npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-GHVF-QF6H-G8X5High@nocobase/server: NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code executionCVE-2026-55445Critical@whyour/qinglong: Qinglong has an incomplete fix for CVE-2026-3965: Improper AuthenticationCVE-2026-54156Highnode-opcua: node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoSCVE-2026-54155Highnode-opcua: node-opcua missing nonce verification in UserNameIdentityToken authenticationCVE-2026-54150Mediumnext-video: next-video: Unauthenticated arbitrary file read via /api/video request handlerCVE-2026-55410Medium@nocobase/plugin-backups: NocoBase backup restore schema name allows command injectionCVE-2026-63123Medium@tinacms/cli: Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media rootCVE-2026-59992Mediumnext-tinacms-s3: Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)CVE-2026-63188High@logto/tunnel: logto-tunnel serves files outside --experience-path via path traversalGHSA-HJWH-XVFW-QRWJMediummcp-searxng: SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error ResponsesCVE-2026-54689Mediummcp-searxng: SearXNG MCP Server: Additional hardened-mode SSRF bypassesCVE-2026-54688Mediummcp-searxng: SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)CVE-2026-53957High@contentful/mcp-server: Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to…GHSA-RR55-JP92-8WP2Highclaude-faf-mcp: claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF toolsGHSA-J4R7-8PH4-43G3Highfaf-mcp: faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF toolsGHSA-CC2G-GQ8C-R332Highgrok-faf-mcp: grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF toolsGHSA-C7HR-448W-65PXHighmeshcentral: MeshCentral has unsanitized data fieldsCVE-2026-63640Mediummagicmirror: MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variablesCVE-2026-55178High@geolens/sdk: GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile…CVE-2026-63643Mediummagicmirror: MagicMirror: ssrf calendar .jsCVE-2026-63642Mediummagicmirror: MagicMirror newsfeed Socket.IO notification allows blind server-side request forgeryCVE-2026-63641Lowmagicmirror: MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actionsGHSA-2MF3-MR2R-R4VFHigh@rhinostone/swig: @rhinostone/swig: arbitrary local file read via include/extends path traversalCVE-2026-69148Highmlflow: MLflow: CreateModelVersion source validation does not check READ permission on referenced run_idCVE-2026-69146Mediummlflow: MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

Stop the waste.
Protect your environment with Kodem.