Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.7
npm

CVE-2026-33060

SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks

MEDIUM 5.7
npm

CVE-2026-53509

@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)

MEDIUM 5.7
npm

CVE-2026-61612

@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509

UNKNOWN
npm

CVE-2026-63628

mppx: Gas Draining with access list

UNKNOWN
npm

CVE-2026-76909

Unleash: CR-approval email renders user-controlled raw HTML

UNKNOWN
npm

CVE-2026-77426

Unleash: Missing await on permission check + cross-project IDOR in admin API

MEDIUM 4.3
npm

CVE-2026-77425

Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log

UNKNOWN
npm

CVE-2026-63627

mppx: Gas Draining with padding

UNKNOWN
npm

CVE-2026-75510

Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme

UNKNOWN
npm

CVE-2026-76910

Unleash: Clone-feature lets a user copy a feature from a project they cannot read

HIGH 8.8
npm

CVE-2026-63116

deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes

HIGH 7.5
npm

CVE-2026-62985

request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process

MEDIUM 5.3
npm

CVE-2026-56682

9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header

HIGH 7.3
npm

CVE-2026-56681

9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header

MEDIUM 6.5
npm

CVE-2026-58270

Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`

UNKNOWN
npm

CVE-2026-61647

@roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory

MEDIUM 5.3
npm

CVE-2026-58272

Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)

HIGH 8.1
npm

CVE-2026-58269

Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`

MEDIUM 6.8
npm

CVE-2026-58271

@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`

CRITICAL 9.8
npm

CVE-2026-12866

expr-eval vulnerable to Code Execution

CRITICAL 9.1
npm

CVE-2025-61686

React Router has Path Traversal in File Session Storage

MEDIUM 6.1
npm

CVE-2026-56326

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

HIGH 8.2
npm

CVE-2026-91127

File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

HIGH 7.5
npm

CVE-2026-77301

adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)

MEDIUM 6.1
npm

CVE-2026-84992

md-editor-v3: XSS via fenced-code language rendering bypass

UNKNOWN
npm

CVE-2026-71869

Orval: Import-time RCE via array-items default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-71868

Orval: Import-time RCE via enum-typed default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-62681

Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)

UNKNOWN
npm

CVE-2026-62682

Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

UNKNOWN
npm

CVE-2026-71864

Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client

UNKNOWN
npm

CVE-2026-72717

Orval: Import-time RCE via schema default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-71865

Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli

MEDIUM 5.3
npm

CVE-2026-92963

vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`

HIGH 7.5
npm

CVE-2026-92961

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

UNKNOWN
npm

CVE-2026-92962

vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter

CRITICAL 10.0
npm

CVE-2026-92960

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

MEDIUM 6.1
npm

CVE-2026-88976

@platejs/core HTML deserialization can trigger browser behavior during parsing

MEDIUM 5.3
npm

CVE-2026-81176

Svelte devalue: DoS via malformed input

CRITICAL 9.4
npm

CVE-2026-76969

@sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)

HIGH 8.2
npm

CVE-2026-86039

libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses

HIGH 7.5
npm

CVE-2026-86038

libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID

MEDIUM 5.0
npm

CVE-2026-54546

TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard

HIGH 7.5
npm

CVE-2026-85715

ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion

HIGH 8.8
npm

CVE-2026-63506

Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site

MEDIUM 4.4
npm

CVE-2026-63225

Redocly CLI: Path traversal when using `split` command

CRITICAL 9.1
npm

CVE-2026-63472

Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification

HIGH 8.7
npm

CVE-2026-63459

Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

UNKNOWN
npm

CVE-2026-61793

Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter

MEDIUM 5.3
npm

CVE-2026-63461

Vendure: Shop API list queries can return non-public entities when filterOperator is OR

UNKNOWN
npm

CVE-2026-71538

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows

UNKNOWN
npm

CVE-2026-77360

oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass

HIGH 7.5
npm

CVE-2026-63460

Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends

HIGH 7.5
npm

CVE-2026-92596

Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

MEDIUM 6.5
npm

CVE-2026-92597

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

MEDIUM 5.9
npm

CVE-2026-92595

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

MEDIUM 6.5
npm

CVE-2026-92598

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

MEDIUM 4.7
npm

CVE-2026-68921

DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)

UNKNOWN
npm

CVE-2026-58201

Lokka: Azure Resource Manager URL path validation issue

HIGH 8.1
npm

CVE-2026-63671

@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration

HIGH 7.5
npm

CVE-2026-59879

Immutable.js `List` 32-bit trie overflow → unrecoverable DoS

Ready to move

Start Securing

Free, no credit card | First findings in minutes