npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59817Mediumghost: Ghost: Paid gift memberships obtainable at minimal cost via the donations featureCVE-2026-53947Mediumghost: Ghost: Member existence leak via magic link sign-in responseCVE-2026-53950High@tryghost/activitypub: XSS in Ghost's ActivityPub clientCVE-2026-70594Mediumghost: Ghost: Session Fixation in Ghost AdminCVE-2026-70593Mediumghost: Ghost: Theme Upload Path TraversalCVE-2026-70592Mediumghost: Ghost: Database Backup Path TraversalCVE-2026-70591Mediumghost: Ghost: Server-Side Request Forgery in Image FetchingCVE-2026-70590Mediumghost: Ghost: Blind Password Hash Disclosure in Ghost Admin APICVE-2026-53946Mediumghost: Ghost: Mobiledoc image-size fetch SSRFCVE-2026-53945Mediumghost: Ghost: Server-side request forgery via DNS rebinding in external request handlingCVE-2026-53944Mediumghost: Ghost: Private IP filtering bypass to make server-side requests to internal servicesCVE-2026-70589Mediumghost: Ghost: Archived Offers can be RedeemedCVE-2026-53948Mediumghost: Ghost: File Upload Content-Type SpoofingCVE-2026-70588Mediumghost: Ghost: Cross-Site Scripting in Universal ImportCVE-2026-70478Criticalflowise: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected serviceCVE-2026-70477Criticalflowise: Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityCVE-2026-70476Highflowise: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing ManipulationGHSA-8GJ2-2CVC-6XX7Mediumflowise: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS CredentialsCVE-2026-70475Highflowise: Flowise: Missing Authorization on Execution Update EndpointCVE-2026-70474Highflowise: Flowise: Cross-Workspace OAuth2 Credential Metadata LeakGHSA-RWRP-9823-P2XQMediumflowise: Flowise: Incomplete Credential Redaction Exposes Secrets via APICVE-2026-70473Highflowise: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert historyCVE-2026-70472Highflowise: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-storeCVE-2026-69264Criticalflowise: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validationGHSA-88PR-878C-24WFHighflowise-components: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys …

Stop the waste.
Protect your environment with Kodem.