npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-65593Mediumn8n: n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network AccessCVE-2026-65595Highn8n: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTsCVE-2026-59208Highn8n: n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity ResolutionCVE-2026-59207Highn8n: n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP ConnectorCVE-2026-59206Highn8n: n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project EnumerationCVE-2026-59209Highn8n: n8n: Shared Credential Header Leak via HTTP Request Pagination ExpressionCVE-2026-65599Mediumn8n: n8n: Google Service Account Private Key Exposed in JWT HeaderCVE-2026-65592Highn8n: n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`CVE-2026-65597Highn8n: n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML PreviewCVE-2026-65598Highn8n: n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code ExecutionCVE-2026-65015Highn8n: n8n: AI Agents Project Viewer Privilege Escalation via run_node_toolCVE-2026-16221Highfast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-F88M-G3JW-G9CJHighsharp: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591GHSA-8R6M-32JQ-JX6QHighfast-xml-parser: fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limitsGHSA-9MQV-5HH9-4CGGMedium@hono/node-server: Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshakeGHSA-2RP8-MM9Q-FP49Mediumtypeorm: TypeORM: migration:generate template-literal code injectionGHSA-2P49-HGCM-8545Highsvgo: SVGO removeScripts plugin leaves some executable scripts intactGHSA-C2J3-45GR-MQC4Lowdompurify: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.GHSA-P63J-VCC4-9VMVCritical@vitest/browser: @vitest/browser: Browser Mode provider commands bypass the file-access permission gateCVE-2026-59891Critical@sigstore/oci: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registryCVE-2026-59892High@opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed headerCVE-2026-59887Highlinkify-it: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker textCVE-2026-13760Highaws-cdk-lib: aws-cdk-lib: OS Command Injection in NodejsFunction Docker BundlingCVE-2026-13676Highfast-uri: fast-uri vulnerable to host confusion via failed IDN canonicalizationCVE-2026-59880Highimmutable: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

Stop the waste.
Protect your environment with Kodem.