Vendor Intelligence

npm

126 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-54309 · CVSS 10

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

View CVE report →
CVE-2026-54305 · CVSS 9.9

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

View CVE report →
CVE-2026-54307 · CVSS 9.6

n8n: Credential Exfiltration via Permission Bypass

View CVE report →
CVE-2026-43941 · CVSS 8.8

Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click

View CVE report →
CVE-2026-43943 · CVSS 8.8

Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor

View CVE report →
CVE-2026-45716 · CVSS 8.8

Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration

View CVE report →
CVE-2026-45717 · CVSS 8.8

Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL

View CVE report →
CVE-2026-48017 · CVSS 8.8

DbGate: Remote Code Execution via functionName injection in loadReader endpoint

View CVE report →
CVE-2026-48054 · CVSS 8.8

OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri

View CVE report →
CVE-2026-49143 · CVSS 8.8

browserstack-runner vulnerable to Remote Code Execution via vm sandbox escape in _log HTTP handler

View CVE report →
CVE-2026-49255 · CVSS 8.8

electerm has Command Injection in File System Operations (rmrf, mv, cp)

View CVE report →
CVE-2026-49473 · CVSS 8.8

@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation

View CVE report →
CVE-2026-49987 · CVSS 8.8

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

View CVE report →
CVE-2026-50016 · CVSS 8.8

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

View CVE report →
CVE-2026-53806 · CVSS 8.8

OpenClaw: Combined POSIX shell options could confuse exec revalidation

View CVE report →
CVE-2026-53810 · CVSS 8.8

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

View CVE report →
CVE-2026-53811 · CVSS 8.8

OpenClaw: Matrix allowFrom could bind to mutable display names

View CVE report →
CVE-2026-53819 · CVSS 8.8

OpenClaw: Workspace .env could override Homebrew executable selection for skill install flows

View CVE report →
CVE-2026-54504 · CVSS 8.8

@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default

View CVE report →
CVE-2026-55698 · CVSS 8.8

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

View CVE report →
CVE-2026-28445 · CVSS 8.7

Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview

View CVE report →
CVE-2026-44295 · CVSS 8.7

protobuf.js: Code injection in pbjs static output from crafted schema names

View CVE report →
CVE-2026-44494 · CVSS 8.7

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

View CVE report →
CVE-2026-47135 · CVSS 8.7

vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks

View CVE report →
CVE-2026-47759 · CVSS 8.7

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

View CVE report →
CVE-2026-47760 · CVSS 8.7

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

View CVE report →
CVE-2026-47761 · CVSS 8.7

TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection

View CVE report →
CVE-2026-47762 · CVSS 8.7

TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments

View CVE report →
CVE-2026-48527 · CVSS 8.7

HaxCMS has a stored Cross-Site Scripting (XSS) bypass in its saveNode endpoint

View CVE report →
CVE-2026-42047 · CVSS 8.6

Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods

View CVE report →
CVE-2026-42089 · CVSS 8.6

yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation

View CVE report →
CVE-2026-44001 · CVSS 8.6

vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)

View CVE report →
CVE-2026-44492 · CVSS 8.6

axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

View CVE report →
CVE-2026-47139 · CVSS 8.6

NodeVM network builtin exclusions bypass via internal _http_client and _http_server

View CVE report →
CVE-2026-47209 · CVSS 8.6

vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain

View CVE report →
CVE-2026-48795 · CVSS 8.6

@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754

View CVE report →
CVE-2026-50131 · CVSS 8.6

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

View CVE report →
CVE-2026-42226 · CVSS 8.5

n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay

View CVE report →
CVE-2026-42449 · CVSS 8.5

n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders

View CVE report →
CVE-2026-43998 · CVSS 8.5

vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape

View CVE report →
CVE-2026-46372 · CVSS 8.5

SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

View CVE report →
CVE-2026-48153 · CVSS 8.5

Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata

View CVE report →
CVE-2026-49444 · CVSS 8.5

n8n: Python sandbox escape

View CVE report →
CVE-2026-54312 · CVSS 8.5

n8n: Microsoft SQL Node Prototype Pollution

View CVE report →
CVE-2026-54353 · CVSS 8.5

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

View CVE report →
CVE-2026-53814 · CVSS 8.4

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

View CVE report →
CVE-2026-44966 · CVSS 8.3

Velocity.js has a Prototype Pollution vulnerability through #set path assignment

View CVE report →
CVE-2026-49229 · CVSS 8.3

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

View CVE report →
CVE-2026-42235 · CVSS 8.2

n8n Vulnerable to XSS via MCP OAuth client

View CVE report →
CVE-2026-42353 · CVSS 8.2

i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters

View CVE report →
CVE-2026-43893 · CVSS 8.2

exiftool-vendored vulnerable to argument injection via newline characters in tag names

View CVE report →
CVE-2026-44483 · CVSS 8.2

@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data)

View CVE report →
CVE-2026-44728 · CVSS 8.2

@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input

View CVE report →
CVE-2026-45302 · CVSS 8.2

parse-nested-form-data has Prototype Pollution via `__proto__` in FormData field names

View CVE report →
CVE-2026-45325 · CVSS 8.2

@tmlmobilidade/utils has prototype pollution in its setValueAtPath

View CVE report →
CVE-2026-46509 · CVSS 8.2

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @ranfdev/deepobj

View CVE report →
CVE-2026-46510 · CVSS 8.2

form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys

View CVE report →
CVE-2026-47423 · CVSS 8.2

DOMPurify XSS via selectedcontent re-clone

View CVE report →
CVE-2026-47719 · CVSS 8.2

FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading

View CVE report →
CVE-2026-54351 · CVSS 8.2

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

View CVE report →
CVE-2026-59731 · CVSS 8.2

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

View CVE report →
CVE-2026-42211 · CVSS 8.1

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

View CVE report →
CVE-2026-44291 · CVSS 8.1

protobuf.js: Code generation gadget after prototype pollution

View CVE report →
CVE-2026-45013 · CVSS 8.1

Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation

View CVE report →
CVE-2026-45665 · CVSS 8.1

Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order

View CVE report →
CVE-2026-45707 · CVSS 8.1

n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete

View CVE report →
CVE-2026-48152 · CVSS 8.1

Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL

View CVE report →
CVE-2026-50143 · CVSS 8.1

Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token

View CVE report →
CVE-2026-53517 · CVSS 8.1

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

View CVE report →
CVE-2026-53518 · CVSS 8.1

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

View CVE report →
CVE-2026-53849 · CVSS 8.1

OpenClaw: Discord allowFrom could bind to mutable display names

View CVE report →
CVE-2026-53855 · CVSS 8.1

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

View CVE report →
CVE-2026-53857 · CVSS 8.1

OpenClaw: Zalo allowFrom could bind to mutable display names

View CVE report →
CVE-2026-33245 · CVSS 8

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

View CVE report →
CVE-2026-53817 · CVSS 8

OpenClaw: Control UI locality spoofing could mint a durable admin device token

View CVE report →
CVE-2026-42290 · CVSS 7.8

protobuf.js is Vulnerable to OS Command Injection in the CLI

View CVE report →
CVE-2026-44724 · CVSS 7.8

Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name

View CVE report →
CVE-2026-53813 · CVSS 7.8

OpenClaw: Fake package roots could influence memory-core artifact loading

View CVE report →
CVE-2026-54074 · CVSS 7.8

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

View CVE report →
CVE-2026-61835 · CVSS 7.7

Directus: SSRF Protection Bypass via 0.0.0.0 in File Import

View CVE report →
CVE-2026-46701 · CVSS 7.6

Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

View CVE report →
CVE-2026-34077 · CVSS 7.5

React Router vulnerable to Denial of Service via reflected user input in single-fetch

View CVE report →
CVE-2026-42342 · CVSS 7.5

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

View CVE report →
CVE-2026-42856 · CVSS 7.5

Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls

View CVE report →
CVE-2026-43897 · CVSS 7.5

link-preview-js vulnerable to IPv6 and internal loopback attacks

View CVE report →
CVE-2026-43945 · CVSS 7.5

FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection

View CVE report →
CVE-2026-44232 · CVSS 7.5

dssrf: every IPv6 category bypasses is_url_safe

View CVE report →
CVE-2026-44648 · CVSS 7.5

SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover

View CVE report →
CVE-2026-44705 · CVSS 7.5

tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

View CVE report →
CVE-2026-44895 · CVSS 7.5

@yoda.digital/gitlab-mcp-server's SSE transport has no authentication and wildcard CORS, exposing all 86 GitLab tools

View CVE report →
CVE-2026-44974 · CVSS 7.5

@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters

View CVE report →
CVE-2026-45109 · CVSS 7.5

Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

View CVE report →
CVE-2026-46417 · CVSS 7.5

@angular/platform-server: SSRF via Hostname Hijacking

View CVE report →
CVE-2026-46490 · CVSS 7.5

samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions

View CVE report →
CVE-2026-46679 · CVSS 7.5

js-libp2p: Memory DoS via subscription flood of unique topics

View CVE report →
CVE-2026-46681 · CVSS 7.5

@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty

View CVE report →
CVE-2026-48007 · CVSS 7.5

Element Call reports full URLs of visited pages to analytics server

View CVE report →
CVE-2026-49250 · CVSS 7.5

@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields

View CVE report →
CVE-2026-49357 · CVSS 7.5

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

View CVE report →
CVE-2026-50137 · CVSS 7.5

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

View CVE report →
CVE-2026-50555 · CVSS 7.5

@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

View CVE report →
CVE-2026-50556 · CVSS 7.5

@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR

View CVE report →
CVE-2026-5079 · CVSS 7.5

Multer vulnerable to Denial of Service via deeply nested field names

View CVE report →
CVE-2026-53571 · CVSS 7.5

vite: `server.fs.deny` bypass on Windows alternate paths

View CVE report →
CVE-2026-55487 · CVSS 7.5

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

View CVE report →
CVE-2026-55660 · CVSS 7.5

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

View CVE report →
CVE-2026-55697 · CVSS 7.5

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

View CVE report →
CVE-2026-6321 · CVSS 7.5

fast-uri vulnerable to path traversal via percent-encoded dot segments

View CVE report →
CVE-2026-6322 · CVSS 7.5

fast-uri vulnerable to host confusion via percent-encoded authority delimiters

View CVE report →
CVE-2026-6734 · CVSS 7.5

undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

View CVE report →
CVE-2026-7768 · CVSS 7.5

@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth

View CVE report →
CVE-2026-8159 · CVSS 7.5

multiparty vulnerable to ReDoS via filename parsing

View CVE report →
CVE-2026-8813 · CVSS 7.5

ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag

View CVE report →
CVE-2026-42033 · CVSS 7.4

Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

View CVE report →
CVE-2026-42035 · CVSS 7.4

Axios: Header Injection via Prototype Pollution

View CVE report →
CVE-2026-42264 · CVSS 7.4

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

View CVE report →
CVE-2026-49857 · CVSS 7.4

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

View CVE report →
CVE-2026-11417 · CVSS 7.3

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

View CVE report →
CVE-2026-50015 · CVSS 7.3

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

View CVE report →
CVE-2026-54328 · CVSS 7.3

Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts

View CVE report →
CVE-2026-42043 · CVSS 7.2

Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

View CVE report →
CVE-2026-50146 · CVSS 7.1

Astro: Reflected XSS via unescaped slot name

View CVE report →
CVE-2026-53846 · CVSS 7.1

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

View CVE report →
CVE-2026-53858 · CVSS 7.1

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

View CVE report →
CVE-2026-53865 · CVSS 7.1

OpenClaw: Workspace-derived service PATH could influence trash command selection

View CVE report →
CVE-2026-55700 · CVSS 7.1

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

View CVE report →