npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-69222Highliquidjs: LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the processCVE-2026-85063Mediumcsv-parse: node-csv: Prototype replacement still reachable via columns pathCVE-2026-72925Medium@swc/html: SWC HTML minifier may allow script element breakout when minifying embedded JSONGHSA-7Q9C-HPX7-9CWMHigh@typespec/spector: TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stopCVE-2026-75911Highdeepseek-tui: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repositoryCVE-2026-75858Highdeepseek-tui: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)CVE-2026-75912Highdeepseek-tui: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without ApprovalCVE-2026-75856Criticaldeepseek-tui: CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinningCVE-2026-75915Highdeepseek-tui: CodeWhale: js_execution leaks parent environment to model context via missing env scrubCVE-2026-75913Highdeepseek-tui: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without ApprovalCVE-2026-75857Highdeepseek-tui: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)CVE-2026-75859Highdeepseek-tui: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repositoryCVE-2026-75914Highdeepseek-tui: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytesGHSA-6HXQ-P678-4HR2Low@simplewebauthn/server: SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchorCVE-2026-77465Hightoml: toml-node: Uncontrolled RecursionCVE-2026-63376Hightoml: toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path DesynchronizationCVE-2026-56812Mediumphoenix: Phoenix: Presence keys colliding with `Object.prototype` members break existence checksCVE-2026-71429Mediumstream-json: stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for…CVE-2026-63670Mediumsanitize-html: ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus closeCVE-2026-63669Mediumapostrophe: ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a…CVE-2026-82404High@toon-format/toon: TOON: Prototype pollution when decoding untrusted TOON inputCVE-2026-73222Highclaude-code-templates: Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)CVE-2026-62681Criticalorval: Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)CVE-2026-62682Criticalorval: Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)CVE-2026-72717Criticalorval: Orval: Import-time RCE via schema default -> zod module-level template literal

Stop the waste.
Protect your environment with Kodem.