npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-86075Highn8n: n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration EndpointCVE-2026-86076Highn8n: n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code ExecutionGHSA-X7M8-JRM8-HPVXHigh@eigenpal/docx-editor-core: @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family nameCVE-2026-59179High@openhop/server: @openhop/server: Path Traversal in Flow ID File OperationsCVE-2026-59176Highfunctype-mcp-server: functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic ImportCVE-2026-59160High@yeger/turbo-graph: @yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/runCVE-2026-59158Highnuxt-ollama: Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser ClientsCVE-2026-85730Highsmol-toml: smol-toml: Denial of Service via malformed TOML documentsCVE-2026-86996Mediumn8n: n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller PolicyGHSA-WMMP-3585-3RMPMediumnodemailer: Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domainGHSA-2X7J-588G-CCC2Highnodemailer: Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address listGHSA-CC9R-2J5M-2M83Mediumnodemailer: Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domainGHSA-2Q42-4Q24-7RGVHigh@typespec/openapi3: OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output treeCVE-2026-77078Highmulter: multer vulnerable to Denial of Service via crafted multipart field namesCVE-2026-77037Highmulter: multer vulnerable to Denial of Service via file descriptor leak on aborted uploadsCVE-2026-77063Lowmulter: multer vulnerable to file size limit bypass via async fileFilter race conditionCVE-2026-82333Highmulter: multer vulnerable to Denial of Service via oversized array index in field namesCVE-2026-15603Mediummorgan: morgan vulnerable to Log Forging via unescaped Unicode line separatorsGHSA-26W7-CXV4-GFX2Criticalastro: Astro: Remote code execution through AVIF image optimizationCVE-2026-84376Mediumastro: Astro: Authorization bypass from missing path-segment boundary check when stripping the configured baseGHSA-RGJ7-G3M4-5G8CHighsharp: sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545CVE-2026-84375Highjs-yaml: js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sourcesGHSA-J95F-988M-3J2FHigh@tiptap/core: Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsingCVE-2026-84365Mediumhono: Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directoryCVE-2026-84364Mediumhono: Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

Stop the waste.
Protect your environment with Kodem.