npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-63669Mediumapostrophe: ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a…CVE-2026-82404High@toon-format/toon: TOON: Prototype pollution when decoding untrusted TOON inputCVE-2026-73222Highclaude-code-templates: Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)CVE-2026-62681Criticalorval: Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)CVE-2026-62682Criticalorval: Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)CVE-2026-72717Criticalorval: Orval: Import-time RCE via schema default -> zod module-level template literalCVE-2026-71869Criticalorval: Orval: Import-time RCE via array-items default -> zod module-level template literalCVE-2026-71871Criticalorval: Orval: Import-time RCE via header-parameter default -> zod module-level template literalCVE-2026-71867Criticalorval: Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generatorCVE-2026-71868Criticalorval: Orval: Import-time RCE via enum-typed default -> zod module-level template literalCVE-2026-71865Criticalorval: Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cliCVE-2026-71864Criticalorval: Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod clientCVE-2026-61556Highliquidjs: LiquidJS has an infinite loop vulnerability in its `strip_html` filterGHSA-W8WF-3QVJ-6XQFHigh@openclaw/feishu: OpenClaw Feishu permission tools could ignore per-account disablementGHSA-2Q7J-2VHX-56G8High@openclaw/feishu: OpenClaw Feishu tools could ignore per-account disablementCVE-2026-73846Medium@aborruso/ckan-mcp-server: CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoningCVE-2026-73844Low@aborruso/ckan-mcp-server: CKAN MCP Server: Information disclosure via verbose error reflectionCVE-2026-68921Medium@dicebear/core: DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)CVE-2026-65842High@platejs/docx-io: Plate: SSRF with response disclosure in DOCX image embeddingCVE-2026-61704Highlink-preview-js: link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897CVE-2026-75931Highfast-uri: fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative referencesCVE-2026-75975Highfast-uri: fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizationCVE-2026-75899Highfast-uri: fast-uri vulnerable to server-side request forgery via repeated hostname percent-decodingCVE-2026-76172Highfast-uri: fast-uri vulnerable to host confusion via percent-encoded scheme normalizationCVE-2026-83610Medium@xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization

Stop the waste.
Protect your environment with Kodem.