npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-49857Highauth-fetch-mcp: auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 LoopbackCVE-2026-49856Medium@jshookmcp/jshook: @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorizationCVE-2026-48795High@adonisjs/bodyparser: @adonisjs/bodyparser has an incomplete fix for CVE-2026-25754CVE-2026-49473High@cedar-policy/authorization-for-expressjs: @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulationGHSA-QRV3-253H-G69CHighpnpm: pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configGHSA-72R4-9C5J-MJ57Highpnpm: pnpm: `patch-remove` could delete project-selected files outside the patches directoryGHSA-FR4H-3CPH-29XVHighpnpm: pnpm: Hoisted install imports lockfile alias outside node_modulesCVE-2026-55700Highpnpm: pnpm: `stage download` writes outside its destination directory via manifest name/version traversalCVE-2026-55699Mediumpnpm: pnpm: Reserved bin name deletes PNPM_HOME during global removeCVE-2026-55698Highpnpm: pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesCVE-2026-55697Highpnpm: pnpm: Repository-controlled configDependencies can select a pacquet native install engineCVE-2026-55487Highpnpm: pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycleCVE-2026-55180Mediumpnpm: pnpm: Repository config can expand victim environment secrets into registry requests before scripts runCVE-2026-50015Highpnpm: pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)CVE-2026-50017Mediumpnpm: pnpm binds unscoped user-level npm auth credentials to a repository-selected registryCVE-2026-50016Highpnpm: pnpm: Transitive dependency alias path traversal allows project path override via symlink replacementCVE-2026-50014Mediumpnpm: pnpm: Git Fetch Argument Injection via Lockfile resolution.commitCVE-2026-50021Mediumpnpm: pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity FieldCVE-2026-50573Mediumpnpm: pnpm: Unsafe default behavior breaks integrity checkCVE-2026-50029Mediumjs-toml: js-toml has silent type confusion via falsy-primitive duplicate-key bypassCVE-2026-49336Medium@microsoft/kiota-http-fetchlibrary: @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in…CVE-2026-49293Highjs-toml: js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literalsCVE-2026-49357Highline-desktop-mcp: Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authenticationCVE-2026-48995Mediumpnpm: pnpm: Tarball hash of GitHub git dependencies is not stored in lockfileGHSA-RP72-5V5Q-2446Low@cardano402/mcp-server: @cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

Stop the waste.
Protect your environment with Kodem.