npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-63643Mediummagicmirror: MagicMirror: ssrf calendar .jsCVE-2026-63642Mediummagicmirror: MagicMirror newsfeed Socket.IO notification allows blind server-side request forgeryCVE-2026-63641Lowmagicmirror: MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actionsGHSA-2MF3-MR2R-R4VFHigh@rhinostone/swig: @rhinostone/swig: arbitrary local file read via include/extends path traversalCVE-2026-69148Highmlflow: MLflow: CreateModelVersion source validation does not check READ permission on referenced run_idCVE-2026-69146Mediummlflow: MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-authCVE-2026-56677High9router: 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test EndpointCVE-2026-53766Mediumchrome-devtools-mcp: chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing rootsCVE-2026-55090Highep_etherpad-lite: Etherpad has stored XSS in HTML export via unescaped attribute-pool valuesGHSA-92HR-GMR6-H8CPMediumep_etherpad-lite: Etherpad addressed weak token RNG, login timing, plugin path handling, API request handlingGHSA-V836-6XW4-9CX3Highvm2: vm2 has Memory Exhaustion DoS via bufferAllocLimit BypassGHSA-M5W8-4GQ2-6F8XCriticalvm2: vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of…CVE-2026-47698Criticalvm2: vm2: Sandbox Breakout Using Dangerous Host Proto MutatorsCVE-2026-47686Criticalvm2: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCECVE-2026-47683Highvm2: vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLikeCVE-2026-19693Highextract-zip: extract-zip allows arbitrary file writes through symlink archive entriesCVE-2026-53728High@medplum/core: Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code LeakageCVE-2026-40345Highdeepmerge-ts: DeepmergeTS has stack exhaustion when merging recursive object graphsCVE-2026-55156Medium@ooples/token-optimizer-mcp: Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API EndpointsCVE-2026-55157High@ooples/token-optimizer-mcp: Token Optimizer MCP: OS command injection in smart_user via username in get-user-infoCVE-2026-35219High@budibase/server: Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP BlacklistCVE-2026-73654High@trigger.dev/core: Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoSCVE-2026-55102Mediumhashi-vault-js: hashi-vault-js: Vault token and secret values exposed in thrown errorsCVE-2026-55088Mediumep_etherpad-lite: ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenCVE-2026-55086Mediumep_etherpad-lite: ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite

Stop the waste.
Protect your environment with Kodem.