>= 9.0.0, < 9.0.79.0.7
minimatch>= 8.0.0, < 8.0.68.0.6
minimatch>= 7.0.0, < 7.4.87.4.8
minimatch>= 6.0.0, < 6.2.26.2.2
minimatch>= 5.0.0, < 5.1.85.1.8
minimatch>= 4.0.0, < 4.2.54.2.5
minimatch< 3.1.33.1.3
CVE-2026-27904highCVSS: 7.5
2026-02-26

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

minimatch>= 10.0.0, < 10.2.310.2.3
minimatch>= 9.0.0, < 9.0.79.0.7
minimatch>= 8.0.0, < 8.0.68.0.6
minimatch>= 7.0.0, < 7.4.87.4.8
minimatch>= 6.0.0, < 6.2.26.2.2
minimatch>= 5.0.0, < 5.1.85.1.8
minimatch>= 4.0.0, < 4.2.54.2.5
minimatch< 3.1.43.1.4
CVE-2026-27837mediumCVSS: 6.3
2026-02-26

dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()

dottie>= 2.0.4, <= 2.0.62.0.7
GHSA-mqpr-49jj-32rcmediumCVSS: 4
2026-02-26

n8n: Webhook Forgery on Github Webhook Trigger

n8n< 1.123.151.123.15
n8n>= 2.0.0, < 2.5.02.5.0
Advertisement
GHSA-f3f2-mcxc-pwjxmediumCVSS: 8.2
2026-02-26

n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes

n8n< 2.4.02.4.0
CVE-2026-27795mediumCVSS: 4.1
2026-02-25

LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader

@langchain/community<= 1.1.171.1.18
CVE-2026-27739critical
2026-02-25

Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

@angular/ssr>= 21.2.0-next.0, < 21.2.0-rc.021.2.0-rc.1
@angular/ssr>= 21.0.0-next.0, < 21.1.521.1.5
@angular/ssr>= 20.0.0-next.0, < 20.3.1720.3.17
@angular/ssr< 19.2.2119.2.21
@nguniversal/common<= 16.2.0
@nguniversal/express-engine<= 16.2.0
CVE-2026-27738medium
2026-02-25

Angular SSR has an Open Redirect via X-Forwarded-Prefix

@angular/ssr>= 21.2.0-next.0, < 21.2.0-rc.021.2.0-rc.1
@angular/ssr>= 21.0.0-next.0, < 21.1.521.1.5
@angular/ssr>= 20.0.0-next.0, < 20.3.1720.3.17
@angular/ssr>= 19.0.0-next.0, < 19.2.2119.2.21
CVE-2026-27606high
2026-02-25

Rollup 4 has Arbitrary File Write via Path Traversal

rollup< 2.80.02.80.0
rollup>= 3.0.0, < 3.30.03.30.0
rollup>= 4.0.0, < 4.59.04.59.0
Advertisement
CVE-2026-27729mediumCVSS: 5.9
2026-02-25

Astro has memory exhaustion DoS due to missing request body size limit in Server Actions

@astrojs/node>= 9.0.0, < 9.5.49.5.4
CVE-2026-27578highCVSS: 5.4
2026-02-25

n8n Vulnerable to Stored XSS via Various Nodes

n8n< 1.123.221.123.22
n8n>= 2.0.0, < 2.9.32.9.3
n8n>= 2.10.0, < 2.10.12.10.1
CVE-2026-27498criticalCVSS: 8.5
2026-02-25

n8n has Arbitrary Command Execution via File Write and Git Operations

n8n< 1.123.81.123.8
n8n>= 2.0.0, < 2.2.02.2.0
CVE-2026-27497criticalCVSS: 9.9
2026-02-25

n8n has Potential Remote Code Execution via Merge Node

n8n< 1.123.221.123.22
n8n>= 2.0.0, < 2.9.32.9.3
n8n>= 2.10.0, < 2.10.12.10.1
CVE-2026-27494highCVSS: 9.9
2026-02-25

n8n has Arbitrary File Read via Python Code Node Sandbox Escape

n8n< 1.123.221.123.22
n8n>= 2.0.0, < 2.9.32.9.3
n8n>= 2.10.0, < 2.10.12.10.1
Advertisement
CVE-2026-27493criticalCVSS: 9
2026-02-25

n8n has Unauthenticated Expression Evaluation via Form Node

n8n< 1.123.221.123.22
n8n>= 2.0.0, < 2.9.32.9.3
n8n>= 2.10.0, < 2.10.12.10.1
CVE-2026-27702criticalCVSS: 9.9
2026-02-25

Budibase: Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)

budibase< 3.30.43.30.4
CVE-2026-27829mediumCVSS: 6.5
2026-02-25

Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

@astrojs/node>= 9.0.0, < 9.5.49.5.4
CVE-2026-27728criticalCVSS: 9.9
2026-02-25

OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()

@oneuptime/common< 10.0.710.0.7
CVE-2026-27597criticalCVSS: 10
2026-02-25

@enclave-vm/core is vulnerable to Sandbox Escape

@enclave-vm/core<= 2.10.12.11.1
Advertisement
CVE-2026-27612mediumCVSS: 6.1
2026-02-25

repostat: Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard

repostat< 1.0.11.0.1
CVE-2025-69985criticalCVSS: 9.8
2026-02-24

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

@frangoteam/fuxa<= 1.2.8
CVE-2026-27574criticalCVSS: 9.9
2026-02-24

OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE

@oneuptime/common< 10.0.010.0.0
CVE-2026-25545mediumCVSS: 8.6
2026-02-23

Astro has Full-Read SSRF in error rendering via Host: header injection

@astrojs/node< 9.5.49.5.4
CVE-2026-27576medium
2026-02-20

OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs

openclaw<= 2026.2.172026.2.19
Advertisement
CVE-2026-27492mediumCVSS: 4.7
2026-02-20

Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reused

lettermint< 1.5.11.5.1
CVE-2026-27485medium
2026-02-20

OpenClaw: Reject symlinks in local skill packaging script

openclaw<= 2026.2.182026.2.19
CVE-2026-27484low
2026-02-20

OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows

openclaw< 2026.2.182026.2.18
CVE-2026-27212critical
2026-02-19

Prototype pollution in swiper

swiper>= 6.5.1, < 12.1.212.1.2
CVE-2026-28479highCVSS: 5.4
2026-02-19

OpenClaw replaced a deprecated sandbox hash algorithm

openclaw<= 2026.2.142026.2.15
Advertisement
CVE-2026-28394mediumCVSS: 6.5
2026-02-19

OpenClaw has a Web Fetch DoS via unbounded response parsing

openclaw< 2026.2.152026.2.15
CVE-2026-27009mediumCVSS: 5.8
2026-02-18

OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection

openclaw< 2026.2.152026.2.15
CVE-2026-27007medium
2026-02-18

OpenClaw's sandbox config hash sorted primitive arrays and suppressed needed container recreation

openclaw< 2026.2.152026.2.15
CVE-2026-27004medium
2026-02-18

OpenClaw session tool visibility hardening and Telegram webhook secret fallback

openclaw< 2026.2.152026.2.15
CVE-2026-27003medium
2026-02-18

OpenClaw: Telegram bot token exposure via logs

openclaw< 2026.2.152026.2.15
Advertisement
CVE-2026-27002high
2026-02-18

OpenClaw: Docker container escape via unvalidated bind mount config injection

openclaw< 2026.2.152026.2.15
CVE-2026-26318highCVSS: 8.8
2026-02-18

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

systeminformation<= 5.30.75.31.0
CVE-2026-26280highCVSS: 8.4
2026-02-18

Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path

systeminformation< 5.30.85.30.8
CVE-2026-26974high
2026-02-18

Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde

@tygo-van-den-hurk/slyde< 0.0.50.0.5
CVE-2026-27486medium
2026-02-18

OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup

openclaw< 2026.2.142026.2.14
Advertisement
CVE-2026-27487highCVSS: 7.6
2026-02-18

OpenClaw: Prevent shell injection in macOS keychain credential write

openclaw< 2026.2.142026.2.14
CVE-2026-28456highCVSS: 7.2
2026-02-18

OpenClaw affected by potential code execution via unsafe hook module path handling in Gateway

openclaw>= 2026.1.5, < 2026.2.142026.2.14
CVE-2026-26960highCVSS: 7.1
2026-02-18

Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

tar< 7.5.87.5.8
CVE-2026-29610highCVSS: 8.8
2026-02-18

OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)

openclaw< 2026.2.142026.2.14
CVE-2026-28476mediumCVSS: 8.3
2026-02-18

OpenClaw affected by SSRF in optional Tlon (Urbit) extension authentication

openclaw< 2026.2.142026.2.14
Advertisement
CVE-2026-29606mediumCVSS: 6.5
2026-02-18

OpenClaw Twilio voice-call webhook auth bypass when ngrok loopback compatibility is enabled

openclaw< 2026.2.142026.2.14
CVE-2026-28469highCVSS: 9.8
2026-02-18

OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

openclaw< 2026.2.142026.2.14
clawdbot<= 2026.1.24-3
CVE-2026-26317highCVSS: 7.1
2026-02-18

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

openclaw< 2026.2.142026.2.14
clawdbot<= 2026.1.24-3
CVE-2026-28452mediumCVSS: 6.5
2026-02-18

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

openclaw< 2026.2.142026.2.14
clawdbot<= 2026.1.24-3
CVE-2026-29609highCVSS: 7.5
2026-02-18

OpenClaw affected by denial of service via unbounded URL-backed media fetch

openclaw< 2026.2.142026.2.14
Advertisement
CVE-2026-28392highCVSS: 4.8
2026-02-18

OpenClaw Slack: dmPolicy=open allowed any DM sender to run privileged slash commands

openclaw< 2026.2.142026.2.14
CVE-2026-28463highCVSS: 5.7
2026-02-18

OpenClaw exec approvals: safeBins could bypass stdin-only constraints via shell expansion

openclaw< 2026.2.142026.2.14
CVE-2026-26329high
2026-02-18

OpenClaw has a path traversal in browser upload allows local file read

openclaw< 2026.2.142026.2.14
CVE-2026-26325highCVSS: 7.2
2026-02-17

OpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvals

openclaw< 2026.2.142026.2.14
CVE-2026-26324highCVSS: 7.5
2026-02-17

OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)

openclaw< 2026.2.142026.2.14
Advertisement
CVE-2026-26322highCVSS: 7.6
2026-02-17

OpenClaw Gateway tool allowed unrestricted gatewayUrl override

openclaw< 2026.2.142026.2.14
CVE-2026-26278highCVSS: 7.5
2026-02-17

fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)

fast-xml-parser>= 4.1.3, < 4.5.44.5.4
fast-xml-parser>= 5.0.0, < 5.3.65.3.6
CVE-2026-29613highCVSS: 5.9
2026-02-17

OpenClaw has a webhook auth bypass when gateway is behind a reverse proxy (loopback remoteAddress trust)

openclaw< 2026.2.122026.2.12
CVE-2026-28391highCVSS: 9.8
2026-02-17

OpenClaw's Windows cmd.exe parsing may bypass exec allowlist/approval gating

openclaw< 2026.2.22026.2.2
CVE-2026-0969highCVSS: 8.8
2026-02-12

next-mdx-remote affected by arbitrary code execution in React server-side rendering of untrusted MDX content

next-mdx-remote>= 4.3.0, < 6.0.06.0.0
Advertisement
GHSA-vx5f-vmr6-32wfmedium
2026-02-10

cap-go/capacitor-native-biometric Authentication Bypass

@capgo/capacitor-native-biometric< 8.3.68.3.6
CVE-2026-25938critical
2026-02-10

FUXA Unauthenticated Remote Code Execution in Node-RED Integration

fuxa-server>= 1.2.8, < 1.2.111.2.11
CVE-2026-25639highCVSS: 7.5
2026-02-09

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

axios>= 1.0.0, <= 1.13.41.13.5
axios<= 0.30.20.30.3
CVE-2026-1615highCVSS: 9.8
2026-02-09

jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions

jsonpath<= 1.2.11.3.0
CVE-2026-25762highCVSS: 7.5
2026-02-06

AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection

@adonisjs/bodyparser<= 10.1.210.1.3
@adonisjs/bodyparser>= 11.0.0-next.0, <= 11.0.0-next.811.0.0-next.9
Advertisement
CVE-2026-25754highCVSS: 7.2
2026-02-06

AdonisJS multipart body parsing has Prototype Pollution issue

@adonisjs/bodyparser<= 10.1.210.1.3
@adonisjs/bodyparser>= 11.0.0-next.0, <= 11.0.0-next.811.0.0-next.9
CVE-2026-25651mediumCVSS: 6.1
2026-02-06

client-certificate-auth Vulnerable to Open Redirect via Host Header Injection in HTTP-to-HTTPS redirect

client-certificate-auth>= 0.2.1, < 1.0.01.0.0
CVE-2026-25586criticalCVSS: 10
2026-02-05

@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution

@nyariv/sandboxjs<= 0.8.280.8.29
CVE-2025-68458lowCVSS: 3.7
2026-02-05

webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

webpack>= 5.49.0, <= 5.104.05.104.1
CVE-2025-68157lowCVSS: 3.7
2026-02-05

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

webpack>= 5.49.0, < 5.104.05.104.0
Advertisement
CVE-2026-25533medium
2026-02-05

Sandbox escape via infinite recursion and error objects

enclave-vm<= 2.7.0
@enclave-vm/core< 2.10.12.10.1
CVE-2026-25631medium
2026-02-04

n8n's domain allowlist bypass enables credential exfiltration

n8n< 1.121.01.121.0
CVE-2026-25115criticalCVSS: 9.9
2026-02-04

n8n has a Python sandbox escape

n8n< 2.4.82.4.8
CVE-2026-25056critical
2026-02-04

n8n Merge Node has Arbitrary File Write leading to RCE

n8n< 1.118.01.118.0
n8n>= 2.0.0, < 2.4.02.4.0
CVE-2026-25055high
2026-02-04

n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node

n8n>= 2.0.0, < 2.4.02.4.0
n8n< 1.123.121.123.12
Advertisement
CVE-2026-25053critical
2026-02-04

n8n has OS Command Injection in Git Node

n8n>= 2.0.0, < 2.5.02.5.0
n8n< 1.123.101.123.10
CVE-2026-23897highCVSS: 7.5
2026-02-04

Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`

apollo-server>= 2.0.0, <= 3.13.0
@apollo/server>= 4.2.0, < 4.13.04.13.0
@apollo/server>= 5.0.0, < 5.4.05.4.0
CVE-2025-61917highCVSS: 7.7
2026-02-04

n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

n8n>= 1.65.0, < 1.114.31.114.3
CVE-2026-25148medium
2026-02-03

Qwik SSR XSS via Unsafe Virtual Node Serialization

@builder.io/qwik-city< 1.19.01.19.0
CVE-2026-25547high
2026-02-03

@isaacs/brace-expansion has Uncontrolled Resource Consumption

@isaacs/brace-expansion<= 5.0.05.0.1
Advertisement
CVE-2026-24884highCVSS: 8.4
2026-02-03

Compressing Vulnerable to Arbitrary File Write via Symlink Extraction

compressing= 2.0.02.0.1
compressing<= 1.10.31.10.4
CVE-2026-25224lowCVSS: 3.7
2026-02-02

Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream

fastify<= 5.7.25.7.3
CVE-2026-25153highCVSS: 7.7
2026-02-02

@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks

@backstage/plugin-techdocs-node= 1.14.01.14.1
@backstage/plugin-techdocs-node< 1.13.111.13.11
CVE-2026-24040medium
2026-02-02

jsPDF has Shared State Race Condition in addJS Plugin

jspdf<= 4.0.04.1.0
CVE-2026-25152mediumCVSS: 5.3
2026-02-02

@backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator

@backstage/plugin-techdocs-node= 1.14.01.14.1
@backstage/plugin-techdocs-node< 1.13.111.13.11
Advertisement
CVE-2026-25128highCVSS: 7.5
2026-01-30

fast-xml-parser has RangeError DoS Numeric Entities Bug

fast-xml-parser>= 5.0.9, <= 5.3.35.3.4
CVE-2026-25047critical
2026-01-29

deepHas vulnerable to Prototype Pollution via constructor.prototype

deephas< 1.0.81.0.8
CVE-2026-23864highCVSS: 7.5
2026-01-29

React Server Components have multiple Denial of Service Vulnerabilities

react-server-dom-parcel>= 19.0.0, < 19.0.419.0.4
react-server-dom-turbopack>= 19.1.0-canary-7130d0c6-20241212, < 19.1.519.1.5
react-server-dom-webpack>= 19.2.0-canary-63779030-20250328, < 19.2.419.2.4
react-server-dom-turbopack>= 19.0.0, < 19.0.419.0.4
react-server-dom-parcel>= 19.1.0-canary-7130d0c6-20241212, < 19.1.519.1.5
react-server-dom-parcel>= 19.2.0-canary-63779030-20250328, < 19.2.419.2.4
react-server-dom-webpack>= 19.1.0-canary-7130d0c6-20241212, < 19.1.519.1.5
react-server-dom-webpack>= 19.0.0, < 19.0.419.0.4
react-server-dom-turbopack>= 19.2.0-canary-63779030-20250328, < 19.2.419.2.4
CVE-2026-24766mediumCVSS: 4.9
2026-01-28

NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS

nocodb< 0.301.00.301.0
CVE-2025-57283medium
2026-01-28

BrowserStack Local vulnerable to Command Injection through logfile variable

browserstack-local<= 1.5.81.5.9
Advertisement
CVE-2026-24842highCVSS: 8.2
2026-01-28

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

tar< 7.5.77.5.7
GHSA-h25m-26qc-wcjfhighCVSS: 7.5
2026-01-28

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

next>= 13.0.0, < 15.0.815.0.8
next>= 15.1.1-canary.0, < 15.1.1215.1.12
next>= 15.2.0-canary.0, < 15.2.915.2.9
next>= 15.3.0-canary.0, < 15.3.915.3.9
next>= 15.4.0-canary.0, < 15.4.1115.4.11
next>= 15.5.1-canary.0, < 15.5.1015.5.10
next>= 15.6.0-canary.0, < 15.6.0-canary.6115.6.0-canary.61
next>= 16.0.0-beta.0, < 16.0.1116.0.11
next>= 16.1.0-canary.0, < 16.1.516.1.5
CVE-2025-59472mediumCVSS: 5.9
2026-01-28

Next.js has Unbounded Memory Consumption via PPR Resume Endpoint

next>= 16.0.0-beta.0, < 16.1.516.1.5
next>= 15.6.0-canary.0, < 15.6.0-canary.6115.6.0-canary.61
next>= 15.0.0-canary.0, <= 15.0.0-canary.205
next>= 15.0.1-canary.0, <= 15.0.1-canary.3
next>= 15.0.2-canary.0, <= 15.0.2-canary.11
next>= 15.0.3-canary.0, <= 15.0.3-canary.9
next>= 15.0.4-canary.0, <= 15.0.4-canary.52
next>= 15.1.1-canary.0, <= 15.1.1-canary.27
next>= 15.2.0-canary.0, <= 15.2.0-canary.77
next>= 15.2.1-canary.0, <= 15.2.1-canary.6
next>= 15.2.2-canary.0, <= 15.2.2-canary.7
next>= 15.3.0-canary.0, <= 15.3.0-canary.46
next>= 15.3.1-canary.0, <= 15.3.1-canary.15
next>= 15.4.0-canary.0, <= 15.4.0-canary.130
next>= 15.4.2-canary.0, <= 15.4.2-canary.56
next>= 15.5.1-canary.0, <= 15.5.1-canary.39
CVE-2025-59471mediumCVSS: 5.9
2026-01-27

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

next>= 10.0.0, < 15.5.1015.5.10
next>= 15.6.0-canary.0, < 16.1.516.1.5
CVE-2026-24472mediumCVSS: 5.3
2026-01-27

Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception

hono< 4.11.74.11.7
Advertisement
CVE-2026-23888mediumCVSS: 6.5
2026-01-26

pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)

pnpm< 10.28.110.28.1
CVE-2026-22696critical
2026-01-26

dcap-qvl has Missing Verification for QE Identity

dcap-qvl< 0.3.90.3.9
@phala/dcap-qvl<= 0.3.00.3.9
@phala/dcap-qvl-web<= 0.3.3
@phala/dcap-qvl-node<= 0.3.3
dcap-qvl< 0.3.90.3.9
CVE-2026-24046highCVSS: 7.1
2026-01-21

Backstage has a Possible Symlink Path Traversal in Scaffolder Actions

@backstage/backend-defaults< 0.12.20.12.2
@backstage/backend-defaults>= 0.13.0, < 0.13.20.13.2
@backstage/backend-defaults>= 0.14.0, < 0.14.10.14.1
@backstage/plugin-scaffolder-backend< 2.2.22.2.2
@backstage/plugin-scaffolder-backend>= 3.0.0, < 3.0.23.0.2
@backstage/plugin-scaffolder-backend>= 3.1.0, < 3.1.13.1.1
@backstage/plugin-scaffolder-node< 0.11.20.11.2
@backstage/plugin-scaffolder-node>= 0.12.0, < 0.12.30.12.3
GHSA-h3hw-29fv-2x75high
2026-01-21

@envelop/graphql-modules has a Race Condition vulnerability

@envelop/graphql-modules< 9.1.09.1.0
CVE-2026-23950highCVSS: 8.8
2026-01-21

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

tar<= 7.5.37.5.4
Advertisement
CVE-2026-1245mediumCVSS: 6.5
2026-01-20

binary-parser library has a code injection vulnerability

binary-parser< 2.3.02.3.0
CVE-2026-22037highCVSS: 8.4
2026-01-20

@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)

@fastify/express<= 4.0.24.0.3
CVE-2026-22031highCVSS: 8.4
2026-01-20

Fastify Middie Middleware Path Bypass

@fastify/middie<= 9.0.39.1.0
CVE-2026-23745high
2026-01-16

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

tar<= 7.5.27.5.3
CVE-2026-23527highCVSS: 8.9
2026-01-15

h3 v1 has Request Smuggling (TE.TE) issue

h3<= 1.15.41.15.5
Advertisement
CVE-2025-67647high
2026-01-15

SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

@sveltejs/kit>= 2.19.0, <= 2.49.42.49.5
@sveltejs/adapter-node>= 5.4.1, <= 5.5.05.5.1
CVE-2026-22036mediumCVSS: 5.9
2026-01-14

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

undici>= 7.0.0, < 7.18.27.18.2
undici< 6.23.06.23.0
CVE-2026-22686criticalCVSS: 10
2026-01-14

enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain

enclave-vm< 2.7.02.7.0
CVE-2026-22814high
2026-01-13

Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State

@adonisjs/lucid<= 21.8.121.8.2
@adonisjs/lucid>= 22.0.0-next.0, < 22.0.0-next.622.0.0-next.6
CVE-2025-68949mediumCVSS: 5.3
2026-01-13

n8n: Webhook Node IP Whitelist Bypass via Partial String Matching

n8n>= 1.36.0, < 2.2.02.2.0
Advertisement
CVE-2026-22030mediumCVSS: 6.5
2026-01-08

React Router has CSRF issue in Action/Server Action Request Processing

react-router>= 7.0.0, <= 7.11.07.12.0
@remix-run/server-runtime<= 2.17.22.17.3
CVE-2026-22029highCVSS: 8
2026-01-08

React Router vulnerable to XSS via Open Redirects

react-router>= 7.0.0, <= 7.11.07.12.0
@remix-run/router<= 1.23.11.23.2
CVE-2026-21884highCVSS: 8.2
2026-01-08

React Router SSR XSS in ScrollRestoration

react-router>= 7.0.0, < 7.12.07.12.0
@remix-run/react< 2.17.32.17.3
CVE-2025-68470mediumCVSS: 6.5
2026-01-08

React Router has unexpected external redirect via untrusted paths

react-router>= 6.0.0, < 6.30.26.30.2
react-router>= 7.0.0, < 7.9.67.9.6
CVE-2025-61686criticalCVSS: 9.1
2026-01-08

React Router has Path Traversal in File Session Storage

@react-router/node>= 7.0.0, <= 7.9.37.9.4
@remix-run/node<= 2.17.12.17.2
@remix-run/deno<= 2.17.12.17.2
Advertisement
CVE-2025-59057highCVSS: 7.6
2026-01-08

React Router has XSS Vulnerability

react-router>= 7.0.0, <= 7.8.27.9.0
@remix-run/react>= 1.15.0, <= 2.17.02.17.1
CVE-2026-21894mediumCVSS: 6.5
2026-01-07

n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

n8n>= 0.150.0, < 2.2.22.2.2
CVE-2025-69264highCVSS: 8.8
2026-01-07

pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

pnpm>= 10.0.0, < 10.26.010.26.0
CVE-2025-69262highCVSS: 7.5
2026-01-07

pnpm vulnerable to Command Injection via environment variable substitution

pnpm>= 6.25.0, < 10.27.010.27.0
CVE-2026-21877criticalCVSS: 9.9
2026-01-06

n8n Vulnerable to RCE via Arbitrary File Write

n8n>= 0.123.0, < 1.121.31.121.3
Advertisement
CVE-2025-68428critical
2026-01-05

jsPDF has Local File Inclusion/Path Traversal vulnerability

jspdf<= 3.0.44.0.0
CVE-2026-21440critical
2026-01-02

AdonisJS Path Traversal in Multipart File Handling

@adonisjs/bodyparser< 10.1.210.1.2
@adonisjs/bodyparser>= 11.0.0-next.0, < 11.0.0-next.611.0.0-next.6
CVE-2025-68619highCVSS: 7.2
2026-01-02

Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package

signalk-server< 2.9.02.9.0
CVE-2025-68272highCVSS: 7.5
2026-01-02

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

signalk-server< 2.19.02.19.0
CVE-2025-69202medium
2025-12-30

axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

axios-cache-interceptor< 1.11.11.11.1
Advertisement
CVE-2025-69206mediumCVSS: 4.3
2025-12-29

hemmelig allows SSRF Filter bypass via Secret Request functionality

hemmelig< 7.3.37.3.3
CVE-2025-68697highCVSS: 7.1
2025-12-26

Self-hosted n8n has Legacy Code node that enables arbitrary file read/write

n8n>= 1.2.1, < 2.0.02.0.0
CVE-2025-68668criticalCVSS: 9.9
2025-12-26

n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node

n8n>= 1.0.0, < 2.0.02.0.0
CVE-2025-61914highCVSS: 7.3
2025-12-26

n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox

n8n< 1.114.01.114.0
CVE-2025-68475highCVSS: 7.5
2025-12-22

Fedify has ReDoS Vulnerability in HTML Parsing Regex

@fedify/fedify< 1.6.131.6.13
@fedify/fedify>= 1.7.0, < 1.7.141.7.14
@fedify/fedify>= 1.8.0, < 1.8.151.8.15
@fedify/fedify>= 1.9.0, < 1.9.21.9.2
Advertisement
GHSA-24v3-254g-jv85low
2025-12-19

Tuta Mail has DOM attribute and CSS injection in its Contact Viewer feature

@tutao/tutanota-utils< 314.251111.0314.251111.0
CVE-2025-68154highCVSS: 8.1
2025-12-16

systeminformation has a Command Injection vulnerability in fsSize() function on Windows

systeminformation< 5.27.145.27.14
CVE-2025-68155highCVSS: 7.5
2025-12-16

@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint

@vitejs/plugin-rsc< 0.5.80.5.8
CVE-2025-68130high
2025-12-16

tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

@trpc/server>= 10.27.0, < 10.45.310.45.3
@trpc/server>= 11.0.0, < 11.8.011.8.0
GHSA-vr6p-vq2p-6j74criticalCVSS: 10
2025-12-15

Withdrawn Advisory: LikeC4 has RCE through vulnerable React and Next.js versions

likec4<= 1.46.1
Advertisement
GHSA-5j59-xgg2-r9c4highCVSS: 7.5
2025-12-12

Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

next>= 13.3.1-canary.0, < 14.2.3514.2.35
next>= 15.0.6, < 15.0.715.0.7
next>= 15.1.10, < 15.1.1115.1.11
next>= 15.2.7, < 15.2.815.2.8
next>= 15.3.7, < 15.3.815.3.8
next>= 15.4.9, < 15.4.1015.4.10
next>= 15.5.8, < 15.5.915.5.9
next>= 15.6.0-canary.59, < 15.6.0-canary.6015.6.0-canary.60
next>= 16.0.9, < 16.0.1016.0.10
next>= 16.1.0-canary.17, < 16.1.0-canary.1916.1.0-canary.19
GHSA-c6m7-q6pr-c64rmediumCVSS: 5.3
2025-12-12

Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components

@vitejs/plugin-rsc<= 0.5.60.5.7
GHSA-cpqf-f22c-r95xhighCVSS: 7.5
2025-12-12

Vite Plugin React has a Denial of Service Vulnerability in React Server Components

@vitejs/plugin-rsc<= 0.5.60.5.7
CVE-2025-67779highCVSS: 7.5
2025-12-12

Denial of Service Vulnerability in React Server Components

react-server-dom-parcel>= 19.0.2, < 19.0.319.0.3
react-server-dom-parcel>= 19.1.3, < 19.1.419.1.4
react-server-dom-parcel>= 19.2.2, < 19.2.319.2.3
react-server-dom-turbopack>= 19.0.2, < 19.0.319.0.3
react-server-dom-turbopack>= 19.1.3, < 19.1.419.1.4
react-server-dom-turbopack>= 19.2.2, < 19.2.319.2.3
react-server-dom-webpack>= 19.0.2, < 19.0.319.0.3
react-server-dom-webpack>= 19.1.3, < 19.1.419.1.4
react-server-dom-webpack>= 19.2.2, < 19.2.319.2.3
GHSA-w37m-7fhw-fmv9mediumCVSS: 5.3
2025-12-11

Next Server Actions Source Code Exposure

next>= 15.0.0-canary.0, < 15.0.615.0.6
next>= 15.1.1-canary.0, < 15.1.1015.1.10
next>= 15.2.0-canary.0, < 15.2.715.2.7
next>= 15.3.0-canary.0, < 15.3.715.3.7
next>= 15.4.0-canary.0, < 15.4.915.4.9
next>= 15.5.1-canary.0, < 15.5.815.5.8
next>= 15.6.0-canary.0, < 15.6.0-canary.5915.6.0-canary.59
next>= 16.0.0-beta.0, < 16.0.916.0.9
next>= 16.1.0-canary.0, < 16.1.0-canary.1716.1.0-canary.17
Advertisement
GHSA-mwv6-3258-q52chighCVSS: 7.5
2025-12-11

Next Vulnerable to Denial of Service with Server Components

next>= 13.3.0, < 14.2.3414.2.34
next>= 15.0.0-canary.0, < 15.0.615.0.6
next>= 15.1.1-canary.0, < 15.1.1015.1.10
next>= 15.2.0-canary.0, < 15.2.715.2.7
next>= 15.3.0-canary.0, < 15.3.715.3.7
next>= 15.4.0-canary.0, < 15.4.915.4.9
next>= 15.5.1-canary.0, < 15.5.815.5.8
next>= 15.6.0-canary.0, < 15.6.0-canary.5915.6.0-canary.59
next>= 16.0.0-beta.0, < 16.0.916.0.9
next>= 16.1.0-canary.0, < 16.1.0-canary.1716.1.0-canary.17
CVE-2025-55184highCVSS: 7.5
2025-12-11

Denial of Service Vulnerability in React Server Components

react-server-dom-parcel>= 19.0.0, < 19.0.219.0.2
react-server-dom-turbopack>= 19.0.0, < 19.0.219.0.2
react-server-dom-webpack>= 19.0.0, < 19.0.219.0.2
react-server-dom-parcel>= 19.1.0, < 19.1.319.1.3
react-server-dom-parcel>= 19.2.0, < 19.2.219.2.2
react-server-dom-turbopack>= 19.1.0, < 19.1.319.1.3
react-server-dom-turbopack>= 19.2.0, < 19.2.219.2.2
react-server-dom-webpack>= 19.1.0, < 19.1.319.1.3
react-server-dom-webpack>= 19.2.0, < 19.2.219.2.2
CVE-2025-55183mediumCVSS: 5.3
2025-12-11

Source Code Exposure Vulnerability in React Server Components

react-server-dom-parcel>= 19.0.0, < 19.0.219.0.2
react-server-dom-turbopack>= 19.0.0, < 19.0.219.0.2
react-server-dom-webpack>= 19.0.0, < 19.0.219.0.2
react-server-dom-parcel>= 19.1.0, < 19.1.319.1.3
react-server-dom-parcel>= 19.2.0, < 19.2.219.2.2
react-server-dom-turbopack>= 19.1.0, < 19.1.319.1.3
react-server-dom-turbopack>= 19.2.0, < 19.2.219.2.2
react-server-dom-webpack>= 19.1.0, < 19.1.319.1.3
react-server-dom-webpack>= 19.2.0, < 19.2.219.2.2
CVE-2025-67716lowCVSS: 3.7
2025-12-10

Improper Validation of Query Parameters in Auth0 Next.js SDK

@auth0/nextjs-auth0>= 4.9.0, < 4.13.04.13.0
CVE-2025-67490mediumCVSS: 5.4
2025-12-10

Improper Request Caching Lookup in the Auth0 Next.js SDK

@auth0/nextjs-auth0>= 4.11.0, < 4.11.24.11.2
@auth0/nextjs-auth0>= 4.12.0, < 4.12.14.12.1
Advertisement
CVE-2025-67489criticalCVSS: 9.8
2025-12-08

@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server

@vitejs/plugin-rsc<= 0.5.50.5.6
CVE-2025-65964critical
2025-12-08

n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook

n8n>= 0.123.1, < 1.119.21.119.2
CVE-2025-65959highCVSS: 8.7
2025-12-04

Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'

open-webui<= 0.6.360.6.37
CVE-2025-65945highCVSS: 7.5
2025-12-04

auth0/node-jws Improperly Verifies HMAC Signature

jws< 3.2.33.2.3
jws= 4.0.04.0.1
CVE-2025-66404mediumCVSS: 6.4
2025-12-03

mcp-server-kubernetes has potential security issue in exec_in_pod tool

mcp-server-kubernetes<= 2.9.72.9.8
Advertisement
GHSA-fmh4-wr37-44fpcriticalCVSS: 10
2025-12-03

React Server Components are Vulnerable to RCE

@vitejs/plugin-rsc<= 0.5.20.5.3
CVE-2025-55182criticalCVSS: 10
2025-12-03

React Server Components are Vulnerable to RCE

react-server-dom-webpack>= 19.1.0, < 19.1.219.1.2
react-server-dom-webpack= 19.2.019.2.1
react-server-dom-turbopack>= 19.1.0, < 19.1.219.1.2
react-server-dom-turbopack= 19.2.019.2.1
react-server-dom-parcel>= 19.1.0, < 19.1.219.1.2
react-server-dom-parcel= 19.2.019.2.1
react-server-dom-turbopack= 19.0.019.0.1
react-server-dom-parcel= 19.0.019.0.1
react-server-dom-webpack= 19.0.019.0.1
GHSA-9qr9-h5gf-34mpcriticalCVSS: 10
2025-12-03

Next.js is vulnerable to RCE in React flight protocol

next>= 14.3.0-canary.77, < 15.0.515.0.5
next>= 15.2.0-canary.0, < 15.2.615.2.6
next>= 15.3.0-canary.0, < 15.3.615.3.6
next>= 15.4.0-canary.0, < 15.4.815.4.8
next>= 16.0.0-canary.0, < 16.0.716.0.7
next>= 15.1.0-canary.0, < 15.1.915.1.9
next>= 15.5.0-canary.0, < 15.5.715.5.7
CVE-2025-14874highCVSS: 7.5
2025-12-01

Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls

nodemailer<= 7.0.107.0.11
CVE-2025-66031high
2025-11-26

node-forge has ASN.1 Unbounded Recursion

node-forge< 1.3.21.3.2
Advertisement
CVE-2025-66030medium
2025-11-26

node-forge is vulnerable to ASN.1 OID Integer Truncation

node-forge< 1.3.21.3.2
CVE-2025-12816highCVSS: 8.6
2025-11-26

node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization

node-forge< 1.3.21.3.2
CVE-2025-66020highCVSS: 7.5
2025-11-26

Valibot has a ReDoS vulnerability in `EMOJI_REGEX`

valibot>= 0.31.0, < 1.2.01.2.0
CVE-2025-65944medium
2025-11-24

Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true`

@sentry/node>= 10.11.0, < 10.27.010.27.0
@sentry/astro>= 10.11.0, < 10.27.010.27.0
@sentry/aws-serverless>= 10.11.0, < 10.27.010.27.0
@sentry/bun>= 10.11.0, < 10.27.010.27.0
@sentry/google-cloud-serverless>= 10.11.0, < 10.27.010.27.0
@sentry/nestjs>= 10.11.0, < 10.27.010.27.0
@sentry/nextjs>= 10.11.0, < 10.27.010.27.0
@sentry/node-core>= 10.11.0, < 10.27.010.27.0
@sentry/nuxt>= 10.11.0, < 10.27.010.27.0
@sentry/remix>= 10.11.0, < 10.27.010.27.0
@sentry/solidstart>= 10.11.0, < 10.27.010.27.0
@sentry/sveltekit>= 10.11.0, < 10.27.010.27.0
CVE-2025-64762high
2025-11-20

authkit-nextjs may let session cookies be cached in CDNs

@workos-inc/authkit-nextjs<= 2.11.02.11.1
Advertisement
CVE-2025-65019mediumCVSS: 5.4
2025-11-19

Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

astro< 5.15.95.15.9
CVE-2025-64765medium
2025-11-19

Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

astro< 5.15.85.15.8
CVE-2025-64757lowCVSS: 3.5
2025-11-19

Astro Development Server has Arbitrary Local File Read

astro< 5.14.35.14.3
CVE-2025-64756highCVSS: 7.5
2025-11-17

glob CLI: Command injection via -c/--cmd executes matches with shell:true

glob>= 11.0.0, < 11.1.011.1.0
glob>= 10.2.0, < 10.5.010.5.0
CVE-2025-64718mediumCVSS: 5.3
2025-11-14

js-yaml has prototype pollution in merge (<<)

js-yaml>= 4.0.0, < 4.1.14.1.1
js-yaml< 3.14.23.14.2
Advertisement
CVE-2025-64525mediumCVSS: 6.5
2025-11-13

Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass

astro>= 2.16.0, < 5.15.55.15.5
CVE-2025-12613highCVSS: 8.6
2025-11-10

Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand

cloudinary< 2.7.02.7.0
CVE-2025-64496highCVSS: 7.3
2025-11-07

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

open-webui<= 0.6.340.6.35
open-webui<= 0.6.340.6.35
CVE-2025-11953criticalCVSS: 9.8
2025-11-03

@react-native-community/cli has arbitrary OS command injection

@react-native-community/cli>= 20.0.0-alpha.0, < 20.0.020.0.0
@react-native-community/cli>= 19.0.0-alpha.0, < 19.1.219.1.2
@react-native-community/cli>= 18.0.0, < 18.0.118.0.1
@react-native-community/cli-server-api>= 20.0.0-alpha.0, < 20.0.020.0.0
@react-native-community/cli-server-api>= 19.0.0-alpha.0, < 19.1.219.1.2
@react-native-community/cli-server-api>= 18.0.0, < 18.0.118.0.1
CVE-2025-64118medium
2025-10-30

node-tar has a race condition leading to uninitialized memory exposure

tar= 7.5.17.5.2
Advertisement
CVE-2025-62726highCVSS: 8.8
2025-10-30

n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook

n8n< 1.113.01.113.0
CVE-2025-60542highCVSS: 6.5
2025-10-29

TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update

typeorm< 0.3.260.3.26
GHSA-5jpx-9hw9-2fx4medium
2025-10-29

NextAuthjs Email misdelivery Vulnerability

next-auth< 4.24.124.24.12
next-auth>= 5.0.0-beta.0, < 5.0.0-beta.305.0.0-beta.30
CVE-2025-62713high
2025-10-23

Kottster app reinitialization can be re-triggered allowing command injection in development mode

@kottster/server>= 3.2.0, < 3.3.23.3.2
GHSA-xvp7-8vm8-xfxxmediumCVSS: 4.2
2025-10-20

Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers

@actual-app/sync-server<= 25.10.025.11.0
Advertisement
CVE-2025-62427high
2025-10-16

Angular SSR has a Server-Side Request Forgery (SSRF) flaw

@angular/ssr>= 19.0.0-next.0, < 19.2.1819.2.18
@angular/ssr>= 20.0.0-next.0, < 20.3.620.3.6
@angular/ssr>= 21.0.0-next.0, < 21.0.0-next.821.0.0-next.8
CVE-2025-62410critical
2025-10-15

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

happy-dom>= 19.0.0, < 20.0.220.0.2
CVE-2025-34267high
2025-10-14

Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages

flowise>= 3.0.1, < 3.0.83.0.8
CVE-2025-61927critical
2025-10-10

Happy DOM: VM Context Escape can lead to Remote Code Execution

happy-dom< 20.0.020.0.0
CVE-2025-61925mediumCVSS: 6.5
2025-10-10

Astro's `X-Forwarded-Host` is reflected without validation

astro< 5.14.35.14.3
Advertisement
GHSA-j44m-5v8f-gc9chighCVSS: 7.7
2025-10-10

Flowise is vulnerable to arbitrary file exposure through its ReadFileTool

flowise< 3.0.83.0.8
flowise-components< 3.0.83.0.8
GHSA-365g-vjw2-grx8highCVSS: 8.8
2025-10-09

n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host

n8n-nodes-base<= 1.113.0
n8n<= 1.114.4
CVE-2025-61913criticalCVSS: 9.9
2025-10-09

Flowise is vulnerable to arbitrary file write through its WriteFileTool

flowise< 3.0.83.0.8
flowise-components< 3.0.83.0.8
Flowise<= 3.0.53.0.8
CVE-2025-61687highCVSS: 8.3
2025-10-08

FlowiseAI/Flosise has File Upload vulnerability

flowise= 3.0.73.0.8
CVE-2025-55346criticalCVSS: 9.8
2025-10-06

Flowise vulnerable to RCE via Dynamic function constructor injection

flowise<= 2.2.7-patch.1
Advertisement
GHSA-4fr9-3x69-36wvmedium
2025-10-03

Flowise vulnerable to XSS

flowise< 3.0.83.0.8
CVE-2025-11149highCVSS: 7.5
2025-09-30

@nubosoftware/node-static failure to catch exception can result in server crash

@nubosoftware/node-static<= 0.7.11
CVE-2025-59364medium
2025-09-26

express-xss-sanitizer has an unbounded recursion depth

express-xss-sanitizer< 2.0.12.0.1
CVE-2025-59936criticalCVSS: 9.4
2025-09-26

get-jwks: poisoned JWKS cache allows post-fetch issuer validation bypass

get-jwks<= 11.0.111.0.2
CVE-2025-57348low
2025-09-24

node-cube vulnerable to prototype pollution

node-cube<= 5.0.0-beta.19
Advertisement
CVE-2025-59834criticalCVSS: 9.8
2025-09-24

Command Injection in adb-mcp MCP Server

adb-mcp<= 0.1.0
CVE-2025-57354mediumCVSS: 6.5
2025-09-24

counterpart vulnerable to prototype pollution

counterpart<= 0.18.6
CVE-2025-57353mediumCVSS: 5.3
2025-09-24

messageformat prototype pollution vulnerability

@messageformat/runtime= 3.0.13.0.2
CVE-2025-59831highCVSS: 8.8
2025-09-22

`git-comiters` Command Injection vulnerability

git-commiters< 0.1.20.1.2
CVE-2025-59417medium
2025-09-18

Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages

@lobehub/chat<= 1.129.31.129.4
Advertisement
CVE-2025-10619mediumCVSS: 6.3
2025-09-17

@sequa-ai/sequa-mcp has Command Injection vulnerability

@sequa-ai/sequa-mcp< 1.0.141.0.14
CVE-2025-59333highCVSS: 8.1
2025-09-16

@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode

@executeautomation/database-server<= 1.1.0
CVE-2025-59331high
2025-09-15

is-arrayish@0.3.3 contains malware after npm account takeover

is-arrayish= 0.3.30.3.4
CVE-2025-59330high
2025-09-15

error-ex@1.3.3 contains malware after npm account takeover

error-ex= 1.3.31.3.4
CVE-2025-59162high
2025-09-15

color-convert@3.1.1 contains malware after npm account takeover

color-convert= 3.1.13.1.2
Advertisement
CVE-2025-59145high
2025-09-15

color-name@2.0.1 contains malware after npm account takeover

color-name= 2.0.12.0.2
CVE-2025-59144high
2025-09-15

debug@4.4.2 contains malware after npm account takeover

debug= 4.4.24.4.3
CVE-2025-59143high
2025-09-15

color@5.0.1 contains malware after npm account takeover

color= 5.0.15.0.2
CVE-2025-59142high
2025-09-15

color-string@2.1.1 contains malware after npm account takeover

color-string= 2.1.12.1.2
CVE-2025-59141high
2025-09-15

simple-swizzle@0.2.3 contains malware after npm account takeover

simple-swizzle= 0.2.30.2.4
Advertisement
CVE-2025-59140high
2025-09-15

backslash@0.2.1 contains malware after npm account takeover

backslash= 0.2.10.2.2
GHSA-6933-jpx5-q87qhigh
2025-09-15

Flowise has unsandboxed remote code execution via Custom MCP

flowise>= 2.2.7-patch.1, < 3.0.63.0.6
CVE-2025-59528criticalCVSS: 10
2025-09-15

Flowise has Remote Code Execution vulnerability

flowise= 3.0.53.0.6
CVE-2025-57164criticalCVSS: 9.1
2025-09-15

FlowiseAI Pre-Auth Arbitrary Code Execution

flowise= 3.0.53.0.6
CVE-2025-58177mediumCVSS: 4.1
2025-09-15

Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter

n8n>= 1.24.0, < 1.107.01.107.0
Advertisement
GHSA-qj3p-xc97-xw74medium
2025-09-15

MetaMask SDK indirectly exposed via malicious debug@4.4.2 dependency

@metamask/sdk>= 0.16.0, <= 0.33.00.33.1
@metamask/sdk-react>= 0.16.0, <= 0.33.00.33.1
@metamask/sdk-communication-layer>= 0.16.0, <= 0.33.00.33.1
GHSA-qhwp-454g-2gv4medium
2025-09-15

Duplicate Advisory: express-xss-sanitizer has an unbounded recursion depth

express-xss-sanitizer<= 2.0.0
CVE-2025-58754highCVSS: 7.5
2025-09-11

Axios is vulnerable to DoS attack through lack of data size check

axios>= 1.0.0, < 1.12.01.12.0
axios>= 0.28.0, < 0.30.20.30.2
CVE-2025-59052high
2025-09-10

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

@angular/platform-server>= 16.0.0-next.0, < 18.2.1418.2.14
@angular/platform-server>= 20.0.0-next.0, < 20.3.020.3.0
@angular/platform-server>= 19.0.0-next.0, < 19.2.1519.2.15
@angular/platform-server>= 21.0.0-next.0, < 21.0.0-next.321.0.0-next.3
@angular/ssr>= 17.0.0-next.0, < 18.2.2118.2.21
@angular/ssr>= 19.0.0-next.0, < 19.2.1619.2.16
@angular/ssr>= 20.0.0-next.0, < 20.3.020.3.0
@angular/ssr>= 21.0.0-next.0, < 21.0.0-next.321.0.0-next.3
@nguniversal/common>= 16.0.0-next.0, <= 16.2.0
CVE-2025-59046criticalCVSS: 9.8
2025-09-10

interactive-git-checkout has a Command Injection vulnerability

interactive-git-checkout<= 1.1.4
Advertisement
CVE-2025-58751low
2025-09-09

Vite middleware may serve files starting with the same name with the public directory

vite>= 7.1.0, <= 7.1.47.1.5
vite>= 7.0.0, <= 7.0.67.0.7
vite>= 6.0.0, <= 6.3.56.3.6
vite<= 5.4.195.4.20
CVE-2025-58752low
2025-09-09

Vite's `server.fs` settings were not applied to HTML files

vite>= 7.1.0, <= 7.1.47.1.5
vite>= 7.0.0, <= 7.0.67.0.7
vite>= 6.0.0, <= 6.3.56.3.6
vite<= 5.4.195.4.20
CVE-2025-59037high
2025-09-09

DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware

duckdb= 1.3.31.3.4
@duckdb/node-api= 1.3.31.3.4-alpha.27
@duckdb/node-bindings= 1.3.31.3.4-alpha.27
@duckdb/duckdb-wasm= 1.29.21.30.0
CVE-2025-54994critical
2025-09-08

@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API

@akoskm/create-mcp-server-stdio< 0.0.130.0.13
CVE-2025-58358highCVSS: 7.5
2025-09-02

mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool

mcp-markdownify-server<= 0.0.10.0.2
Advertisement
CVE-2025-57752mediumCVSS: 6.2
2025-08-29

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

next>= 15.0.0, <= 15.4.415.4.5
next>= 0.9.9, < 14.2.3114.2.31
CVE-2025-55173mediumCVSS: 4.3
2025-08-29

Next.js Content Injection Vulnerability for Image Optimization

next>= 15.0.0, <= 15.4.415.4.5
next>= 0.9.9, < 14.2.3114.2.31
CVE-2025-57822mediumCVSS: 6.5
2025-08-29

Next.js Improper Middleware Redirect Handling Leads to SSRF

next>= 15.0.0-canary.0, < 15.4.715.4.7
next>= 0.9.9, < 14.2.3214.2.32
CVE-2025-4643medium
2025-08-29

Payload does not invalidate JWTs after log out

payload< 3.44.03.44.0
@payloadcms/next< 3.44.03.44.0
@payloadcms/graphql< 3.44.03.44.0
CVE-2025-4644medium
2025-08-29

Payload's SQLite adapter Session Fixation vulnerability

payload< 3.44.03.44.0
@payloadcms/next< 3.44.03.44.0
@payloadcms/graphql< 3.44.03.44.0
Advertisement
CVE-2025-10894critical
2025-08-27

Malicious versions of Nx were published

nx= 21.5.0
@nx/key= 3.2.0
@nx/enterprise-cloud= 3.2.0
@nx/devkit= 21.5.0
@nx/js= 21.5.0
@nx/workspace= 21.5.0
@nx/eslint= 21.5.0
@nx/node= 21.5.0
nx= 20.9.0
nx= 20.10.0
nx= 21.6.0
nx= 20.11.0
nx= 21.7.0
nx= 21.8.0
nx= 20.12.0
@nx/node= 20.9.0
@nx/devkit= 20.9.0
@nx/js= 20.9.0
@nx/workspace= 20.9.0
GHSA-224p-v68g-5g8fmediumCVSS: 5.3
2025-08-26

GraphQL Armor Max-Depth Plugin Bypass via fragment caching

@escape.tech/graphql-armor-max-depth<= 2.4.12.4.2
GHSA-hmfr-rx46-4jx2mediumCVSS: 5.3
2025-08-26

GraphQL Armor Max-Depth Plugin Bypass via Introspection Query Obfuscation

@escape.tech/graphql-armor-max-depth<= 2.4.12.4.2
CVE-2025-9287criticalCVSS: 9.1
2025-08-21

cipher-base is missing type checks, leading to hash rewind and passing on crafted data

cipher-base<= 1.0.41.0.5
GHSA-3j63-5h8p-gf7chigh
2025-08-20

x402 SDK vulnerable in outdated versions in resource servers for builders

x402< 0.5.20.5.2
x402-next< 0.5.20.5.2
x402-express< 0.5.20.5.2
x402-hono< 0.5.20.5.2
Advertisement
CVE-2025-57749mediumCVSS: 6.5
2025-08-20

n8n symlink traversal vulnerability in "Read/Write File" node allows access to restricted files

n8n< 1.106.01.106.0
CVE-2025-54881medium
2025-08-19

Mermaid improperly sanitizes sequence diagram labels leading to XSS

mermaid>= 11.0.0-alpha.1, < 11.10.011.10.0
mermaid>= 10.9.0-rc.1, < 10.9.410.9.4
CVE-2025-54880medium
2025-08-19

Mermaid does not properly sanitize architecture diagram iconText leading to XSS

mermaid>= 11.1.0, < 11.10.011.10.0
CVE-2025-55303mediumCVSS: 6.1
2025-08-19

Astro allows unauthorized third-party images in _image endpoint

@astrojs/node<= 9.1.09.1.1
astro<= 4.16.184.16.19
astro>= 5.0.0-alpha.0, < 5.13.25.13.2
CVE-2025-52478highCVSS: 8.7
2025-08-19

Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source

n8n>= 1.77.0, < 1.98.21.98.2
Advertisement
CVE-2025-55207medium
2025-08-15

@astrojs/node's trailing slash handling causes open redirect issue

@astrojs/node<= 9.4.09.4.1
CVE-2025-55164high
2025-08-12

content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE

content-security-policy-parser< 0.6.00.6.0
CVE-2025-55008highCVSS: 7.1
2025-08-08

The AuthKit React Router Library rendered sensitive auth data in HTML

@workos-inc/authkit-react-router< 0.7.00.7.0
CVE-2025-54793medium
2025-08-07

Astros's duplicate trailing slash feature leads to an open redirection security issue

astro>= 5.2.0, < 5.12.85.12.8
CVE-2025-54798lowCVSS: 2.5
2025-08-06

tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

tmp<= 0.2.30.2.4
Advertisement
CVE-2025-54387medium
2025-08-04

IPX Allows Path Traversal via Prefix Matching Bypass

ipx< 1.3.21.3.2
ipx>= 2.0.0-0, < 2.1.12.1.1
ipx>= 3.0.0, < 3.1.13.1.1
CVE-2025-54782critical
2025-08-01

@nestjs/devtools-integration: CSRF to Sandbox Escape Allows for RCE against JS Developers

@nestjs/devtools-integration<= 0.2.00.2.1
CVE-2025-54419criticalCVSS: 10
2025-07-28

Node-SAML SAML Signature Verification Vulnerability

@node-saml/node-saml<= 5.0.15.1.0
passport-saml<= 3.2.4
@node-saml/passport-saml<= 5.0.15.1.0
CVE-2025-54369critical
2025-07-25

Node-SAML SAML Authentication Bypass

node-saml<= 3.1.2
@node-saml/node-saml<= 5.0.15.1.0
CVE-2025-7783critical
2025-07-21

form-data uses unsafe random function in form-data for choosing boundary

form-data< 2.5.42.5.4
form-data>= 3.0.0, < 3.0.43.0.4
form-data>= 4.0.0, < 4.0.44.0.4
Advertisement
CVE-2025-54313highCVSS: 7.5
2025-07-19

eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code

eslint-config-prettier= 8.10.18.10.2
eslint-config-prettier= 9.1.19.1.2
eslint-config-prettier>= 10.1.6, <= 10.1.710.1.8
eslint-plugin-prettier>= 4.2.2, <= 4.2.34.2.4
synckit= 0.11.90.11.10
@pkgr/core= 0.2.80.2.9
napi-postinstall= 0.3.10.3.2
got-fetch>= 5.1.11, <= 5.1.126.0.0
GHSA-xffm-g5w8-qvg7low
2025-07-18

@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser

@eslint/plugin-kit< 0.3.40.3.4
CVE-2025-53892medium
2025-07-16

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes

vue-i18n>= 9.0.0, < 9.14.59.14.5
vue-i18n>= 10.0.0, < 10.0.810.0.8
vue-i18n>= 11.0.0, < 11.1.1011.1.10
@intlify/core>= 9.0.0, < 9.14.59.14.5
@intlify/core>= 10.0.0, < 10.0.810.0.8
@intlify/core>= 11.0.0, < 11.1.1011.1.10
@intlify/core-base>= 9.0.0, < 9.14.59.14.5
@intlify/core-base>= 10.0.0, < 10.0.810.0.8
@intlify/core-base>= 11.0.0, < 11.1.1011.1.10
@intlify/vue-i18n-core>= 9.2.0, < 9.14.59.14.5
@intlify/vue-i18n-core>= 10.0.0, < 10.0.810.0.8
@intlify/vue-i18n-core>= 11.0.0, < 11.1.1011.1.10
petite-vue-i18n>= 10.0.0, < 10.0.810.0.8
petite-vue-i18n>= 11.0.0, < 11.1.1011.1.10
CVE-2025-53818high
2025-07-15

GitHub Kanban MCP Server vulnerable to Command Injection

@sunwood-ai-labs/github-kanban-mcp-server<= 0.3.0
CVE-2025-53620critical
2025-07-09

Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests

@builder.io/qwik-city< 1.13.01.13.0
Advertisement
CVE-2025-53548highCVSS: 7.5
2025-07-09

@clerk/backend Performs Insufficient Verification of Data Authenticity

@clerk/backend>= 2.0.0, < 2.4.02.4.0
@clerk/astro>= 2.9.0, < 2.10.22.10.2
@clerk/express>= 1.6.0, < 1.7.41.7.4
@clerk/fastify>= 2.3.0, < 2.4.42.4.4
@clerk/nextjs>= 6.2.10, < 6.23.36.23.3
@clerk/nuxt>= 1.7.0, < 1.7.51.7.5
@clerk/react-router>= 1.5.0, < 1.6.41.6.4
@clerk/remix>= 4.8.0, < 4.8.54.8.5
@clerk/tanstack-react-start>= 0.16.0, < 0.18.30.18.3
CVE-2025-59427medium
2025-07-08

Cloudflare Vite plugin exposes secrets over the built-in dev server

@cloudflare/vite-plugin< 1.6.01.6.0
CVE-2025-53372highCVSS: 7.5
2025-07-08

Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection

node-code-sandbox-mcp<= 1.2.01.3.0
CVE-2025-49826highCVSS: 7.5
2025-07-03

Next.JS vulnerability can lead to DoS via cache poisoning

next>= 15.0.4-canary.51, < 15.1.815.1.8
CVE-2025-49005lowCVSS: 3.7
2025-07-03

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

next>= 15.3.0, < 15.3.315.3.3
Advertisement
CVE-2025-52554mediumCVSS: 4.3
2025-07-03

n8n is vulnerable to Improper Authorization through its `/stop` endpoint

n8n< 1.99.11.99.1
CVE-2024-49365high
2025-06-30

tiny-secp256k1 allows for verify() bypass when running in bundled environment

tiny-secp256k1<= 1.1.61.1.7
CVE-2024-49364high
2025-06-30

tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment

tiny-secp256k1<= 1.1.61.1.7
CVE-2025-52573mediumCVSS: 6
2025-06-26

iOS Simulator MCP Command Injection allowed via exec API

ios-simulator-mcp< 1.3.31.3.3
CVE-2025-6547critical
2025-06-23

pbkdf2 silently disregards Uint8Array input, returning static keys

pbkdf2>= 1.0.0, <= 3.1.23.1.3
Advertisement
CVE-2025-6545critical
2025-06-23

pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos

pbkdf2>= 3.0.10, <= 3.1.23.1.3
CVE-2025-6087high
2025-06-16

OpenNext for Cloudflare (opennextjs-cloudflare) has a SSRF vulnerability via /_next/image endpoint

@opennextjs/cloudflare< 1.3.01.3.0
CVE-2025-5897mediumCVSS: 4.3
2025-06-09

@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability

@vue/cli-plugin-pwa<= 5.0.8
CVE-2025-5896mediumCVSS: 4.3
2025-06-09

taro-css-to-react-native Regular Expression Denial of Service vulnerability

taro-css-to-react-native< 4.1.24.1.2
CVE-2025-45001highCVSS: 7.5
2025-06-09

react-native-keys insecurely stores encryption cipher and Base64 chunks

react-native-keys<= 0.7.11
Advertisement
CVE-2025-48947high
2025-06-04

NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies

@auth0/nextjs-auth0>= 4.0.1, <= 4.6.04.6.1
CVE-2025-48068low
2025-05-28

Information exposure in Next.js dev server due to lack of origin verification

next>= 15.0.0, < 15.2.215.2.2
next>= 13.0, < 14.2.3014.2.30
CVE-2024-52588mediumCVSS: 4.9
2025-05-27

Strapi allows Server-Side Request Forgery in Webhook function

@strapi/admin< 4.25.24.25.2
CVE-2025-47935highCVSS: 7.5
2025-05-19

Multer vulnerable to Denial of Service via memory leaks from unclosed streams

multer< 2.0.02.0.0
CVE-2025-32421lowCVSS: 3.7
2025-05-15

Next.js Race Condition to Cache Poisoning

next>= 15.0.0, < 15.1.615.1.6
next>= 0.9.9, < 14.2.2414.2.24
Advertisement
CVE-2025-46653lowCVSS: 3.1
2025-04-26

Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

formidable>= 3.1.1-canary.20211030, < 3.5.33.5.3
formidable>= 2.1.0, < 2.1.32.1.3
GHSA-733v-p3h5-qpq7mediumCVSS: 5.3
2025-04-25

GraphQL Armor Cost-Limit Plugin Bypass via Introspection Query Obfuscation

@escape.tech/graphql-armor-cost-limit< 2.4.22.4.2
CVE-2025-43865highCVSS: 8.2
2025-04-24

React Router allows pre-render data spoofing on React-Router framework mode

react-router>= 7.0.0-pre.0, <= 7.5.17.5.2
CVE-2025-43864highCVSS: 7.5
2025-04-24

React Router allows a DoS via cache poisoning by forcing SPA mode

react-router>= 7.2.0, <= 7.5.17.5.2
CVE-2025-43855high
2025-04-24

tRPC 11 WebSocket DoS Vulnerability

@trpc/server>= 11.0.0, < 11.1.111.1.1
Advertisement
CVE-2025-32388mediumCVSS: 5.4
2025-04-14

@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params

@sveltejs/kit>= 2.0.0, < 2.20.62.20.6
CVE-2025-32395medium
2025-04-11

Vite has an `server.fs.deny` bypass with an invalid `request-target`

vite>= 6.2.0, < 6.2.66.2.6
vite>= 6.1.0, < 6.1.56.1.5
vite>= 6.0.0, < 6.0.156.0.15
vite>= 5.0.0, < 5.4.185.4.18
vite< 4.5.134.5.13
CVE-2025-28269high
2025-04-07

js-object-utilities Vulnerable to Prototype Pollution

js-object-utilities< 2.2.12.2.1
CVE-2025-31486mediumCVSS: 5.3
2025-04-04

Vite allows server.fs.deny to be bypassed with .svg or relative paths

vite>= 6.2.0, < 6.2.56.2.5
vite>= 6.1.0, < 6.1.46.1.4
vite>= 6.0.0, < 6.0.146.0.14
vite>= 5.0.0, < 5.4.175.4.17
vite< 4.5.124.5.12
CVE-2025-3191lowCVSS: 6.1
2025-04-04

React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button

react-draft-wysiwyg<= 1.15.0
Advertisement
CVE-2025-30218low
2025-04-02

Next.js may leak x-middleware-subrequest-id to external hosts

next= 12.3.512.3.6
next= 13.5.913.5.10
next= 14.2.2514.2.26
next= 15.2.315.2.4
CVE-2025-71319highCVSS: 7.5
2025-04-02

image-size Denial of Service via Infinite Loop during Image Processing

image-size>= 1.1.0, < 1.2.11.2.1
image-size>= 2.0.0, < 2.0.22.0.2
CVE-2025-31137highCVSS: 7.5
2025-04-01

Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers

@react-router/express>= 7.0.0, < 7.4.17.4.1
@remix-run/express>= 2.11.1, < 2.16.32.16.3
CVE-2025-26042medium
2025-03-31

Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

uptime-kuma>= 1.15.0, <= 1.23.16
uptime-kuma>= 2.0.0-beta.0, < 2.0.0-beta.22.0.0-beta.2
CVE-2025-30350mediumCVSS: 5.3
2025-03-26

Directus's S3 assets become unavailable after a burst of HEAD requests

@directus/storage-driver-s3>= 9.22.0, < 12.0.112.0.1
directus>= 9.22, < 11.5.011.5.0
Advertisement
CVE-2025-30225mediumCVSS: 5.3
2025-03-26

Directus's S3 assets become unavailable after a burst of malformed transformations

@directus/storage-driver-s3>= 9.22.0, < 12.0.112.0.1
directus>= 9.22.0, < 11.5.011.5.0
CVE-2025-30222low
2025-03-26

Shescape has potential environment variable exposure on Windows with CMD

shescape>= 1.7.2, < 2.1.22.1.2
CVE-2025-29927criticalCVSS: 9.1
2025-03-21

Authorization Bypass in Next.js Middleware

next>= 13.0.0, < 13.5.913.5.9
next>= 14.0.0, < 14.2.2514.2.25
next>= 15.0.0, < 15.2.315.2.3
next>= 12.0.0, < 12.3.512.3.5
CVE-2025-27415highCVSS: 7.5
2025-03-19

Nuxt allows DOS via cache poisoning with payload rendering response

nuxt>= 3.0.0, < 3.16.03.16.0
CVE-2025-30144mediumCVSS: 6.5
2025-03-19

Fast-JWT Improperly Validates iss Claims

fast-jwt< 5.0.65.0.6
Advertisement
CVE-2025-29775critical
2025-03-14

xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment

xml-crypto>= 4.0.0, < 6.0.16.0.1
xml-crypto>= 3.0.0, < 3.2.13.2.1
xml-crypto< 2.1.62.1.6
CVE-2025-29774critical
2025-03-14

xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References

xml-crypto>= 4.0.0, < 6.0.16.0.1
xml-crypto>= 3.0.0, < 3.2.13.2.1
xml-crypto< 2.1.62.1.6
GHSA-h42x-xx2q-6v6gcritical
2025-03-13

Flowise Pre-auth Arbitrary File Upload

flowise<= 2.2.7
CVE-2025-27789mediumCVSS: 6.2
2025-03-11

Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups

@babel/helpers< 7.26.107.26.10
@babel/runtime< 7.26.107.26.10
@babel/runtime-corejs2< 7.26.107.26.10
@babel/runtime-corejs3< 7.26.107.26.10
@babel/helpers>= 8.0.0-alpha.0, < 8.0.0-alpha.168.0.0-alpha.17
@babel/runtime>= 8.0.0-alpha.0, < 8.0.0-alpha.168.0.0-alpha.17
@babel/runtime-corejs2>= 8.0.0-alpha.0, < 8.0.0-alpha.168.0.0-alpha.17
@babel/runtime-corejs3>= 8.0.0-alpha.0, < 8.0.0-alpha.168.0.0-alpha.17
CVE-2025-27597high
2025-03-07

Vue I18n Allows Prototype Pollution in `handleFlatJson`

@intlify/message-resolver>= 9.1.0, < 9.1.119.1.11
@intlify/vue-i18n-core>= 9.2.0, < 9.14.39.14.3
petite-vue-i18n>= 10.0.0, < 10.0.610.0.6
vue-i18n>= 9.1.0, < 9.14.39.14.3
@intlify/core-base>= 9.1.0, < 9.1.119.1.11
@intlify/core>= 9.1.0, < 9.1.119.1.11
@intlify/vue-i18n-core>= 10.0.0-alpha.1, < 10.0.611.1.2
@intlify/vue-i18n-core>= 11.0.0-beta.0, < 11.1.211.1.2
petite-vue-i18n>= 11.0.0-beta.0, < 11.1.211.1.2
vue-i18n>= 10.0.0-alpha.1, < 10.0.610.0.6
vue-i18n>= 11.0.0-beta.0, < 11.1.211.1.2
Advertisement
CVE-2025-27152high
2025-03-07

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

axios>= 1.0.0, < 1.8.21.8.2
axios< 0.30.00.30.0
CVE-2025-25290mediumCVSS: 5.3
2025-02-14

@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

@octokit/request>= 9.0.0-beta.1, < 9.2.19.2.1
@octokit/request>= 1.0.0, < 8.4.18.4.1
CVE-2025-25289mediumCVSS: 5.3
2025-02-14

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

@octokit/request-error>= 1.0.0, < 5.1.15.1.1
@octokit/request-error>= 6.0.0, < 6.1.76.1.7
CVE-2025-25288mediumCVSS: 5.3
2025-02-14

@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

@octokit/plugin-paginate-rest>= 9.3.0-beta.1, < 11.4.111.4.1
@octokit/plugin-paginate-rest>= 1.0.0, < 9.2.29.2.2
CVE-2025-25285mediumCVSS: 5.3
2025-02-14

@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

@octokit/endpoint>= 9.0.5, < 9.0.69.0.6
@octokit/endpoint>= 10.0.0, < 10.1.310.1.3
Advertisement
CVE-2025-25283highCVSS: 7.5
2025-02-12

parse-duration has a Regex Denial of Service that results in event loop delay and out of memory

parse-duration< 2.1.32.1.3
CVE-2025-24876highCVSS: 8.1
2025-02-11

Authentication bypass in @sap/approuter

@sap/approuter>= 2.6.1, < 16.7.216.7.2
CVE-2024-57086highCVSS: 8.2
2025-02-06

node-opcua-alarm-condition prototype pollution vulnerability

node-opcua-alarm-condition< 2.137.02.137.0
CVE-2024-57075highCVSS: 7.5
2025-02-06

eazy-logger prototype pollution

eazy-logger<= 4.0.14.1.0
CVE-2025-24963mediumCVSS: 5.9
2025-02-04

Vitest browser mode serves arbitrary files

@vitest/browser>= 2.0.4, < 2.1.92.1.9
@vitest/browser>= 3.0.0, < 3.0.43.0.4
Advertisement
GHSA-r5w7-f542-q2j4lowCVSS: 3.7
2025-01-28

Potential DoS when using ContextLines integration

@sentry/node>= 8.10.0, < 8.49.08.49.0
@sentry/astro>= 8.10.0, < 8.49.08.49.0
@sentry/aws-serverless>= 8.10.0, < 8.49.08.49.0
@sentry/bun>= 8.10.0, < 8.49.08.49.0
@sentry/google-cloud-serverless>= 8.10.0, < 8.49.08.49.0
@sentry/nestjs>= 8.10.0, < 8.49.08.49.0
@sentry/nextjs>= 8.10.0, < 8.49.08.49.0
@sentry/nuxt>= 8.10.0, < 8.49.08.49.0
@sentry/remix>= 8.10.0, < 8.49.08.49.0
@sentry/solidstart>= 8.10.0, < 8.49.08.49.0
@sentry/sveltekit>= 8.10.0, < 8.49.08.49.0
CVE-2025-24360mediumCVSS: 5.3
2025-01-27

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

@nuxt/vite-builder>= 3.8.1, < 3.15.33.15.3
CVE-2025-23221mediumCVSS: 5.4
2025-01-21

Infinite loop and Blind SSRF found inside the Webfinger mechanism in @fedify/fedify

@fedify/fedify= 1.0.131.0.14
@fedify/fedify= 1.1.101.1.11
@fedify/fedify= 1.2.101.2.11
@fedify/fedify= 1.3.31.3.4
CVE-2025-24010mediumCVSS: 6.5
2025-01-21

Websites were able to send any requests to the development server and read the response in vite

vite>= 6.0.0, <= 6.0.86.0.9
vite>= 5.0.0, <= 5.4.115.4.12
vite<= 4.5.54.5.6
CVE-2025-23206low
2025-01-17

AWS Cloud Development Kit (AWS CDK) IAM OIDC custom resource allows connection to unauthorized OIDC provider

aws-cdk-lib< 2.177.02.177.0
Advertisement
GHSA-m9c9-mc2h-9wjwlow
2025-01-14

Lodestar snappy checksum issue

@lodestar/reqresp< 1.25.01.25.0
CVE-2024-56332mediumCVSS: 5.3
2025-01-03

Next.js Allows a Denial of Service (DoS) with Server Actions

next>= 13.0.0, < 13.5.813.5.8
next>= 14.0.0, < 14.2.2114.2.21
next>= 15.0.0, < 15.1.215.1.2
CVE-2024-56140mediumCVSS: 5.9
2024-12-18

Atro CSRF Middleware Bypass (security.checkOrigin)

astro< 4.16.174.16.17
CVE-2024-51479highCVSS: 7.5
2024-12-17

Next.js authorization bypass vulnerability

next>= 9.5.5, < 14.2.1514.2.15
CVE-2024-55565mediumCVSS: 4.3
2024-12-09

Predictable results in nanoid generation when given non-integer values

nanoid>= 4.0.0, < 5.0.95.0.9
nanoid< 3.3.83.3.8
Advertisement
CVE-2024-53983mediumCVSS: 5.4
2024-12-02

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

@backstage/plugin-scaffolder-node< 0.4.120.4.12
@backstage/plugin-scaffolder-node= 0.5.00.5.1
@backstage/plugin-scaffolder-node= 0.6.00.6.1
CVE-2024-52810medium
2024-12-02

@intlify/shared Prototype Pollution vulnerability

@intlify/shared>= 9.7.0, < 9.14.29.14.2
@intlify/vue-i18n-core>= 9.7.0, < 9.14.29.14.2
vue-i18n>= 9.7.0, < 9.14.29.14.2
petite-vue-i18n>= 10.0.0, < 10.0.510.0.5
@intlify/shared>= 10.0.0, < 10.0.510.0.5
@intlify/vue-i18n-core>= 10.0.0, < 10.0.510.0.5
vue-i18n>= 10.0.0, < 10.0.510.0.5
CVE-2024-52809medium
2024-12-02

vue-i18n has cross-site scripting vulnerability with prototype pollution

@intlify/core-base>= 9.3.0, < 9.14.29.14.2
vue-i18n>= 9.3.0, < 9.14.29.14.2
@intlify/core>= 9.3.0, < 9.14.29.14.2
@intlify/vue-i18n-core>= 9.3.0, < 9.14.29.14.2
petite-vue-i18n>= 10.0.0, < 10.0.510.0.5
@intlify/core-base>= 10.0.0, < 10.0.510.0.5
vue-i18n>= 10.0.0, < 10.0.510.0.5
@intlify/core>= 10.0.0, < 10.0.510.0.5
@intlify/vue-i18n-core>= 10.0.0, < 10.0.510.0.5
CVE-2024-21539lowCVSS: 3.5
2024-11-15

Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit

@eslint/plugin-kit< 0.2.30.2.3
CVE-2024-49362highCVSS: 7.7
2024-11-14

Remote Code Execution on click of <a> Link in markdown preview

joplin= 3.0.03.1.0
Advertisement
CVE-2024-49770highCVSS: 7.5
2024-11-01

Path traversal in oak allows transfer of hidden files within the served root directory

@oakserver/oak<= 14.1.0
CVE-2020-26311mediumCVSS: 7.5
2024-10-26

useragent Regular Expression Denial of Service vulnerability

useragent<= 2.3.0
CVE-2024-48930high
2024-10-21

secp256k1-node allows private key extraction over ECDH

secp256k1= 5.0.05.0.1
secp256k1>= 4.0.0, < 4.0.44.0.4
secp256k1<= 3.8.03.8.1
CVE-2024-21536highCVSS: 7.5
2024-10-19

Denial of service in http-proxy-middleware

http-proxy-middleware< 2.0.72.0.7
http-proxy-middleware>= 3.0.0, < 3.0.33.0.3
CVE-2024-9506lowCVSS: 3.7
2024-10-15

ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

vue>= 2.0.0-alpha.1, < 3.0.0-alpha.03.0.0-alpha.0
Advertisement
CVE-2024-47824high
2024-10-15

Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room

matrix-react-sdk>= 3.18.0, < 3.102.03.102.0
CVE-2024-48914criticalCVSS: 9.1
2024-10-15

Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy

@vendure/asset-server-plugin< 2.3.32.3.3
@vendure/asset-server-plugin>= 3.0.0, < 3.0.53.0.5
CVE-2024-48948lowCVSS: 4.8
2024-10-15

Valid ECDSA signatures erroneously rejected in Elliptic

elliptic< 6.6.06.6.0
CVE-2024-47831mediumCVSS: 5.9
2024-10-14

Denial of Service condition in Next.js image optimization

next>= 10.0.0, < 14.2.714.2.7
CVE-2024-21534criticalCVSS: 9.8
2024-10-11

JSONPath Plus Remote Code Execution (RCE) Vulnerability

org.webjars.npm:jsonpath-plus<= 6.0.1
jsonpath-plus< 10.2.010.2.0
Advertisement
CVE-2024-48949lowCVSS: 5.3
2024-10-10

Elliptic's verify function omits uniqueness validation

elliptic< 6.5.66.5.6
CVE-2024-21532mediumCVSS: 7.3
2024-10-08

ggit is vulnerable to Command Injection via the fetchTags(branch) API

ggit<= 2.4.12
CVE-2024-45277mediumCVSS: 4.3
2024-10-08

SAP HANA Node.js client package vulnerable to Prototype Pollution

@sap/hana-client>= 2.0.0, < 2.21.312.21.31
GHSA-pf56-h9qf-rxq4mediumCVSS: 6.1
2024-10-07

Saltcorn Server Stored Cross-Site Scripting (XSS) in event logs page

@saltcorn/server< 1.0.0-beta.161.0.0-beta.16
CVE-2024-47066mediumCVSS: 9
2024-09-23

lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

@lobehub/chat<= 1.19.121.19.13
Advertisement
CVE-2024-47061highCVSS: 8.3
2024-09-20

Plate allows arbitrary DOM attributes in element.attributes and leaf.attributes

@udecode/plate-core>= 37.0.0, < 38.0.638.0.6
@udecode/plate-core>= 22.0.0, < 36.5.936.5.9
@udecode/plate-core< 21.5.121.5.1
CVE-2024-46982highCVSS: 7.5
2024-09-17

Next.js Cache Poisoning

next>= 13.5.1, < 13.5.713.5.7
next>= 14.0.0, < 14.2.1014.2.10
CVE-2024-45812mediumCVSS: 6.4
2024-09-17

Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS

vite>= 4.0.0, < 4.5.44.5.4
vite>= 5.4.0, < 5.4.65.4.6
vite>= 5.3.0, < 5.3.65.3.6
vite>= 5.2.0, < 5.2.145.2.14
vite< 3.2.113.2.11
vite>= 5.0.0, < 5.1.85.1.8
CVE-2024-21528highCVSS: 5.9
2024-09-10

node-gettext vulnerable to Prototype Pollution

node-gettext<= 3.0.0
CVE-2024-43373mediumCVSS: 7.7
2024-08-14

webcrack has an Arbitrary File Write Vulnerability on Windows when Parsing and Saving a Malicious Bundle

webcrack<= 2.14.02.14.1
Advertisement
CVE-2024-42347mediumCVSS: 4.1
2024-08-06

Matrix SDK for React's URL preview setting for a room is controllable by the homeserver

matrix-react-sdk< 3.105.13.105.1
CVE-2023-49785criticalCVSS: 9.1
2024-08-05

NextChat has full-read SSRF and XSS vulnerability in /api/cors endpoint

nextchat<= 2.11.2
CVE-2024-34344criticalCVSS: 8.8
2024-08-05

Nuxt vulnerable to remote code execution via the browser when running the test locally

nuxt>= 3.4.0, < 3.12.43.12.4
CVE-2024-34343mediumCVSS: 6.3
2024-08-05

nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR

nuxt< 3.12.43.12.4
CVE-2024-23657highCVSS: 8.8
2024-08-05

Nuxt Devtools has a Path Traversal: '../filedir'

@nuxt/devtools< 1.3.91.3.9
Advertisement
CVE-2024-42461lowCVSS: 5.3
2024-08-02

Elliptic allows BER-encoded signatures

elliptic>= 5.2.1, <= 6.5.66.5.7
CVE-2024-42460lowCVSS: 5.3
2024-08-02

Elliptic's ECDSA missing check for whether leading bit of r and s is zero

elliptic>= 2.0.0, <= 6.5.66.5.7
CVE-2024-42459lowCVSS: 5.3
2024-08-02

Elliptic's EDDSA missing signature length check

elliptic>= 4.0.0, <= 6.5.66.5.7
CVE-2024-41945lowCVSS: 3.1
2024-07-30

The fuels-ts typescript SDK has no awareness of to-be-spent transactions

@fuel-ts/account< 0.93.00.93.0
CVE-2024-6783mediumCVSS: 4.2
2024-07-23

vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)

vue-template-compiler>= 2.0.0, < 3.0.0
Advertisement
CVE-2024-41655highCVSS: 7.5
2024-07-23

(ReDoS) Regular Expression Denial of Service in tf2-item-format

tf2-item-format>= 4.2.6, <= 5.9.135.9.14
CVE-2024-39693highCVSS: 7.5
2024-07-10

Next.js Denial of Service (DoS) condition

next>= 13.3.1, < 13.5.013.5.0
CVE-2024-21525highCVSS: 8.3
2024-07-10

node-twain vulnerable to Improper Check or Handling of Exceptional Conditions

node-twain<= 0.0.16
CVE-2024-21524highCVSS: 8.2
2024-07-10

node-stringbuilder vulnerable to Out-of-bounds Read

node-stringbuilder<= 2.2.7
CVE-2024-38372lowCVSS: 2
2024-07-09

Undici vulnerable to data leak when using response.arrayBuffer()

undici>= 6.14.0, < 6.19.26.19.2
Advertisement
CVE-2024-39687mediumCVSS: 7.2
2024-07-05

Server Side Request Forgery (SSRF) attack in Fedify

@fedify/fedify< 0.9.20.9.2
@fedify/fedify>= 0.10.0, < 0.10.20.10.2
@fedify/fedify>= 0.11.0, < 0.11.20.11.2
CVE-2024-39943highCVSS: 9.9
2024-07-05

rejetto HFS vulnerable to OS Command Execution by remote authenticated users

hfs< 0.52.100.52.10
CVE-2024-38993criticalCVSS: 9.8
2024-07-01

jsonic was discovered to contain a prototype pollution via the function empty.

jsonic<= 2.12.1
CVE-2024-38527mediumCVSS: 5.4
2024-06-26

Cross-site Scripting in ZenUML

@zenuml/core< 3.23.253.23.25
CVE-2024-38355mediumCVSS: 7.3
2024-06-19

socket.io has an unhandled 'error' event

socket.io< 2.5.02.5.1
socket.io>= 3.0.0, < 4.6.24.6.2
Advertisement
CVE-2024-34065highCVSS: 7.1
2024-06-12

@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass

@strapi/plugin-users-permissions< 4.24.24.24.2
CVE-2024-31217mediumCVSS: 5.3
2024-06-12

@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling

@strapi/plugin-upload< 4.22.04.22.0
CVE-2024-35255mediumCVSS: 5.5
2024-06-11

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

azure-identity< 1.16.11.16.1
@azure/identity< 4.2.14.2.1
com.azure:azure-identity< 1.12.21.12.2
Azure.Identity< 1.11.41.11.4
@azure/msal-node>= 2.7.0, < 2.9.22.9.2
com.microsoft.azure:msal4j>= 1.14.4-beta, < 1.15.11.15.1
Microsoft.Identity.Client>= 4.49.1, < 4.60.44.60.4
Microsoft.Identity.Client>= 4.61.0, < 4.61.34.61.3
github.com/Azure/azure-sdk-for-go/sdk/azidentity< 1.6.0-beta.4.0.20240610221955-50774cd970991.6.0-beta.4.0.20240610221955-50774cd97099
CVE-2024-29415highCVSS: 8.1
2024-06-02

ip SSRF improper categorization in isPublic

ip<= 2.0.1
CVE-2023-49781highCVSS: 7.3
2024-05-13

NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue

nocodb<= 0.202.80.202.9
Advertisement
CVE-2024-34708mediumCVSS: 4.9
2024-05-13

Directus allows redacted data extraction on the API through "alias"

directus< 10.11.010.11.0
CVE-2024-34351highCVSS: 7.5
2024-05-09

Next.js Server-Side Request Forgery in Server Actions

next>= 13.4.0, < 14.1.114.1.1
CVE-2024-34350highCVSS: 7.5
2024-05-09

Next.js Vulnerable to HTTP Request Smuggling

next>= 13.4.0, < 13.5.113.5.1
CVE-2024-34342highCVSS: 7.1
2024-05-07

react-pdf vulnerable to arbitrary JavaScript execution upon opening a malicious PDF with PDF.js

react-pdf< 7.7.37.7.3
react-pdf>= 8.0.0, < 8.0.28.0.2
CVE-2024-34393criticalCVSS: 8.1
2024-05-02

libxmljs2 type confusion vulnerability when parsing specially crafted XML

libxmljs2<= 0.33.0
Advertisement
CVE-2024-34394criticalCVSS: 8.1
2024-05-02

libxmljs2 vulnerable to type confusion when parsing specially crafted XML

libxmljs2<= 0.35.0
CVE-2024-34392criticalCVSS: 8.1
2024-05-02

libxmljs vulnerable to type confusion when parsing specially crafted XML

libxmljs<= 1.0.11
CVE-2024-34391criticalCVSS: 8.1
2024-05-02

libxmljs vulnerable to type confusion when parsing specially crafted XML

libxmljs<= 1.0.11
CVE-2024-32962criticalCVSS: 10
2024-05-01

xml-crypto vulnerable to XML signature verification bypass due improper verification of signature/signature spoofing

xml-crypto>= 4.0.0, < 6.0.06.0.0
CVE-2023-36821highCVSS: 8.8
2024-05-01

Uptime Kuma vulnerable to authenticated remote code execution via malicious plugin installation

uptime-kuma<= 1.22.01.22.1
Advertisement
CVE-2024-33883mediumCVSS: 4
2024-04-28

ejs lacks certain pollution protection

ejs< 3.1.103.1.10
CVE-2024-21511criticalCVSS: 9.8
2024-04-23

MySQL2 for Node Arbitrary Code Injection

mysql2< 3.9.73.9.7
CVE-2024-34347highCVSS: 8.3
2024-04-22

@hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE

@hoppscotch/cli>= 0.5.0, < 0.8.00.8.0
CVE-2024-32652highCVSS: 7.5
2024-04-19

@hono/node-server has Denial of Service risk when receiving Host header that cannot be parsed

@hono/node-server>= 1.3.0, < 1.10.11.10.1
GHSA-82jv-9wjw-pqh6low
2024-04-17

Prototype pollution in emit function

derby<= 2.3.12.3.2
derby>= 3.0.0, <= 3.0.13.0.2
derby>= 4.0.0-beta1, <= 4.0.0-beta.104.0.0-beta.11
Advertisement
CVE-2021-4438mediumCVSS: 5.3
2024-04-07

React Native Sms User Consent Intent Redirection Vulnerability

@kyivstarteam/react-native-sms-user-consent< 1.1.51.1.5
CVE-2024-29900highCVSS: 7.5
2024-03-29

@electron/packager's build process memory potentially leaked into final executable

@electron/packager= 18.3.018.3.1
CVE-2024-29041mediumCVSS: 6.1
2024-03-25

Express.js Open Redirect in malformed URLs

express< 4.19.24.19.2
express>= 5.0.0-alpha.1, < 5.0.0-beta.35.0.0-beta.3
CVE-2024-28863mediumCVSS: 6.5
2024-03-22

Denial of service while parsing a tar file due to lack of folders count validation

node-tar< 6.2.16.2.1
tar< 6.2.16.2.1
CVE-2024-28176mediumCVSS: 5.3
2024-03-07

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext

jose>= 3.0.0, <= 4.15.44.15.5
jose-node-cjs-runtime<= 4.15.44.15.5
jose-node-esm-runtime<= 4.15.44.15.5
jose< 2.0.72.0.7
Advertisement
CVE-2024-27922criticalCVSS: 9.8
2024-03-05

HTTP Handling Vulnerability in the Bare server

@tomphttp/bare-server-node< 2.0.22.0.2
GHSA-68c2-4mpx-qh95low
2024-03-01

Potential leakage of Sentry auth tokens by React Native SDK with Expo plugin

@sentry/react-native>= 5.16.0, <= 5.19.05.19.1
CVE-2024-26135highCVSS: 8.3
2024-02-21

MeshCentral cross-site websocket hijacking (CSWSH) vulnerability

meshcentral< 1.1.211.1.21
GHSA-w4hv-vmv9-hgcrhighCVSS: 8.3
2024-02-16

GitHub Security Lab (GHSL) Vulnerability Report, scrypted: `GHSL-2023-218`, `GHSL-2023-219`

@scrypted/server<= 0.56.0
@scrypted/core<= 0.1.142
CVE-2024-25466highCVSS: 7.3
2024-02-16

React Native Document Picker Directory Traversal vulnerability

react-native-document-picker>= 9.0.0, < 9.1.19.1.1
react-native-document-picker< 8.2.28.2.2
Advertisement
CVE-2024-24828mediumCVSS: 6.6
2024-02-09

Pkg Local Privilege Escalation

pkg<= 5.8.1
CVE-2024-24556highCVSS: 7.2
2024-01-30

@urql/next Cross-site Scripting vulnerability

@urql/next< 1.1.11.1.1
CVE-2024-24558highCVSS: 8.2
2024-01-30

react-query-streamed-hydration Cross-site Scripting vulnerability

@tanstack/react-query-next-experimental>= 5.0.0, < 5.18.05.18.0
CVE-2024-23641highCVSS: 7.5
2024-01-24

Sending a GET or HEAD request with a body crashes SvelteKit

@sveltejs/kit>= 2.0.0, < 2.4.32.4.3
@sveltejs/adapter-node>= 2.0.0, < 2.1.22.1.2
@sveltejs/adapter-node>= 3.0.0, < 3.0.33.0.3
@sveltejs/adapter-node= 4.0.04.0.1
CVE-2024-23340mediumCVSS: 5.3
2024-01-23

@hono/node-server cannot handle "double dots" in URL

@hono/node-server>= 1.3.0, < 1.4.11.4.1
Advertisement
GHSA-wg2x-rv86-mmpxhigh
2024-01-19

SPV Merkle proof malleability allows the maintainer to prove invalid transactions

@keep-network/tbtc-v2<= 1.5.11.5.2
CVE-2024-23331highCVSS: 7.5
2024-01-19

Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

vite>= 2.7.0, <= 2.9.162.9.17
vite>= 3.0.0, <= 3.2.73.2.8
vite>= 4.0.0, <= 4.5.14.5.2
vite>= 5.0.0, <= 5.0.115.0.12
CVE-2024-22206criticalCVSS: 9
2024-01-12

@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)

@clerk/nextjs>= 4.7.0, < 4.29.34.29.3
CVE-2024-21668mediumCVSS: 4.4
2024-01-09

react-native-mmkv Insertion of Sensitive Information into Log File vulnerability

react-native-mmkv< 2.11.02.11.0
GHSA-cfxh-frx4-9gjgcritical
2023-12-15

Cross-site Scripting in @spscommerce/ds-react

@spscommerce/ds-react>= 4.12.2, < 7.17.47.17.4
Advertisement
CVE-2023-50710mediumCVSS: 4.2
2023-12-15

Named path parameters can be overridden in TrieRouter

hono< 3.11.73.11.7
CVE-2023-49583criticalCVSS: 9.1
2023-12-12

Escalation of privileges in @sap/xssec

@sap/xssec< 3.6.03.6.0
CVE-2023-49799highCVSS: 7.5
2023-12-12

SSRF & Credentials Leak

nuxt-api-party< 0.22.00.22.0
CVE-2023-49800highCVSS: 7.5
2023-12-11

DOS by abusing `fetchOptions.retry`.

nuxt-api-party< 0.22.10.22.1
CVE-2023-49293mediumCVSS: 6.1
2023-12-05

Vite XSS vulnerability in `server.transformIndexHtml` via URL payload

vite>= 4.4.0, < 4.4.124.4.12
vite= 4.5.04.5.1
vite>= 5.0.0, < 5.0.55.0.5
Advertisement
CVE-2023-48711lowCVSS: 3.7
2023-11-27

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

google-translate-api-browser< 4.1.04.1.0
CVE-2023-49210criticalCVSS: 9.8
2023-11-23

openssl npm package vulnerable to command execution

openssl<= 2.0.0
CVE-2023-48309mediumCVSS: 5.3
2023-11-20

Possible user mocking that bypasses basic authentication

next-auth< 4.24.54.24.5
CVE-2023-48223mediumCVSS: 5.9
2023-11-20

JWT Algorithm Confusion

fast-jwt< 3.3.23.3.2
CVE-2023-48238highCVSS: 7.5
2023-11-17

json-web-token library is vulnerable to a JWT algorithm confusion attack

json-web-token<= 3.1.14.0.0
Advertisement
CVE-2023-46729mediumCVSS: 6.1
2023-11-09

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

@sentry/nextjs>= 7.26.0, < 7.77.07.77.0
CVE-2023-45827highCVSS: 7.3
2023-11-03

Prototype Pollution(PP) vulnerability in setByPath

@clickbar/dot-diver< 1.0.21.0.2
CVE-2023-39345highCVSS: 7.6
2023-11-03

Unauthorized Access to Private Fields in User Registration API

@strapi/plugin-users-permissions>= 4.0.0, < 4.13.14.13.1
@strapi/strapi>= 4.0.0, < 4.13.14.13.1
CVE-2023-39619highCVSS: 7.5
2023-10-25

Inefficient Regular Expression Complexity in node-email-check

node-email-check<= 1.0.4
CVE-2023-46298low
2023-10-22

Next.js missing cache-control header may lead to CDN caching empty reply

next>= 0.9.9, < 13.4.20-canary.1313.4.20-canary.13
Advertisement
CVE-2023-46115highCVSS: 8.4
2023-10-20

Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables

tauri-cli>= 2.0.0-alpha.0, < 2.0.0-alpha.162.0.0-alpha.16
@tauri-apps/cli>= 2.0.0-alpha.0, < 2.0.0-alpha.162.0.0-alpha.16
@tauri-apps/cli>= 1.0.0, < 1.5.61.5.6
tauri-cli>= 1.0.0, < 1.5.61.5.6
CVE-2023-45820highCVSS: 7.5
2023-10-19

Directus crashes on invalid WebSocket message

directus>= 10.4.0, < 10.6.210.6.2
CVE-2023-45818mediumCVSS: 6.1
2023-10-19

TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin

tinymce>= 6.0.0, < 6.7.16.7.1
TinyMCE>= 6.0.0, < 6.7.16.7.1
tinymce/tinymce>= 6.0.0, < 6.7.16.7.1
tinymce< 5.10.85.10.8
TinyMCE< 5.10.85.10.8
tinymce/tinymce< 5.10.85.10.8
CVE-2023-5654mediumCVSS: 6.5
2023-10-19

React Developer Tools extension Improper Authorization vulnerability

react-devtools-core< 4.28.44.28.4
CVE-2023-45811highCVSS: 7.8
2023-10-18

Synchrony deobfuscator prototype pollution vulnerability leading to arbitrary code execution

deobfuscator>= 2.0.1, < 2.4.42.4.4
Advertisement
CVE-2023-26155highCVSS: 7.3
2023-10-14

node-qpdf vulnerable to command injection

node-qpdf<= 1.0.3
CVE-2023-38507highCVSS: 7.3
2023-09-13

Strapi Improper Rate Limiting vulnerability

@strapi/admin< 4.12.14.12.1
@strapi/plugin-users-permissions< 4.12.14.12.1
GHSA-j5g3-5c8r-7qfxlow
2023-08-30

Prevent logging invalid header values

@apollo/server< 4.9.34.9.3
apollo-server-core>= 3.0.0, < 3.12.13.12.1
apollo-server-core< 2.26.12.26.1
CVE-2021-32050mediumCVSS: 4.2
2023-08-29

MongoDB Driver may publish events containing authentication-related data

mongodb/mongodb>= 1.0.0, < 1.9.21.9.2
mongodb>= 3.6.0, < 3.6.103.6.10
mongodb>= 4.0.0, < 4.17.04.17.0
mongodb>= 5.0.0, < 5.8.05.8.0
github.com/mongodb/mongo-swift-driver>= 1.0.0, < 1.1.11.1.1
CVE-2023-41167mediumCVSS: 4.8
2023-08-24

@webiny/react-rich-text-renderer vulnerable to insecure rendering of rich text content

@webiny/react-rich-text-renderer<= 5.37.15.37.2
Advertisement
CVE-2023-40185highCVSS: 8.6
2023-08-22

Shescape on Windows escaping may be bypassed in threaded context

shescape< 1.7.41.7.4
CVE-2023-40178mediumCVSS: 5.3
2023-08-21

@node-saml/node-saml's validatePostRequestAsync does not include checkTimestampsValidityError

@node-saml/node-saml< 4.0.54.0.5
CVE-2023-26140mediumCVSS: 6.1
2023-08-16

@excalidraw/excalidraw Cross-site Scripting vulnerability

@excalidraw/excalidraw< 0.15.30.15.3
CVE-2021-29057mediumCVSS: 6.5
2023-08-11

SUCHMOKUO node-worker-threads-pool denial of service Vulnerability

node-worker-threads-pool<= 1.4.3
CVE-2023-39532criticalCVSS: 9.8
2023-08-09

SES's dynamic import and spread operator provides possible path to arbitrary exfiltration and execution

ses>= 0.13.0, < 0.13.50.13.5
ses>= 0.14.0, < 0.14.50.14.5
ses>= 0.15.0, < 0.15.240.15.24
ses= 0.16.00.16.1
ses= 0.17.00.17.1
ses>= 0.18.0, < 0.18.70.18.7
Advertisement
CVE-2023-37478highCVSS: 7.5
2023-08-01

pnpm incorrectly parses tar archives relative to specification

pnpm< 7.33.47.33.4
@pnpm/exe< 7.33.47.33.4
@pnpm/linux-arm64< 7.33.47.33.4
@pnpm/linux-x64< 7.33.47.33.4
@pnpm/linuxstatic-arm64< 7.33.47.33.4
@pnpm/macos-arm64< 7.33.47.33.4
@pnpm/macos-x64< 7.33.47.33.4
@pnpm/win-x64< 7.33.47.33.4
@pnpm/cafs< 7.0.57.0.5
pnpm>= 8.0.0, < 8.6.88.6.8
@pnpm/exe>= 8.0.0, < 8.6.88.6.8
@pnpm/linux-arm64>= 8.0.0, < 8.6.88.6.8
@pnpm/linux-x64>= 8.0.0, < 8.6.88.6.8
@pnpm/linuxstatic-arm64>= 8.0.0, < 8.6.88.6.8
@pnpm/macos-arm64>= 8.0.0, < 8.6.88.6.8
@pnpm/macos-x64>= 8.0.0, < 8.6.88.6.8
@pnpm/win-x64>= 8.0.0, < 8.6.88.6.8
CVE-2023-38504highCVSS: 7.5
2023-07-27

DoS vulnerability for apps with sockets enabled

sails< 1.5.71.5.7
CVE-2023-37259mediumCVSS: 6.1
2023-07-18

matrix-react-sdk vulnerable to XSS in Export Chat feature

matrix-react-sdk>= 3.32.0, < 3.76.03.76.0
CVE-2023-37903criticalCVSS: 9.8
2023-07-13

vm2 Sandbox Escape vulnerability

vm2<= 3.9.19
CVE-2023-30589highCVSS: 7.5
2023-07-01

llhttp vulnerable to HTTP request smuggling

llhttp< 8.1.18.1.1
Advertisement
CVE-2023-35931lowCVSS: 3.1
2023-06-22

Shescape potential environment variable exposure on Windows with CMD

shescape< 1.7.11.7.1
CVE-2023-34459mediumCVSS: 5.3
2023-06-19

OpenZeppelin Contracts using MerkleProof multiproofs may allow proving arbitrary leaves for specific trees

@openzeppelin/contracts>= 4.7.0, < 4.9.24.9.2
@openzeppelin/contracts-upgradeable>= 4.7.0, < 4.9.24.9.2
CVE-2020-36732mediumCVSS: 5.3
2023-06-12

crypto-js uses insecure random numbers

crypto-js= 3.2.03.2.1
CVE-2023-34232highCVSS: 7.3
2023-06-09

Snowflake NodeJS Driver vulnerable to Command Injection

snowflake-sdk< 1.6.211.6.21
CVE-2023-34092highCVSS: 7.5
2023-06-06

Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)

vite< 2.9.162.9.16
vite>= 3.0.2, < 3.2.73.2.7
vite>= 4.0.0, < 4.0.54.0.5
vite>= 4.1.0, < 4.1.54.1.5
vite>= 4.2.0, < 4.2.34.2.3
vite>= 4.3.0, < 4.3.94.3.9
Advertisement
CVE-2023-26127highCVSS: 7.8
2023-05-27

n158 vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function

n158<= 1.4.1
CVE-2023-26128highCVSS: 8.4
2023-05-27

keep-module-latest vulnerable to Command Injection due to missing input sanitization

keep-module-latest<= 1.0.1
CVE-2023-26129highCVSS: 7.8
2023-05-27

bwm-ng vulnerable to command injection

bwm-ng<= 0.1.1
GHSA-7cgc-fjv4-52x6critical
2023-05-24

Malware in pre-build binaries of bignum

bignum>= 0.12.2, < 0.13.10.13.1
CVE-2023-32695mediumCVSS: 7.3
2023-05-23

Insufficient validation when decoding a Socket.IO packet

socket.io-parser>= 3.4.0, < 3.4.33.4.3
socket.io-parser>= 4.0.4, < 4.2.34.2.3
socket.io-parser< 3.3.43.3.4
Advertisement
CVE-2023-32313mediumCVSS: 5.3
2023-05-17

vm2 vulnerable to Inspect Manipulation

vm2< 3.9.183.9.18
CVE-2023-27562mediumCVSS: 6.5
2023-05-10

n8n Directory Traversal vulnerability

n8n< 0.216.10.216.1
CVE-2023-27564highCVSS: 7.5
2023-05-10

n8n Information Disclosure vulnerability

n8n< 0.216.10.216.1
CVE-2023-27563highCVSS: 8.8
2023-05-10

n8n Privilege Escalation vulnerability

n8n< 0.216.10.216.1
CVE-2023-31125mediumCVSS: 6.5
2023-05-03

engine.io Uncaught Exception vulnerability

engine.io>= 5.1.0, < 6.4.26.4.2
Advertisement
CVE-2023-30846criticalCVSS: 9.1
2023-04-27

Potential leak of authentication data to 3rd parties

typed-rest-client< 1.8.01.8.0
CVE-2023-30609highCVSS: 8.2
2023-04-25

HTML injection in search results via plaintext message highlighting

matrix-react-sdk< 3.71.03.71.0
CVE-2023-29566criticalCVSS: 9.8
2023-04-24

Remote code execution in dawnsparks-node-tesseract

dawnsparks-node-tesseract< 0.4.10.4.1
CVE-2023-30543mediumCVSS: 5.2
2023-04-18

`chainId` may be outdated if user changes chains as part of connection in @web3-react

@web3-react/coinbase-wallet>= 6.0.0, < 8.0.35-beta.08.0.35-beta.0
@web3-react/eip1193>= 6.0.0, < 8.0.27-beta.08.0.27-beta
@web3-react/metamask>= 6.0.0, < 8.0.30-beta.08.0.30-beta.0
@web3-react/walletconnect>= 6.0.0, < 8.0.37-beta.08.0.37-beta.0
CVE-2023-29017criticalCVSS: 9.8
2023-04-07

vm2 vulnerable to sandbox escape

vm2< 3.9.153.9.15
Advertisement
CVE-2023-29003highCVSS: 8.8
2023-04-04

SvelteKit vulnerable to Cross-Site Request Forgery

@sveltejs/kit< 1.15.11.15.1
CVE-2023-28427highCVSS: 8.2
2023-03-30

Prototype pollution in matrix-js-sdk (part 2)

matrix-js-sdk< 24.0.024.0.0
CVE-2023-28103highCVSS: 8.2
2023-03-29

Prototype pollution in matrix-react-sdk

matrix-react-sdk< 3.69.03.69.0
CVE-2022-36060highCVSS: 7.2
2023-03-28

matrix-react-sdk Prototype pollution vulnerability

matrix-react-sdk< 3.53.03.53.0
GHSA-2w9p-xf5h-qwj3high
2023-03-27

Duplicate Advisory: pullit Command Injection vulnerability

pullit< 1.4.0
Advertisement
CVE-2023-28444criticalCVSS: 9.9
2023-03-24

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

angular-server-side-configuration>= 15.0.0, < 15.1.015.1.0
CVE-2023-26113highCVSS: 7.5
2023-03-18

Collection.js vulnerable to Prototype Pollution

collection.js< 6.8.16.8.1
CVE-2023-28155mediumCVSS: 6.1
2023-03-16

Server-Side Request Forgery in Request

request<= 2.88.2
@cypress/request<= 2.88.123.0.0
CVE-2023-27490highCVSS: 8.1
2023-03-13

Missing proper state, nonce and PKCE checks for OAuth authentication

next-auth< 4.20.14.20.1
CVE-2022-43441highCVSS: 8.1
2023-03-13

sqlite vulnerable to code execution due to Object coercion

sqlite3>= 5.0.0, < 5.1.55.1.5
Advertisement
CVE-2023-26109criticalCVSS: 9.8
2023-03-09

node-bluetooth-serial-port is vulnerable to Buffer Overflow via the findSerialPortChannel

node-bluetooth-serial-port<= 2.2.7
CVE-2023-26110criticalCVSS: 9.8
2023-03-09

node-bluetooth is vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation

node-bluetooth<= 1.2.6
CVE-2023-1283criticalCVSS: 9.8
2023-03-09

builderio/qwik is vulnerable to code injection

@builder.io/qwik< 0.21.00.21.0
CVE-2023-26111highCVSS: 7.5
2023-03-06

node-static and @nubosoftware/node-static vulnerable to Directory Traversal

node-static<= 0.7.11
@nubosoftware/node-static<= 0.7.11
CVE-2022-2237mediumCVSS: 6.1
2023-03-02

keycloak-connect contains Open redirect vulnerability in the Node.js adapter

keycloak-connect< 21.0.121.0.1
Advertisement
CVE-2023-25653highCVSS: 7.5
2023-02-16

Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)

node-jose< 2.2.02.2.0
CVE-2023-25572mediumCVSS: 5.4
2023-02-14

Cross-Site-Scripting attack on `<RichTextField>`

react-admin< 3.19.123.19.12
react-admin>= 4.0.0, < 4.7.64.7.6
ra-ui-materialui>= 4.0.0, < 4.7.64.7.6
ra-ui-materialui< 3.19.123.19.12
CVE-2020-36651highCVSS: 7.5
2023-01-18

Path Traversal in web-node-server

web-node-server< 0.0.110.0.11
CVE-2020-36650highCVSS: 8
2023-01-11

gry vulnerable to Command Injection

gry< 6.0.06.0.0
CVE-2023-0163highCVSS: 8.4
2023-01-10

convict vulnerable to Prototype Pollution

convict< 6.2.46.2.4
Advertisement
CVE-2017-20165highCVSS: 7.5
2023-01-09

debug Inefficient Regular Expression Complexity vulnerability

debug< 2.6.92.6.9
debug>= 3.0.0, < 3.1.03.1.0
CVE-2018-25053mediumCVSS: 6.1
2022-12-28

Json2html vulnerable to cross-site scripting

node-json2html< 1.2.01.2.0
CVE-2022-23541mediumCVSS: 5
2022-12-22

jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC

jsonwebtoken<= 8.5.19.0.0
CVE-2022-23529highCVSS: 7.6
2022-12-22

jsonwebtoken has insecure input validation in jwt.verify function

jsonwebtoken<= 8.5.19.0.0
CVE-2020-36618criticalCVSS: 9.8
2022-12-19

FurqanSoftware/node-whois vulnerable to Prototype Pollution

whois< 2.13.62.13.6
Advertisement
CVE-2022-24999highCVSS: 7.5
2022-11-27

qs vulnerable to Prototype Pollution

qs>= 6.10.0, < 6.10.36.10.3
qs>= 6.9.0, < 6.9.76.9.7
qs>= 6.8.0, < 6.8.36.8.3
qs>= 6.7.0, < 6.7.36.7.3
qs>= 6.6.0, < 6.6.16.6.1
qs>= 6.5.0, < 6.5.36.5.3
qs>= 6.4.0, < 6.4.16.4.1
qs>= 6.3.0, < 6.3.36.3.3
qs< 6.2.46.2.4
CVE-2022-41940mediumCVSS: 6.5
2022-11-21

Uncaught exception in engine.io

engine.io< 3.6.13.6.1
engine.io>= 4.0.0, < 6.2.16.2.1
CVE-2022-39353criticalCVSS: 9.8
2022-11-01

xmldom allows multiple root nodes in a DOM

xmldom<= 0.6.0
@xmldom/xmldom< 0.7.70.7.7
@xmldom/xmldom>= 0.8.0, < 0.8.40.8.4
@xmldom/xmldom>= 0.9.0-beta.1, < 0.9.0-beta.40.9.0-beta.4
CVE-2022-3783mediumCVSS: 6.1
2022-11-01

node-red-dashboard vulnerable to Cross-site Scripting

node-red-dashboard< 3.2.03.2.0
CVE-2022-39300highCVSS: 8.1
2022-10-12

Signature bypass via multiple root elements

node-saml< 4.0.0-beta.54.0.0-beta.5
Advertisement
CVE-2022-39299highCVSS: 8.1
2022-10-12

Signature bypass via multiple root elements

passport-saml< 3.2.23.2.2
node-saml< 4.0.0-beta.54.0.0-beta.5
@node-saml/node-saml< 4.0.0-beta.54.0.0-beta.5
@node-saml/passport-saml< 4.0.0-beta.34.0.0-beta.3
GHSA-2p3c-p3qw-69r4medium
2022-10-12

The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutations

apollo-server>= 2.0.0, < 2.25.42.25.4
CVE-2022-37616criticalCVSS: 9.8
2022-10-11

Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom

xmldom<= 0.6.0
@xmldom/xmldom= 0.9.0-beta.10.9.0-beta.2
@xmldom/xmldom>= 0.8.0, < 0.8.30.8.3
@xmldom/xmldom< 0.7.60.7.6
CVE-2022-24373highCVSS: 7.5
2022-10-01

react-native-reanimated vulnerable to ReDoS

react-native-reanimated< 2.10.02.10.0
CVE-2022-39263mediumCVSS: 6.8
2022-09-30

Upstash Adapter missing token verification

@next-auth/upstash-redis-adapter< 3.0.23.0.2
Advertisement
CVE-2022-41340highCVSS: 7.5
2022-09-25

secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery

@lionello/secp256k1-js< 1.1.01.1.0
CVE-2022-36083mediumCVSS: 5.3
2022-09-16

JOSE vulnerable to resource exhaustion via specifically crafted JWE

jose>= 1.0.0, <= 1.28.11.28.2
jose-browser-runtime>= 3.0.0, <= 3.20.33.20.4
jose-node-cjs-runtime>= 3.0.0, <= 3.20.33.20.4
jose-node-esm-runtime>= 3.0.0, <= 3.20.33.20.4
jose>= 2.0.0, <= 2.0.52.0.6
jose>= 3.0.0, <= 3.20.33.20.4
jose>= 4.0.0, <= 4.9.14.9.2
jose-browser-runtime>= 4.0.0, <= 4.9.14.9.2
jose-node-cjs-runtime>= 4.0.0, <= 4.9.14.9.2
jose-node-esm-runtime>= 4.0.0, <= 4.9.14.9.2
CVE-2022-39202mediumCVSS: 4.3
2022-09-15

matrix-appservice-irc vulnerable to IRC mode parameter confusion

matrix-appservice-irc< 0.35.00.35.0
CVE-2022-39203highCVSS: 8.8
2022-09-15

Parsing issue in matrix-org/node-irc leading to room takeovers

matrix-appservice-irc< 0.35.00.35.0
CVE-2022-36046mediumCVSS: 5.3
2022-08-30

Unexpected server crash in Next.js

next= 12.2.312.2.4
Advertisement
GHSA-56x4-j7p9-fcf9low
2022-08-30

Command Injection in moment-timezone

moment-timezone>= 0.1.0, < 0.5.350.5.35
CVE-2020-26938highCVSS: 7.2
2022-08-30

oauth2-server through 3.1.1 vulnerable to Open Redirect

oauth2-server<= 3.1.1
CVE-2022-24375highCVSS: 7.5
2022-08-25

node-opcua DoS when bypassing limitations for excessive memory consumption

node-opcua< 2.74.02.74.0
CVE-2022-25231highCVSS: 7.5
2022-08-24

node-opcua DoS vulnerability via message with memory allocation that exceeds v8's memory limit

node-opcua< 2.74.02.74.0
CVE-2022-21208highCVSS: 7.5
2022-08-24

Uncontrolled Resource Consumption in node-opcua

node-opcua< 2.74.02.74.0
Advertisement
CVE-2022-36010criticalCVSS: 10
2022-08-18

React Editable Json Tree vulnerable to arbitrary code execution via function parsing

react-editable-json-tree< 2.2.22.2.2
CVE-2022-35948mediumCVSS: 5.3
2022-08-18

Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type

undici<= 5.8.15.8.2
CVE-2022-35949mediumCVSS: 5.3
2022-08-18

`undici.request` vulnerable to SSRF using absolute URL on `pathname`

undici<= 5.8.15.8.2
CVE-2022-31186lowCVSS: 3.3
2022-08-06

next-auth before v4.10.2 and v3.29.9 leaks excessive information into log

next-auth< 3.29.93.29.9
next-auth>= 4.0.0, < 4.10.24.10.2
CVE-2020-28433criticalCVSS: 9.8
2022-08-03

node-latex-pdf is susceptible to command injection

node-latex-pdf<= 0.0.2
Advertisement
CVE-2022-35924criticalCVSS: 9.1
2022-08-02

NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails

next-auth>= 4.0.0, < 4.10.34.10.3
next-auth< 3.29.103.29.10
CVE-2022-2596mediumCVSS: 5.9
2022-08-02

node-fetch Inefficient Regular Expression Complexity

node-fetch>= 3.0.0, < 3.2.103.2.10
CVE-2020-7678criticalCVSS: 9.8
2022-07-26

node-import `params` argument can be controlled by users without any sanitization

node-import<= 0.9.2
CVE-2022-35131criticalCVSS: 9
2022-07-26

Joplin is vulnerable to arbitrary code execution

joplin< 2.9.12.9.1
CVE-2022-36313highCVSS: 7.5
2022-07-22

file-type vulnerable to Infinite Loop via malformed MKV file

file-type>= 17.0.0, < 17.1.317.1.3
file-type>= 13.0.0, < 16.5.416.5.4
Advertisement
CVE-2022-31151lowCVSS: 3.7
2022-07-21

undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect

undici< 5.8.05.8.0
CVE-2022-31150mediumCVSS: 5.3
2022-07-21

undici before v5.8.0 vulnerable to CRLF injection in request headers

undici< 5.8.05.8.0
CVE-2022-31180criticalCVSS: 9.8
2022-07-15

Shescape vulnerable to insufficient escaping of whitespace

shescape>= 1.4.0, < 1.5.81.5.8
CVE-2022-31179highCVSS: 8.1
2022-07-15

Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD

shescape< 1.5.81.5.8
CVE-2022-32214criticalCVSS: 9.1
2022-07-15

llhttp allows HTTP Request Smuggling via Improper Delimiting of Header Fields

llhttp< 6.0.76.0.7
Advertisement
CVE-2022-32213criticalCVSS: 9.1
2022-07-15

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

llhttp< 6.0.76.0.7
CVE-2022-31127highCVSS: 7.1
2022-07-06

Improper handling of email input

next-auth< 3.29.83.29.8
next-auth>= 4.0.0, < 4.9.04.9.0
CVE-2022-31103highCVSS: 7.5
2022-06-23

Improper handling of CSS at-rules in lettersanitizer

lettersanitizer< 1.0.21.0.2
CVE-2022-31093highCVSS: 7.5
2022-06-21

Improper Handling of `callbackUrl` parameter in next-auth

next-auth< 3.29.53.29.5
next-auth>= 4.0.0, < 4.5.04.5.0
CVE-2022-33987mediumCVSS: 5.3
2022-06-19

Got allows a redirect to a UNIX socket

got>= 12.0.0, < 12.1.012.1.0
got< 11.8.511.8.5
Advertisement
GHSA-4jqc-jvh2-pxg9medium
2022-06-17

Path traversal for local publishers in TechDocs backend

@backstage/plugin-techdocs-node< 1.1.21.1.2
@backstage/techdocs-common< 0.11.160.11.16
CVE-2022-32210highCVSS: 7.7
2022-06-17

ProxyAgent vulnerable to MITM

undici>= 4.8.2, <= 5.5.05.5.1
CVE-2022-29247lowCVSS: 2.2
2022-06-16

Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled

electron< 15.5.515.5.5
electron>= 16.0.0, < 16.2.616.2.6
electron>= 17.0.0, < 17.2.017.2.0
electron>= 18.0.0-beta.1, <= 18.0.0-beta.518.0.0-beta.6
CVE-2022-25863highCVSS: 8.1
2022-06-03

Unsanitized JavaScript code injection possible in gatsby-plugin-mdx

gatsby-plugin-mdx< 2.14.12.14.1
gatsby-plugin-mdx>= 3.0.0, < 3.15.23.15.2
CVE-2021-34084high
2022-06-03

OS Command Injection in s3-uploader

s3-uploader<= 2.0.3
Advertisement
CVE-2021-34082high
2022-06-03

OS Command Injection in proctree

proctree<= 0.1.1
CVE-2021-34083highCVSS: 8.1
2022-06-03

Command injection in google-it

google-it<= 1.6.2
CVE-2021-34080high
2022-06-03

OS Command injection in ssl-utils

ssl-utils<= 1.0.0
CVE-2022-29244highCVSS: 7.5
2022-06-02

Packing does not respect root-level ignore files in workspaces

npm>= 7.9.0, < 8.11.08.11.0
CVE-2021-4231mediumCVSS: 5.4
2022-05-27

Angular vulnerable to Cross-site Scripting

@angular/core>= 11.1.0-next.0, <= 11.1.0-next.211.1.0-next.3
@angular/core>= 11.0.0, < 11.0.511.0.5
@angular/core< 10.2.510.2.5
Advertisement
CVE-2022-29229mediumCVSS: 6.3
2022-05-25

Missing Cryptographic Step in cassproject

cassproject< 1.5.81.5.8
CVE-2021-26073highCVSS: 7.7
2022-05-24

Broken Authentication in Atlassian Connect Express

atlassian-connect-express>= 3.0.2, < 6.6.06.6.0
CVE-2022-29214mediumCVSS: 6.1
2022-05-24

URL Redirection to Untrusted Site ('Open Redirect') in next-auth

next-auth< 3.29.33.29.3
next-auth>= 4.0.0, < 4.3.34.3.3
CVE-2019-19729highCVSS: 7.5
2022-05-24

bson-objectid contains Improper input validation

bson-objectid<= 1.3.0
CVE-2021-42740criticalCVSS: 9.8
2022-05-24

Improper Neutralization of Special Elements used in a Command in Shell-quote

shell-quote>= 1.6.3, <= 1.7.21.7.3
Advertisement
CVE-2021-24037criticalCVSS: 9.8
2022-05-24

Use After Free in Hermes

hermes-engine<= 0.7.20.8.0
CVE-2020-1915highCVSS: 7.5
2022-05-24

Out-of-bounds Read in Facebook Hermes

hermes-engine<= 0.7.10.7.2
CVE-2020-1914criticalCVSS: 9.8
2022-05-24

Always-Incorrect Control Flow Implementation in Facebook Hermes

hermes-engine<= 0.7.10.7.2
CVE-2020-1913highCVSS: 8.1
2022-05-24

Signed to Unsigned Conversion Error in Facebook Hermes

hermes-engine<= 0.4.30.5.2
CVE-2020-1912highCVSS: 8.1
2022-05-24

Out-of-bounds Read and Out-of-bounds Write in Facebook Hermes

hermes-engine<= 0.4.30.5.2
Advertisement
CVE-2020-1911criticalCVSS: 9.8
2022-05-24

Access of Resource Using Incompatible Type in Facebook Hermes

hermes-engine<= 0.4.30.5.2
CVE-2018-21268criticalCVSS: 9.8
2022-05-24

Node-Traceroute RCE Vulnerability

traceroute<= 1.0.0
GHSA-f478-xwv9-p93qhighCVSS: 7.8
2022-05-24

Duplicate Advisory: Kerberos for NodeJS allows DLL Injection

kerberos< 1.0.01.0.0
CVE-2020-11883mediumCVSS: 5.3
2022-05-24

Diavante vue-storefront-api and storefront-api disclose stack trace

storefront-api< 1.0.0-rc31.0.0-rc3
vue-storefront-api< 1.12.01.12.0
CVE-2019-15598criticalCVSS: 9.8
2022-05-24

Treekill Enables OS Command Injection

tree-kill< 1.2.21.2.2
Advertisement
GHSA-mxq6-vrrr-ppmgcriticalCVSS: 9.8
2022-05-24

Duplicate Advisory: tree-kill vulnerable to remote code execution

tree-kill<= 1.2.1
CVE-2016-1000021lowCVSS: 3.5
2022-05-24

Duplicate Advisory: Node CLI Allows Arbitrary File Overwrite

cli>= 0.1.0, <= 0.11.31.0.0
CVE-2019-17606mediumCVSS: 6.1
2022-05-24

hexo-admin plugin for Node.js XSS Vulnerability

hexo-admin<= 2.3.0
CVE-2019-17625criticalCVSS: 9
2022-05-24

Rambox RCE Vulnerability

Rambox<= 0.6.9
CVE-2019-14939mediumCVSS: 5.5
2022-05-24

MySQL for Node.js Unsafe Options

mysql= 2.17.12.18.0
Advertisement
CVE-2022-29166highCVSS: 8
2022-05-23

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

matrix-appservice-irc<= 0.33.10.33.2
CVE-2022-24434highCVSS: 7.5
2022-05-21

Crash in HeaderParser in dicer

dicer<= 0.3.1
org.webjars.npm:dicer<= 0.3.0
CVE-2017-12581highCVSS: 8.1
2022-05-17

Electron vulnerable to remote command execution

electron< 1.6.81.6.8
CVE-2017-1000491mediumCVSS: 6.1
2022-05-14

Shiba vulnerable to XSS leading to code execution

shiba< 1.1.11.1.1
CVE-2018-3749criticalCVSS: 9.8
2022-05-14

Improper Input Validation in Deap

deap< 1.0.11.0.1
Advertisement
CVE-2022-21190criticalCVSS: 9.8
2022-05-14

Prototype Pollution in convict

convict< 6.2.36.2.3
CVE-2018-7408highCVSS: 7.8
2022-05-13

Incorrect Permission Assignment for Critical Resource in NPM

npm< 5.7.15.7.1
CVE-2018-6835criticalCVSS: 9.8
2022-05-13

Etherpad Lite Access Restriction Bypass

ep_etherpad-lite< 1.6.31.6.3
CVE-2018-0114highCVSS: 7.5
2022-05-13

Cisco node-jose improper validation of JWT signature

node-jose< 0.11.00.11.0
CVE-2018-7160highCVSS: 8.8
2022-05-13

Withdrawn Advisory: Node.js Inspector RCE via DNS Rebinding

node-inspector>= 6.0
Advertisement
CVE-2022-25324highCVSS: 7.5
2022-05-07

Uncaught Exception in bignum

bignum<= 0.13.1
GHSA-52rh-5rpj-c3w6highCVSS: 8
2022-05-05

Improper handling of multiline messages in node-irc

matrix-org-irc<= 1.2.01.2.1
CVE-2013-7371mediumCVSS: 6.1
2022-05-05

Node Connect Reflected Cross-Site Scripting in Sencha Labs Connect middleware

connect< 2.8.22.8.2
CVE-2022-30241mediumCVSS: 6.1
2022-05-05

Cross-site Scripting in jquery.json-viewer

jquery.json-viewer< 1.5.01.5.0
CVE-2022-29078criticalCVSS: 9.8
2022-04-26

ejs template injection vulnerability

ejs< 3.1.73.1.7
Advertisement
CVE-2022-24858mediumCVSS: 6.1
2022-04-22

NextAuth.js default redirect callback vulnerable to open redirects

next-auth< 3.29.23.29.2
next-auth>= 4.0.0, < 4.3.24.3.2
CVE-2022-29080criticalCVSS: 9.8
2022-04-13

Command injection in npm-dependency-versions

npm-dependency-versions<= 0.3.0
CVE-2022-24066highCVSS: 8.1
2022-04-02

Command injection in simple-git

simple-git< 3.5.03.5.0
CVE-2022-24773mediumCVSS: 5.3
2022-03-18

Improper Verification of Cryptographic Signature in `node-forge`

node-forge< 1.3.01.3.0
CVE-2022-24772highCVSS: 7.5
2022-03-18

Improper Verification of Cryptographic Signature in node-forge

node-forge< 1.3.01.3.0
Advertisement
CVE-2022-24771highCVSS: 7.5
2022-03-18

Improper Verification of Cryptographic Signature in node-forge

node-forge< 1.3.01.3.0
CVE-2022-21164highCVSS: 7.5
2022-03-17

Unhandled case in node-lmdb

node-lmdb< 0.9.70.9.7
GHSA-3mpp-xfvh-qh37low
2022-03-16

node-ipc behavior change

node-ipc>= 11.0.0, < 12.0.012.0.0
GHSA-8gr3-2gjw-jj7glow
2022-03-16

Hidden functionality in node-ipc

node-ipc= 9.2.2
CVE-2022-23812criticalCVSS: 9.8
2022-03-16

Embedded Malicious Code in node-ipc

node-ipc>= 10.1.1, < 10.1.310.1.3
Advertisement
CVE-2022-24740mediumCVSS: 5
2022-03-14

Sudden swap of user auth tokens in Volto

@plone/volto>= 14.0.0-alpha.6, <= 14.10.015.0.0-alpha.0
CVE-2021-46708mediumCVSS: 6.1
2022-03-12

Spoofing attack in swagger-ui-dist

swagger-ui-dist< 4.1.34.1.3
CVE-2022-24760criticalCVSS: 10
2022-03-11

Command injection in Parse Server through prototype pollution

parse-server< 4.10.74.10.7
CVE-2022-24719lowCVSS: 2.6
2022-03-01

Forwarding of confidentials headers to third parties in fluture-node

fluture-node>= 4.0.0, < 4.0.24.0.2
pyquest<= 0.0.1
CVE-2022-24709highCVSS: 8.8
2022-02-25

Cross site scripting in @awsui/components-react

@awsui/components-react< 3.0.3673.0.367
Advertisement
CVE-2022-0654highCVSS: 7.5
2022-02-24

Cookie exposure in requestretry

requestretry< 7.0.07.0.0
CVE-2022-23646mediumCVSS: 5.9
2022-02-17

Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0

next>= 10.0.0, < 12.1.012.1.0
CVE-2021-23555criticalCVSS: 9.8
2022-02-12

Sandbox bypass in vm2

vm2< 3.9.63.9.6
CVE-2021-28860criticalCVSS: 9.1
2022-02-10

Prototype Pollution in mixme

mixme< 0.5.10.5.1
CVE-2021-32622mediumCVSS: 4.2
2022-02-10

Improper file handling in matrix-react-sdk

matrix-react-sdk< 3.21.03.21.0
Advertisement
CVE-2020-7627criticalCVSS: 9.8
2022-02-10

OS Command Injection in node-key-sender

node-key-sender<= 1.0.11
CVE-2021-29369criticalCVSS: 9.8
2022-02-10

Code injection in @rkesters/gnuplot

@rkesters/gnuplot< 0.1.10.1.1
CVE-2017-18869lowCVSS: 2.5
2022-02-10

Time-of-check Time-of-use (TOCTOU) Race Condition in chownr

chownr< 1.1.01.1.0
GHSA-h87q-g2wp-47pjmedium
2022-02-09

Signatures are mistakenly recognized to be valid in jsrsasign

jsrsasign< 10.2.010.2.0
CVE-2020-24025mediumCVSS: 5.3
2022-02-09

Improper Certificate Validation in node-sass

node-sass>= 2.0.0, < 7.0.07.0.0
Advertisement
CVE-2021-23460highCVSS: 7.5
2022-02-01

Prototype pollution in min-dash

min-dash< 3.8.13.8.1
org.webjars.npm:min-dash< 3.8.13.8.1
CVE-2022-21721mediumCVSS: 5.9
2022-01-28

Denial of Service Vulnerability in next.js

next>= 12.0.0, < 12.0.912.0.9
CVE-2022-0235highCVSS: 8.8
2022-01-21

node-fetch forwards secure headers to untrusted sites

node-fetch>= 3.0.0, < 3.1.13.1.1
node-fetch< 2.6.72.6.7
CVE-2022-0122mediumCVSS: 6.1
2022-01-21

Open Redirect in node-forge

node-forge< 1.0.01.0.0
CVE-2022-21704mediumCVSS: 5.5
2022-01-21

Incorrect Default Permissions in log4js

log4js< 6.4.06.4.0
Advertisement
CVE-2022-21676highCVSS: 7.5
2022-01-13

Uncaught Exception in engine.io

engine.io>= 4.0.0, < 4.1.24.1.2
engine.io>= 5.0.0, < 5.2.15.2.1
engine.io>= 6.0.0, < 6.1.16.1.1
CVE-2022-0087highCVSS: 7.1
2022-01-12

Reflected cross-site scripting (XSS) vulnerability

@keystone-6/auth< 1.0.21.0.2
@keystone-next/auth<= 37.0.0
GHSA-5rqg-jm4f-cqx7high
2022-01-10

Infinite loop causing Denial of Service in colors

Colors>= 1.4.1, <= 1.4.2
Colors= 1.4.44-liberty-2
GHSA-5rrq-pxf6-6jx5low
2022-01-08

Prototype Pollution in node-forge debug API.

node-forge< 1.0.01.0.0
GHSA-wxgw-qj99-44c2low
2022-01-08

Prototype Pollution in node-forge util.setPath API

node-forge< 0.10.00.10.0
Advertisement
GHSA-gf8q-jrpm-jvxqlow
2022-01-08

URL parsing in node-forge could lead to undesired behavior.

node-forge< 1.0.01.0.0
CVE-2020-7632criticalCVSS: 9.8
2022-01-07

OS Command Injection in node-mpv

node-mpv<= 1.4.3
GHSA-qpw2-xchm-655qmediumCVSS: 6.5
2022-01-06

Out-of-Bounds read in stringstream

stringstream< 0.0.60.0.6
CVE-2021-45459criticalCVSS: 9.8
2022-01-05

Command Injection in node-windows

node-windows<= 1.0.0-beta.51.0.0-beta.6
CVE-2021-23797highCVSS: 7.5
2022-01-05

Path Traversal in http-server-node

http-server-node<= 1.0.2
Advertisement
CVE-2020-7609criticalCVSS: 9.8
2021-12-10

Code Injection in node-rules

node-rules>= 3.0.0, < 5.0.05.0.0
CVE-2021-23398mediumCVSS: 6.1
2021-12-10

Cross-site scripting in react-bootstrap-table

react-bootstrap-table<= 4.3.1
CVE-2021-36716highCVSS: 7.5
2021-12-10

Improper Input Validation in is-email

is-email< 1.0.11.0.1
GHSA-qrmm-w75w-3wpxmedium
2021-12-09

Server side request forgery in SwaggerUI

swagger-ui< 4.1.34.1.3
swagger-ui-dist< 4.1.34.1.3
swagger-ui-react< 4.1.34.1.3
Swashbuckle.AspNetCore.SwaggerUI< 6.3.06.3.0
CVE-2021-43803highCVSS: 7.5
2021-12-07

Unexpected server crash in Next.js.

next>= 12.0.0, < 12.0.512.0.5
next>= 0.9.9, < 11.1.311.1.3
Advertisement
CVE-2021-40830highCVSS: 6.3
2021-11-24

Improper certificate management in AWS IoT Device SDK v2

software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk< 1.5.01.5.0
aws-iot-device-sdk-v2< 1.5.31.5.3
awsiotsdk< 1.6.11.6.1
CVE-2021-40829highCVSS: 6.3
2021-11-24

Improper certificate management in AWS IoT Device SDK v2

software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk< 1.4.21.4.2
aws-iot-device-sdk-v2< 1.5.31.5.3
awsiotsdk< 1.6.11.6.1
CVE-2021-40828mediumCVSS: 6.3
2021-11-24

Improper certificate management in AWS IoT Device SDK v2

software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk< 1.3.31.3.3
aws-iot-device-sdk-v2< 1.5.11.5.1
awsiotsdk< 1.5.181.5.18
CVE-2021-40831highCVSS: 6.3
2021-11-24

Improper certificate management in AWS IoT Device SDK v2

software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk< 1.5.01.5.0
aws-iot-device-sdk-v2< 1.6.01.6.0
awsiotsdk< 1.7.01.7.0
CVE-2021-43571criticalCVSS: 9.8
2021-11-10

Improper Verification of Cryptographic Signature in starkbank-ecdsa

starkbank-ecdsa< 1.1.31.1.3
Advertisement
CVE-2021-41249highCVSS: 7.1
2021-11-08

XSS vulnerability in GraphQL Playground from untrusted schemas

graphql-playground-react< 1.7.281.7.28
CVE-2021-41248highCVSS: 7.1
2021-11-08

GraphiQL introspection schema template injection attack

graphiql>= 0.5.0, < 1.4.71.4.7
CVE-2021-23807mediumCVSS: 5.6
2021-11-08

Prototype Pollution in node-jsonpointer

jsonpointer< 5.0.05.0.0
org.webjars.npm:json-pointer< 5.0.05.0.0
CVE-2020-36378criticalCVSS: 9.8
2021-11-02

Vulnerability in packageCmd function leads to arbitrary code execution via filePath parameters

aaptjs<= 1.3.1
CVE-2020-36379criticalCVSS: 9.8
2021-11-02

Vulnerability in remove function leads to arbitrary code execution via filePath parameters

aaptjs<= 1.3.1
Advertisement
CVE-2020-36377criticalCVSS: 9.8
2021-11-02

Vulnerability in dump function leads to arbitrary code execution via filePath parameters

aaptjs<= 1.3.1
CVE-2020-36376criticalCVSS: 9.8
2021-11-02

Vulnerability in list function leads to arbitrary code execution via filePath parameters

aaptjs<= 1.3.1
CVE-2020-36381criticalCVSS: 9.8
2021-11-01

Vulnerability in singleCrunch function leads to arbitrary code execution via filePath parameters

aaptjs<= 1.3.1
CVE-2020-36380criticalCVSS: 9.8
2021-11-01

Vulnerability in crunch function leads to arbitrary code execution via filePath parameters

aaptjs<= 1.3.1
CVE-2019-10061criticalCVSS: 9.8
2021-10-12

OS Command Injection in node-opencv

opencv< 6.1.06.1.0
Advertisement
CVE-2021-41117highCVSS: 8.7
2021-10-11

Insecure random number generation in keypair

keypair< 1.0.41.0.4
CVE-2021-41580mediumCVSS: 5.3
2021-09-29

Improper Access Control in passport-oauth2

passport-oauth2< 1.6.11.6.1
CVE-2021-23443mediumCVSS: 5.4
2021-09-22

Cross-site Scripting in edge.js

edge.js< 5.3.25.3.2
GHSA-8r4g-cg4m-x23cmedium
2021-09-22

Denial of Service in node-static

node-static<= 0.7.11
CVE-2020-26301highCVSS: 7.5
2021-09-21

OS Command Injection in ssh2

ssh2< 1.4.01.4.0
Advertisement
CVE-2021-3794highCVSS: 7.5
2021-09-20

Inefficient Regular Expression Complexity in vuelidate

@vuelidate/validators<= 2.0.0-alpha.212.0.0-alpha.22
CVE-2021-23406highCVSS: 8.1
2021-09-02

Code Injection in pac-resolver

pac-resolver< 5.0.05.0.0
degenerator< 3.0.13.0.1
CVE-2021-39187highCVSS: 7.5
2021-09-02

Parse Server crashes with query parameter

parse-server< 4.10.34.10.3
CVE-2021-39176highCVSS: 7.5
2021-09-01

Missing Release of Memory after Effective Lifetime in detect-character-encoding

detect-character-encoding< 0.3.10.3.1
CVE-2021-39178highCVSS: 7.5
2021-09-01

XSS in Image Optimization API for Next.js

next>= 10.0.0, < 11.1.111.1.1
Advertisement
CVE-2021-32831highCVSS: 7.5
2021-09-01

Code Injection in total.js

total.js< 3.4.93.4.9
CVE-2021-37701highCVSS: 8.2
2021-08-31

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

tar>= 5.0.0, < 5.0.85.0.8
tar>= 6.0.0, < 6.1.76.1.7
tar>= 3.0.0, < 4.4.164.4.16
CVE-2021-37712highCVSS: 8.2
2021-08-31

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

tar>= 5.0.0, < 5.0.105.0.10
tar>= 6.0.0, < 6.1.96.1.9
tar>= 3.0.0, < 4.4.184.4.18
CVE-2021-37713highCVSS: 8.2
2021-08-31

Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization

tar< 4.4.184.4.18
tar>= 5.0.0, < 5.0.105.0.10
tar>= 6.0.0, < 6.1.96.1.9
CVE-2021-39134highCVSS: 8.2
2021-08-31

@npmcli/arborist vulnerable to UNIX Symbolic Link (Symlink) Following

@npmcli/arborist< 2.8.22.8.2
Advertisement
CVE-2020-22403highCVSS: 8.8
2021-08-30

Cross-Site Request Forgery in express-cart

express-cart< 1.1.171.1.17
CVE-2021-39171mediumCVSS: 5.3
2021-08-30

Unlimited transforms allowed for signed nodes

passport-saml< 3.1.03.1.0
CVE-2021-39157highCVSS: 7.5
2021-08-25

Improper Handling of Exceptional Conditions in detect-character-encoding

detect-character-encoding< 0.7.00.7.0
CVE-2021-39131highCVSS: 7.5
2021-08-23

Improper Handling of Unexpected Data Type in ced

ced< 1.0.01.0.0
CVE-2021-37699mediumCVSS: 6.9
2021-08-12

Open Redirect in Next.js

next>= 0.9.9, < 11.1.011.1.0
Advertisement
CVE-2018-3718mediumCVSS: 5.3
2021-08-09

vercel/serve allows access to restricted files if filename is URL encoded.

serve< 6.5.26.5.2
GHSA-xh2p-7p87-fhghlowCVSS: 3.1
2021-08-05

Incorrect TCR calculation in batchLiquidateTroves() during Recovery Mode

@liquity/contracts<= 1.0.0
CVE-2021-32804highCVSS: 8.2
2021-08-03

Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization

tar< 3.2.23.2.2
tar>= 4.0.0, < 4.4.144.4.14
tar>= 5.0.0, < 5.0.65.0.6
tar>= 6.0.0, < 6.1.16.1.1
CVE-2021-32803highCVSS: 8.2
2021-08-03

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

tar>= 4.0.0, < 4.4.154.4.15
tar>= 5.0.0, < 5.0.75.0.7
tar>= 6.0.0, < 6.1.26.1.2
tar>= 3.0.0, < 3.2.33.2.3
CVE-2020-1920highCVSS: 7.5
2021-07-20

Regular expression denial of service in react-native

react-native>= 0.59.0, < 0.62.30.62.3
react-native>= 0.63.0, < 0.64.10.64.1
Advertisement
CVE-2021-3647mediumCVSS: 5.3
2021-07-19

URIjs Vulnerable to Hostname spoofing via backslashes in URL

urijs< 1.19.71.19.7
GHSA-5w25-hxp5-h8c9criticalCVSS: 9.8
2021-06-21

Duplicate Advisory: Improper Verification of Cryptographic Signature

tenvoy< 7.0.37.0.3
CVE-2021-33502highCVSS: 7.5
2021-06-08

ReDoS in normalize-url

normalize-url>= 5.0.0, < 5.3.15.3.1
normalize-url>= 6.0.0, < 6.0.16.0.1
normalize-url>= 4.3.0, < 4.5.14.5.1
CVE-2021-33587highCVSS: 7.5
2021-06-07

Denial of service in css-what

css-what>= 4.0.0, <= 5.0.05.0.1
CVE-2021-33623highCVSS: 7.5
2021-06-07

Uncontrolled Resource Consumption in trim-newlines

trim-newlines< 3.0.13.0.1
trim-newlines= 4.0.04.0.1
Advertisement
CVE-2021-26707criticalCVSS: 9.8
2021-06-07

Prototype pollution in Merge-deep

merge-deep< 3.0.33.0.3
GHSA-h45p-w933-jxh3medium
2021-06-01

Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript

@aws-crypto/client-browser< 1.9.01.9.0
@aws-crypto/client-browser>= 2.0.0, < 2.2.02.2.0
@aws-crypto/client-node< 1.9.01.9.0
@aws-crypto/client-node>= 2.0.0, < 2.2.02.2.0
GHSA-5vm8-hhgr-jcjpmedium
2021-05-28

Cross-site scripting vulnerability in TinyMCE

tinymce< 5.7.15.7.1
CVE-2021-31597criticalCVSS: 9.4
2021-05-24

Improper Certificate Validation in xmlhttprequest-ssl

xmlhttprequest-ssl< 1.6.11.6.1
CVE-2020-7696mediumCVSS: 5.3
2021-05-18

Credential leak in react-native-fast-image

react-native-fast-image< 8.3.08.3.0
Advertisement
CVE-2020-7673criticalCVSS: 9.8
2021-05-17

Code Injection in node-extend

node-extend<= 0.2.0
GHSA-8796-gc9j-63rvmediumCVSS: 4.2
2021-05-17

File upload local preview can run embedded scripts after user interaction

matrix-react-sdk< 3.21.03.21.0
CVE-2020-7740highCVSS: 8.2
2021-05-10

Server-Side Request Forgery in node-pdf-generator

node-pdf-generator<= 0.0.6
GHSA-r2gr-fhmr-66c5highCVSS: 7.8
2021-05-10

Duplicate Advisory: "Arbitrary code execution in socket.io-file"

socket.io-file<= 2.0.31
CVE-2020-7602criticalCVSS: 9.8
2021-05-07

OS Command Injection in node-prompt-here

node-prompt-here<= 1.0.1
Advertisement
CVE-2020-7721criticalCVSS: 9.8
2021-05-06

Prototype Pollution in node-oojs

node-oojs<= 1.4.0
CVE-2021-23371highCVSS: 7.5
2021-05-06

Denial of service in chrono-node

chrono-node< 2.2.42.2.4
CVE-2021-31712mediumCVSS: 5.4
2021-05-06

Cross-site Scripting in React Draft Wysiwyg

react-draft-wysiwyg< 1.14.61.14.6
CVE-2021-29491highCVSS: 7.1
2021-05-06

Use of Potentially Dangerous Function in mixme

mixme< 0.5.10.5.1
CVE-2021-29469highCVSS: 7.5
2021-04-27

Node-Redis potential exponential regex in monitor mode

redis>= 2.6.0, < 3.1.13.1.1
Advertisement
CVE-2017-18924highCVSS: 7.5
2021-04-22

Code Injection in oauth2-server

oauth2-server<= 3.1.1
CVE-2021-29446mediumCVSS: 5.9
2021-04-19

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-cjs-runtime

jose-node-cjs-runtime< 3.11.43.11.4
CVE-2021-29445mediumCVSS: 5.9
2021-04-19

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtime

jose-node-esm-runtime< 3.11.43.11.4
CVE-2021-26276mediumCVSS: 5.3
2021-04-13

Improper Control of Dynamically-Managed Code Resources in config-shield

config-shield< 0.2.30.2.3
CVE-2021-25864highCVSS: 7.5
2021-04-13

Path Traversal in node-red-contrib-huemagic

node-red-contrib-huemagic<= 3.0.0
Advertisement
CVE-2020-7693mediumCVSS: 5.3
2021-04-13

Improper Input Validation in SocksJS-Node

sockjs< 0.3.200.3.20
CVE-2020-8823mediumCVSS: 6.1
2021-04-13

Cross-site scripting in SocksJS-node

sockjs< 0.3.00.3.0
CVE-2020-7787highCVSS: 8.2
2021-04-13

Improper Authentication in react-adal

react-adal< 0.5.10.5.1
CVE-2021-26275criticalCVSS: 9.8
2021-04-13

Command injection in eslint-fixer

eslint-fixer<= 0.1.5
CVE-2021-27191highCVSS: 7.5
2021-04-13

Denial of Service in get-ip-range

get-ip-range< 4.0.04.0.0
Advertisement
CVE-2020-27543highCVSS: 7.5
2021-04-12

Denial of Service (DoS) in restify-paginate

restify-paginate<= 0.0.5
CVE-2021-20327mediumCVSS: 6.8
2021-04-12

mongodb-client-encryption vulnerable to Improper Certificate Validation

mongodb-client-encryption= 1.2.01.2.1
GHSA-prmc-5v5w-c465critical
2021-04-06

Client TLS credentials sent raw to server in npm package nats

nats>= 2.0.0-201, <= 2.0.0-2082.0.0-209
CVE-2021-21421highCVSS: 8.1
2021-04-06

ApiKey secret could be revelated on network issue

node-etsy-client<= 0.2.00.3.0
CVE-2021-29418mediumCVSS: 5.3
2021-03-29

netmask npm package mishandles octal input data

netmask< 2.0.12.0.1
Advertisement
CVE-2021-27884mediumCVSS: 5.1
2021-03-26

Weak JSON Web Token in yapi-vendor

yapi-vendor<= 1.9.21.9.3
CVE-2020-8298criticalCVSS: 9.8
2021-03-25

Command injection in fs-path

fs-path< 0.0.250.0.25
CVE-2021-23344criticalCVSS: 9.8
2021-03-19

total.js Remote Code Execution Vulnerability

total.js< 3.4.73.4.8
CVE-2021-28092highCVSS: 7.5
2021-03-19

Regular Expression Denial of Service (ReDoS)

is-svg>= 2.1.0, < 4.2.24.2.2
CVE-2020-7785criticalCVSS: 9.8
2021-03-19

Command injection in node-ps

node-ps<= 0.0.2
Advertisement
GHSA-hfwx-c7q6-g54chigh
2021-03-12

Vulnerability allowing for reading internal HTTP resources

highcharts-export-server<= 2.0.302.1.0
CVE-2021-24033mediumCVSS: 5.6
2021-03-11

react-dev-utils OS Command Injection in function `getProcessForPort`

react-dev-utils>= 0.4.0, < 11.0.411.0.4
CVE-2021-21320lowCVSS: 2.6
2021-03-03

User content sandbox can be confused into opening arbitrary documents

matrix-react-sdk< 3.15.03.15.0
CVE-2021-21353mediumCVSS: 6.8
2021-03-03

Remote code execution via the `pretty` option.

pug< 3.0.13.0.1
pug-code-gen< 2.0.32.0.3
pug-code-gen>= 3.0.0, < 3.0.23.0.2
CVE-2021-27405mediumCVSS: 4.3
2021-03-01

Regular expression Denial of Service in @progfay/scrapbox-parser

@progfay/scrapbox-parser< 6.0.36.0.3
@progfay/scrapbox-parser>= 7.0.0, < 7.0.27.0.2
Advertisement
CVE-2021-27516highCVSS: 7.5
2021-03-01

URIjs Hostname spoofing via backslashes in URL

urijs< 1.19.61.19.6
CVE-2021-21298low
2021-02-26

Path traversal in Node-Red

@node-red/runtime< 1.2.81.2.8
CVE-2021-21297highCVSS: 7.7
2021-02-26

Prototype Pollution in Node-Red

@node-red/runtime< 1.2.81.2.8
GHSA-f6gj-7592-5jxmhigh
2021-02-23

Directory Traversal

node-simple-router< 0.10.10.10.1
CVE-2021-21310low
2021-02-11

Token verification bug in next-auth

next-auth< 3.3.03.3.0
Advertisement
CVE-2021-27185criticalCVSS: 9.8
2021-02-11

Command injection in samba-client

samba-client< 4.0.04.0.0
CVE-2021-3190criticalCVSS: 9.8
2021-01-29

OS Command Injection in async-git

async-git< 1.13.21.13.2
CVE-2021-3223high
2021-01-29

Path traversal in Node-RED-Dashboard

node-red-dashboard< 2.26.22.26.2
CVE-2024-21911medium
2021-01-06

Cross-site scripting vulnerability in TinyMCE

tinymce< 5.6.05.6.0
TinyMCE< 5.6.05.6.0
tinymce/tinymce< 5.6.05.6.0
CVE-2020-26291mediumCVSS: 6.5
2020-12-30

Hostname spoofing via backslashes in URL

urijs< 1.19.41.19.4
Advertisement
CVE-2020-26288lowCVSS: 7.7
2020-12-28

Parse Server stores password in plain text

parse-server< 4.5.04.5.0
CVE-2020-7789mediumCVSS: 5.6
2020-12-21

OS Command Injection in node-notifier

node-notifier< 8.0.18.0.1
CVE-2020-7788highCVSS: 7.3
2020-12-10

ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse

ini< 1.3.61.3.6
CVE-2020-15242mediumCVSS: 4.7
2020-10-08

Open Redirect in Next.js versions

next>= 9.5.0, < 9.5.49.5.4
CVE-2020-6506mediumCVSS: 6.5
2020-10-02

Android WebView Universal Cross-site Scripting

react-native-webview<= 10.10.211.0.0
Advertisement
CVE-2020-7720highCVSS: 8.8
2020-09-14

Prototype Pollution in node-forge

node-forge< 0.10.00.10.0
GHSA-4wcx-c9c4-89p2criticalCVSS: 9.8
2020-09-11

Malicious Package in react-datepicker-plus

react-datepicker-plus>= 2.4.2, <= 2.4.32.4.6
GHSA-5g6j-8hv4-vfgjhigh
2020-09-11

Cross-Site Scripting in node-red

node-red< 0.18.60.18.6
GHSA-9v62-24cr-58cxmediumCVSS: 5.9
2020-09-11

Denial of Service in node-sass

node-sass>= 3.3.0, < 4.13.14.13.1
GHSA-mvch-rh6h-2m47criticalCVSS: 9.8
2020-09-11

Malicious Package in equest

equest>= 0
Advertisement
GHSA-r863-p739-275ccriticalCVSS: 9.8
2020-09-11

Malicious Package in reuest

reuest>= 0
GHSA-8qx4-r7fx-xc4vcriticalCVSS: 9.8
2020-09-11

Malicious Package in requst

requst>= 0
CVE-2020-15168lowCVSS: 2.6
2020-09-10

The `size` option isn't honored after following a redirect in node-fetch

node-fetch>= 3.0.0-beta.1, <= 3.0.0-beta.83.0.0-beta.9
node-fetch>= 2.0.0, < 2.6.12.6.1
CVE-2020-24660mediumCVSS: 6.5
2020-09-09

Lack of URL normalization may lead to authorization bypass when URL access rules are used

lemonldap-ng-handler< 0.5.20.5.2
GHSA-5vj8-3v2h-h38vhigh
2020-09-04

Remote Code Execution in next

next>= 0.9.9, < 5.1.05.1.0
Advertisement
GHSA-whv6-rj84-2vh2high
2020-09-04

Cross-Site Scripting in nextcloud-vue-collections

nextcloud-vue-collections< 0.4.20.4.2
GHSA-hrpp-f84w-xhfgmediumCVSS: 5.3
2020-09-04

Outdated Static Dependency in vue-moment

vue-moment< 4.1.04.1.0
CVE-2013-7035mediumCVSS: 6.5
2020-09-04

Cross-Site Scripting in react

react>= 0.4.0, < 0.4.20.4.2
react>= 0.5.0, < 0.5.20.5.2
GHSA-hg79-j56m-fxgvhigh
2020-09-04

Cross-Site Scripting in react

react>= 0.0.1, < 0.14.00.14.0
Advertisement