npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-FCRW-F7GG-6G9FMedium@budibase/server: Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role UsersGHSA-4QCJ-M5WP-JMF4Medium@budibase/server: Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappingsGHSA-J9FC-W3MR-X6MVHigh@budibase/server: Budibase: Privilege escalation via public role assignment API missing app-level authorizationCVE-2026-44907Highreact-server-dom-webpack: react-server-dom: Denial of Service in Server FunctionsCVE-2026-55607High@anthropic-ai/claude-code: Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionGHSA-PM4M-PH32-GHV5Highjs-yaml: js-yaml: Exponential parsing time in flow collections leads to denial of serviceGHSA-QWWW-VCR4-C8H2Highreact-router: React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 ResponseGHSA-464C-974J-9XM6Lowaws-cdk-lib: AWS CDK CodeBuild S3 Log Encryption Boolean InversionCVE-2026-7120Medium@fastify/static: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL PathsCVE-2026-15074High@fastify/static: @fastify/static vulnerable to route guard bypass via path traversalGHSA-R292-9MHP-454MMediumtar: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selectionGHSA-R28C-9Q8G-F849Highpostcss: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureGHSA-W28W-GP39-M4P6Critical@prompty/core: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks RendererGHSA-664H-WQGQ-64GWMediummongoose: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)GHSA-7GFH-X38P-PRH3Criticalvelocityjs: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)GHSA-38HQ-7X33-PHP4Medium@backstage/plugin-auth-backend: @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypassGHSA-53G2-MVCC-Q9X3Mediumtrix: Trix: Stored XSS via HTMLParser attribute injection on pasteCVE-2026-59952Mediumvalibot: Valibot: record() issue paths can make flatten() throw for inherited Object property namesCVE-2026-59940Criticalseroval: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationGHSA-866W-XMHQ-WJ7XMedium@sveltejs/kit: SvelteKit: Prototype pollution in file input deletion path in remote-function formsGHSA-WQJV-9729-C5Q2Medium@sveltejs/kit: SvelteKit: Big remote form function payloads can cause Node process to crashGHSA-QQ9H-G4JM-XGF3Highbetter-auth: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-inGHSA-H3RM-78G3-J7CPHigh@better-auth/stripe: @better-auth/stripe: cross-organization billing tampering in organization subscription actionsGHSA-RJG6-39JM-RGG4Critical@better-auth/scim: @better-auth/scim: account takeover and stale access via SCIM provider-id collisionCVE-2026-55685Highreact-router: React Router: Unauthenticated Denial of Service via Inefficient Route Matching

Stop the waste.
Protect your environment with Kodem.