npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-70610Mediumelectron: Electron: contextBridge object copy honors prototype settersCVE-2026-70609Mediumelectron: Electron: DevTools JavaScript Injection via Unsanitized Dock State ParameterCVE-2026-70608Highelectron: Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathCVE-2026-70607Mediumelectron: Electron: window.open features string controls some window options considered privilegedCVE-2026-70606Mediumelectron: Electron: ProtocolResponse.url reuses the default session cache instead of the registering sessionCVE-2026-70605Mediumelectron: Electron: HTTP redirect followed into local file loaderCVE-2026-70604Highelectron: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin readsCVE-2026-70602Mediumelectron: Electron: Extension tab APIs operate across session boundariesCVE-2026-70603Mediumelectron: Electron: shell.openPath path validation bypass via embedded null byteCVE-2026-70601Highelectron: Electron: Context isolation bypass via Function.prototype.bind hijackCVE-2026-70600Lowelectron: Electron: Cross-origin iframe can position native autofill popupCVE-2026-70599Mediumelectron: Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe OriginCVE-2026-70598Lowelectron: Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory sizeCVE-2026-70597Mediumelectron: Electron: Parent process code-sign check is spoofableCVE-2026-53949Mediumghost: Ghost Content API filter bypass reveals private fieldsCVE-2026-70596Mediumghost: Ghost: Cross-Site Scripting in Feature Image CaptionsCVE-2026-70595Mediumghost: Ghost: Server-Side Request Forgery Mitigation IssueCVE-2026-59817Mediumghost: Ghost: Paid gift memberships obtainable at minimal cost via the donations featureCVE-2026-53947Mediumghost: Ghost: Member existence leak via magic link sign-in responseCVE-2026-53950High@tryghost/activitypub: XSS in Ghost's ActivityPub clientCVE-2026-70594Mediumghost: Ghost: Session Fixation in Ghost AdminCVE-2026-70593Mediumghost: Ghost: Theme Upload Path TraversalCVE-2026-70592Mediumghost: Ghost: Database Backup Path TraversalCVE-2026-70591Mediumghost: Ghost: Server-Side Request Forgery in Image FetchingCVE-2026-70590Mediumghost: Ghost: Blind Password Hash Disclosure in Ghost Admin API

Stop the waste.
Protect your environment with Kodem.