3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether tmp is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-44705
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
HIGH 8.2
CVE-2026-49982
tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
LOW 2.5
CVE-2025-54798
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes