npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55638High9router: 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypassCVE-2026-54732Mediumlibreoffice-convert: libreoffice-convert vulnerable to path traversal / arbitrary file writeCVE-2026-54687Mediumn8n-nodes-sqlite3: n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)CVE-2026-54606Highsuneditor: SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe EmbedCVE-2026-54511High@logtape/syslog: @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keysCVE-2026-54356High@budibase/server: Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`CVE-2026-55605Medium@arikusi/deepseek-mcp-server: @arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP EndpointCVE-2026-55604High@arikusi/deepseek-mcp-server: @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled KeyCVE-2026-55609Highconsciousness-explorer: consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file writeCVE-2026-55629Highwhistle: Whistle vulnerable to path traversalCVE-2026-55663Mediummediasoup: mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)CVE-2026-55596High@platejs/media: Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScriptCVE-2026-55557Highbrowse-mcp: browse-mcp has an arbitrary file write via unconfined download and state pathsCVE-2026-55553Highurllib: urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakageGHSA-8QX3-8GM5-9CJ2Highpickem: pickem vulnerable to terminal escape-sequence injection via unsanitized item textCVE-2026-76845Mediumadm-zip: adm-zip extraction follows destination symlinks, allowing arbitrary file overwriteCVE-2026-77415Criticaljsonata: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressionsCVE-2026-77414Criticaljsonata: JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressionsCVE-2026-77413Criticaljsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressionsCVE-2026-63421High@keystone-6/core: Keystone vulnerable to `graphql.maxTake` bypass with negative `take`CVE-2026-61824Highdefuddle: Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractorsCVE-2026-63466Mediumunleash-server: Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted usernameCVE-2026-63004Mediumunleash-server: Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata…CVE-2026-63462Highunleash-server: Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatterCVE-2026-55451Mediumgettext-converter: gettext-converter: Prototype pollution in js2i18next() via crafted translation keys

Stop the waste.
Protect your environment with Kodem.