Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

33,826 vulnerabilities

UNKNOWN
npm

CVE-2026-79743

MCPHub has Path Traversal via Malicious MCPB Manifest Name

MEDIUM 6.5
npm

CVE-2026-82864

PDFME Affected by Decompression Bomb in FlateDecode Stream Parsing Causes Memory Exhaustion DoS

MEDIUM 5.4
npm

CVE-2026-82660

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

MEDIUM 5.3
npm

CVE-2024-58379

nodemailer ReDoS when trying to send a specially crafted email

MEDIUM 6.5
npm

CVE-2026-82662

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

UNKNOWN
npm

CVE-2026-82855

@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails

MEDIUM 5.4
npm

CVE-2026-82661

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

MEDIUM 4.4
npm

CVE-2026-82865

PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel

MEDIUM 6.1
npm

CVE-2026-82867

Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas

UNKNOWN
npm

CVE-2026-82856

@hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators

UNKNOWN
npm

CVE-2026-82860

@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies

MEDIUM 6.8
npm

CVE-2026-82866

PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled

MEDIUM 4.9
npm

CVE-2026-82853

Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)

UNKNOWN
npm

CVE-2026-82854

Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter

UNKNOWN
npm

CVE-2026-82861

@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass

UNKNOWN
npm

CVE-2026-82858

@hulumi/drift: Orphan reconciler accepted externally supplied execute plans

UNKNOWN
npm

CVE-2026-82863

@hulumi/baseline: CloudTrail selector tampering events were not fully detected

MEDIUM 6.1
npm

CVE-2026-82868

Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas

HIGH 7.5
npm

CVE-2026-59724

Socket.IO: Engine.IO WebTransport SID DoS

MEDIUM 5.4
npm

CVE-2026-81888

@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking

HIGH 7.5
npm

CVE-2026-13676

fast-uri vulnerable to host confusion via failed IDN canonicalization

LOW 3.7
npm

CVE-2026-2391

qs's arrayLimit bypass in comma parsing allows denial of service

MEDIUM 6.1
npm

CVE-2026-56326

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

HIGH 7.5
npm

CVE-2026-9496

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

UNKNOWN
npm

CVE-2026-82258

@sveltejs/kit: `query.batch` cross-talk

MEDIUM 5.3
npm

CVE-2026-82256

SvelteKit: Big remote form function payloads can cause Node process to crash

MEDIUM 4.3
npm

CVE-2026-82257

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

UNKNOWN
npm

CVE-2026-82259

SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)

HIGH 8.2
npm

CVE-2026-55641

9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF

HIGH 8.6
npm

CVE-2026-55638

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

HIGH 7.7
npm

CVE-2026-53832

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

HIGH 7.5
npm

GHSA-35c7-4r45-9gv3

Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

LOW 3.7
npm

GHSA-chqm-wxm2-w73w

Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing

HIGH 7.5
npm

CVE-2026-53834

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

LOW 3.7
npm

CVE-2026-53837

OpenClaw: Mattermost handlers could fall open when channel type was missing

HIGH 7.7
npm

GHSA-3qg8-hq7j-jj33

Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

HIGH 7.5
npm

CVE-2026-55697

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

HIGH 8.2
npm

CVE-2026-73650

SVGO removeScripts plugin leaves some executable scripts intact

HIGH 7.7
npm

CVE-2026-53833

OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

HIGH 7.7
npm

GHSA-r27j-fxmq-rg2q

Duplicate Advisory: OpenClaw: QQBot streaming command could mutate config without explicit allowFrom

HIGH 7.5
npm

CVE-2026-54156

node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS

MEDIUM 6.5
npm

CVE-2026-54732

libreoffice-convert vulnerable to path traversal / arbitrary file write

UNKNOWN
npm

CVE-2026-54687

n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)

UNKNOWN
npm

CVE-2026-73412

Shescape: Path disclosure on Unix with Zsh

UNKNOWN
npm

CVE-2026-54606

SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed

CRITICAL 9.8
npm

CVE-2026-50880

YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution

HIGH 8.6
npm

CVE-2026-54511

@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys

HIGH 7.1
npm

CVE-2026-54356

Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`

UNKNOWN
npm

CVE-2025-27597

Vue I18n Allows Prototype Pollution in `handleFlatJson`

CRITICAL 9.8
npm

GHSA-c85p-9pvr-f7f5

Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state

HIGH 8.6
npm

CVE-2026-55604

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

MEDIUM 5.3
npm

CVE-2026-55605

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

MEDIUM 5.6
npm

CVE-2026-55663

mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)

CRITICAL 9.8
npm

CVE-2026-53838

OpenClaw: Node pairing reconnection could confuse approval scope state

HIGH 8.3
npm

GHSA-gwcq-453v-2frr

Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

HIGH 7.1
npm

CVE-2026-53831

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

HIGH 8.8
npm

GHSA-ffhm-8fwq-7q27

Duplicate Advisory: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

HIGH 8.8
npm

CVE-2026-53836

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

LOW 3.1
npm

CVE-2026-2366

Keycloak vulnerable to authorization bypass via the Admin API

HIGH 7.1
npm

CVE-2026-55609

consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write

Ready to move

Start Securing

Free, no credit card | First findings in minutes