npm
OSS Librariespackage-ecosystem
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting npm.
- GHSA-5648-rgj9-v224@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
- GHSA-x7m8-jrm8-hpvx@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
- GHSA-wmmp-3585-3rmpNodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
- GHSA-2x7j-588g-ccc2Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
- GHSA-cc9r-2j5m-2m83Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
- GHSA-2q42-4q24-7rgvOpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
- GHSA-26w7-cxv4-gfx2Astro: Remote code execution through AVIF image optimization
- GHSA-rgj7-g3m4-5g8csharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
- GHSA-j95f-988m-3j2fTiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
- GHSA-2xp9-vwfh-vxw4Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
- GHSA-8m3c-c648-2xjjNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
- GHSA-7q9c-hpx7-9cwmTypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- GHSA-6hxq-p678-4hr2SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
- GHSA-w8wf-3qvj-6xqfOpenClaw Feishu permission tools could ignore per-account disablement
- GHSA-2q7j-2vhx-56g8OpenClaw Feishu tools could ignore per-account disablement