npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-85715Highexifreader: ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory ExhaustionCVE-2026-63506High@tinacms/auth: Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted siteCVE-2026-63225Medium@redocly/cli: Redocly CLI: Path traversal when using `split` commandCVE-2026-77360Medium@orpc/server: oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS BypassCVE-2026-71538High@cyclonedx/cyclonedx-npm: @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on WindowsCVE-2026-63472Critical@vendure/core: Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verificationCVE-2026-63461Medium@vendure/core: Vendure: Shop API list queries can return non-public entities when filterOperator is ORCVE-2026-63460Highvendure/core: Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backendsCVE-2026-63459High@vendure/dashboard: Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptionsCVE-2026-61793Mediumnuxt-og-image: Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameterCVE-2026-63671High@nuxtjs/mdc: @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configurationCVE-2026-68904Highnode-opcua-transport: node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource ExhaustionCVE-2026-61560Critical@zereight/mcp-gitlab: @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeoverCVE-2026-61559Critical@zereight/mcp-gitlab: @zereight/mcp-gitlab Vulnerable to Server-Side Request ForgeryCVE-2026-61568Critical@zereight/mcp-gitlab: @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transportGHSA-5648-RGJ9-V224High@zereight/mcp-gitlab: @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports,…CVE-2026-61534Criticalyayson: yayson: Prototype pollution in Store/LegacyStore deserializationCVE-2026-59148High@mockoon/commons-server: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theftCVE-2026-59149Medium@mockoon/commons-server: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)CVE-2026-59973Highmcp-from-openapi: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fixCVE-2026-59965High@jhb.software/payload-alt-text-plugin: @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` OmissionCVE-2026-59960High@argos-ci/core: @argos-ci/core: CI Branch Name OS Command InjectionCVE-2026-88062Criticalomniroute: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)CVE-2026-86073Mediumn8n: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource SubstitutionCVE-2026-86074Mediumn8n: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

Stop the waste.
Protect your environment with Kodem.