npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-71866Criticalorval: Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod clientCVE-2026-73845Medium@aborruso/ckan-mcp-server: CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)CVE-2026-82562Mediumqs: qs array-limit bypass via bracket-key comma parsingCVE-2026-82417Mediumqs: qs: Denial of Service via Attacker Controlled isBufferGHSA-CP6Q-959Q-F8RHMedium@tiptap/core: Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributesCVE-2026-82392Highpnpm: pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraphCVE-2026-82393Highpnpm: pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installGHSA-P498-V437-472GMedium@humanfs/node: humanfs: Recursive copy follows symlinked files and copies data from outside the source treeCVE-2026-73231High@faker-js/faker: Faker: helpers.fake exploitable into arbritary code executionCVE-2026-84371Mediumsanitize-html: ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypassCVE-2026-73086Highnanoid: nanoid: Integer Overflow or WraparoundGHSA-VX52-2968-3VC6Highpnpm: pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yamlGHSA-2RX9-3G3H-C2JVHighpnpm: pnpm: pacquet trust-lockfile install can create dependency symlinks outside the projectCVE-2026-58191Medium@appium/base-driver: Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesCVE-2026-73089Highbrowserslist: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOMCVE-2026-73088Highbrowserslist: Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)GHSA-3F6P-5WW8-9RCRHighmysql2: MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext CredentialsGHSA-RGWJ-5XJ2-C3M3Mediummysql2: MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoSCVE-2026-45822Mediumdecode-uri-component: decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded inputCVE-2026-59724Highengine.io: Socket.IO: Engine.IO WebTransport SID DoSCVE-2026-81888Medium@hono/oauth-providers: @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linkingCVE-2026-55855Mediummariadb: MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsetsCVE-2026-55854Mediummariadb: MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected CredentialsCVE-2026-55215Highmariadb: MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`CVE-2026-55641High9router: 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF

Stop the waste.
Protect your environment with Kodem.