npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-50029Mediumjs-toml: js-toml has silent type confusion via falsy-primitive duplicate-key bypassCVE-2026-49336Medium@microsoft/kiota-http-fetchlibrary: @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in…CVE-2026-49293Highjs-toml: js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literalsCVE-2026-49357Highline-desktop-mcp: Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authenticationCVE-2026-48995Mediumpnpm: pnpm: Tarball hash of GitHub git dependencies is not stored in lockfileGHSA-RP72-5V5Q-2446Low@cardano402/mcp-server: @cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.urlCVE-2026-49252Critical@deepstream/server: deepstream is vulnerable to prototype pollutionGHSA-3P34-W4F6-5XH2Highbetter-helperjs: better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static ServerGHSA-FHP4-PR5J-46M5Highmuhammara: Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange keyCVE-2026-48801Highlinkify-it: LinkifyIt#match scan loop has quadratic algorithmic complexityCVE-2026-48797Criticalbackpropagate: Backpropagate: backprop ui --auth and backprop ui --share do not enforce authenticationGHSA-5VWR-QCHF-Q4PFMedium@cyclonedx/cdxgen: @cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module pathsCVE-2026-48758Medium@sigstore/core: @sigstore/core has DSSE payloadType type-binding failureGHSA-WRR4-782V-JHWHLowneotoma: neotoma has tenant isolation gap in relationship query endpointsCVE-2026-48713Criticali18next-fs-backend: i18next-fs-backend vulnerable to prototype pollution via crafted missing-key stringCVE-2026-48714Criticali18next-http-middleware: i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting namesCVE-2026-46406Medium@anthropic-ai/claude-code: @anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File WriteCVE-2026-11998Highangular: Angular's deprecated package has a Cross-Site Scripting issueCVE-2026-54350Critical@budibase/server: Budibase has nonymous NoSQL operator injection via published-app query templatesCVE-2026-50179Medium@actual-app/web: @actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes FieldsCVE-2026-54353High@budibase/backend-core: @budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validationCVE-2026-54352Critical@budibase/server: Budibase has arbitrary file read by workspace-builder via PWA-zip symlink uploadCVE-2026-54351High@budibase/server: Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId OverrideCVE-2026-49229High@actual-app/sync-server: @actual-app/sync-server: Disabled OpenID users keep access through existing session tokensCVE-2026-50137High@budibase/server: Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored…

Stop the waste.
Protect your environment with Kodem.