npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-JVM4-4J77-39P6Highopenclaw: OpenClaw: QQBot streaming command could mutate config without explicit allowFromGHSA-83W9-H5WV-J9XMHighopenclaw: OpenClaw: Node pairing reconnection could confuse approval scope stateGHSA-WV26-J37Q-2G7PMediumopenclaw: OpenClaw's Slack plugin approvals used the exec approver gate for plugin actionsGHSA-P2FH-F5FC-44HRMediumopenclaw: OpenClaw: memory-wiki ingest could read local files with operator.write scopeGHSA-HW9R-H9MR-4JFFHighopenclaw: OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gatesGHSA-MHQ8-78PJ-5J79Highopenclaw: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansionCVE-2026-35630Highopenclaw: OpenClaw: QQBot native approval buttons did not enforce configured approver identityCVE-2026-53814Highopenclaw: OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authorityCVE-2026-53817Highopenclaw: OpenClaw: Control UI locality spoofing could mint a durable admin device tokenGHSA-RGGC-M335-3WVJHighopenclaw: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headersCVE-2026-53810Highopenclaw: OpenClaw's marketplace runtime extension metadata could point at unscanned payloadsCVE-2026-53812Mediumopenclaw: OpenClaw's browser act interactions could bypass private-network navigation checksGHSA-2J8V-HWGC-X698HighOpenclaw: OpenClaw: Shell wrapper argv could change between approval and executionGHSA-QH2F-99MV-MRCFMediumopenclaw: OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawnGHSA-XWW8-GQVH-92X9Highopenclaw: OpenClaw: Exec approval display truncation could hide the command being approvedCVE-2026-53815Highopenclaw: OpenClaw: Message read actions could skip channel allowlist checksGHSA-9C3V-684M-579CMediumopenclaw: OpenClaw MCP SSE redirects could forward Authorization headersCVE-2026-50143High@apify/actors-mcp-server: Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify tokenCVE-2026-53943Criticalghost: Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview headerCVE-2026-48819Medium@hey-api/openapi-ts: @hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` keyCVE-2026-48815Highsigstore: sigstore's `certificateOIDs` verification constraints are silently dropped and never enforcedCVE-2026-48816Medium@sigstore/verify: sigstore-js has Insufficient Verification of Data AuthenticityCVE-2026-49988Mediumrepomix: repomix: attach_packed_output can bypass file-read secret scanning for supported local filesCVE-2026-49987Highrepomix: repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument InjectionCVE-2026-49864Highwetty: wetty vulnerable to DOM XSS via file-download filename

Stop the waste.
Protect your environment with Kodem.