npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-19693Highextract-zip: extract-zip allows arbitrary file writes through symlink archive entriesCVE-2026-53728High@medplum/core: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code LeakageCVE-2026-40345Highdeepmerge-ts: DeepmergeTS has stack exhaustion when merging recursive object graphsCVE-2026-55156Medium@ooples/token-optimizer-mcp: Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API EndpointsCVE-2026-55157High@ooples/token-optimizer-mcp: Token Optimizer MCP: OS command injection in smart_user via username in get-user-infoCVE-2026-35219High@budibase/server: Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP BlacklistCVE-2026-73654High@trigger.dev/core: Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoSCVE-2026-55102Mediumhashi-vault-js: hashi-vault-js: Vault token and secret values exposed in thrown errorsCVE-2026-55088Mediumep_etherpad-lite: ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenCVE-2026-55086Mediumep_etherpad-lite: ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwriteCVE-2026-55087Mediumep_etherpad-lite: ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path HeaderCVE-2026-45819Mediumbaseline-browser-mapping: baseline-browser-mapping process termination on invalid input causes denial of serviceCVE-2026-58230High@sap/approuter: SAP Approuter has an Information Disclosure vulnerabilityCVE-2026-71851Criticalcrypto-js: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency ChainCVE-2026-71850Mediumhono: Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureCVE-2026-71849Lowhono: Hono: Proxy Helper does not remove response headers listed in the `Connection` headerCVE-2026-71848Mediumhono: Hono: Algorithmic Complexity DoS in Language MiddlewareCVE-2026-15895Highjsii-diff: jsii-diff: Command Injection via npm: package argumentCVE-2026-66062Medium@sveltejs/kit: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept headerCVE-2026-72744Mediumnuxt: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpointGHSA-55Q2-FJHQ-7XH7Mediumdompurify: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSSCVE-2026-71498Mediumre2: node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap…CVE-2026-71430Mediumre2: node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result…GHSA-W9HM-4M3M-FXMMHighngx-extended-pdf-viewer: ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633CVE-2026-16633Highpdfjs-dist: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

Stop the waste.
Protect your environment with Kodem.