Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 6.3
npm

CVE-2026-70597

Electron: Parent process code-sign check is spoofable

MEDIUM 5.3
npm

CVE-2026-69207

Hono: ReDoS in CORS middleware via Access-Control-Request-Headers

MEDIUM 5.3
npm

CVE-2026-53949

Ghost Content API filter bypass reveals private fields

MEDIUM 4.0
npm

CVE-2026-70595

Ghost: Server-Side Request Forgery Mitigation Issue

MEDIUM 4.3
npm

CVE-2026-70596

Ghost: Cross-Site Scripting in Feature Image Captions

HIGH 7.5
npm

CVE-2026-53950

XSS in Ghost's ActivityPub client

UNKNOWN
npm

GHSA-gj2h-2fpw-fhv9

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

MEDIUM 5.3
npm

CVE-2026-59817

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

MEDIUM 5.3
npm

CVE-2026-53947

Ghost: Member existence leak via magic link sign-in response

MEDIUM 6.7
npm

CVE-2026-70594

Ghost: Session Fixation in Ghost Admin

MEDIUM 6.6
npm

CVE-2026-70593

Ghost: Theme Upload Path Traversal

MEDIUM 5.5
npm

CVE-2026-70592

Ghost: Database Backup Path Traversal

MEDIUM 4.8
npm

CVE-2026-70590

Ghost: Blind Password Hash Disclosure in Ghost Admin API

MEDIUM 4.1
npm

CVE-2026-70591

Ghost: Server-Side Request Forgery in Image Fetching

MEDIUM 5.8
npm

CVE-2026-53944

Ghost: Private IP filtering bypass to make server-side requests to internal services

MEDIUM 5.4
npm

CVE-2026-53946

Ghost: Mobiledoc image-size fetch SSRF

MEDIUM 4.0
npm

CVE-2026-53945

Ghost: Server-side request forgery via DNS rebinding in external request handling

UNKNOWN
npm

CVE-2026-40181

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

UNKNOWN
npm

CVE-2026-69198

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

HIGH 7.5
npm

CVE-2026-69152

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

HIGH 8.2
npm

GHSA-2p49-hgcm-8545

SVGO removeScripts plugin leaves some executable scripts intact

HIGH 7.5
npm

CVE-2026-18446

fast-uri vulnerable to host confusion via backslash authority introducer

HIGH 7.4
npm

CVE-2026-13697

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

UNKNOWN
npm

CVE-2026-69153

PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset

MEDIUM 4.8
npm

CVE-2026-16729

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

UNKNOWN
npm

CVE-2026-54272

ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks

MEDIUM 4.8
npm

CVE-2026-16728

undici vulnerable to downstream response desynchronization via retry interceptor

MEDIUM 4.2
npm

CVE-2026-15157

undici vulnerable to CRLF Injection via blob-like body 'type' property

UNKNOWN
npm

CVE-2026-69192

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

MEDIUM 5.9
npm

CVE-2026-14643

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

MEDIUM 5.0
npm

CVE-2026-70588

Ghost: Cross-Site Scripting in Universal Import

MEDIUM 5.4
npm

CVE-2026-53948

Ghost: File Upload Content-Type Spoofing

MEDIUM 4.8
npm

CVE-2026-70589

Ghost: Archived Offers can be Redeemed

CRITICAL 9.8
npm

CVE-2026-54658

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

UNKNOWN
npm

CVE-2026-70478

Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service

UNKNOWN
npm

CVE-2026-70477

Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

UNKNOWN
npm

GHSA-8gj2-2cvc-6xx7

Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

UNKNOWN
npm

CVE-2026-70475

Flowise: Missing Authorization on Execution Update Endpoint

UNKNOWN
npm

CVE-2026-70476

Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation

UNKNOWN
npm

CVE-2026-70474

Flowise: Cross-Workspace OAuth2 Credential Metadata Leak

UNKNOWN
npm

CVE-2026-69256

Flowise: Remote Code Execution Vulnerability in CSVAgent

UNKNOWN
npm

CVE-2026-70471

Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

UNKNOWN
npm

GHSA-88pr-878c-24wf

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

MEDIUM 6.5
npm

GHSA-rwrp-9823-p2xq

Flowise: Incomplete Credential Redaction Exposes Secrets via API

UNKNOWN
npm

CVE-2026-70472

Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store

UNKNOWN
npm

CVE-2026-70473

Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history

UNKNOWN
npm

CVE-2026-69264

Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

UNKNOWN
npm

CVE-2026-70470

Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE

UNKNOWN
npm

CVE-2026-69263

Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

UNKNOWN
npm

CVE-2026-69262

Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type

UNKNOWN
npm

CVE-2026-69259

Flowise RCE via SQLite Record Manager Node

UNKNOWN
npm

CVE-2026-69257

Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses

UNKNOWN
npm

CVE-2026-69258

Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API

UNKNOWN
npm

CVE-2026-69254

Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

UNKNOWN
npm

CVE-2026-69255

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

UNKNOWN
npm

CVE-2026-69253

Flowise Sandbox Escape to RCE

UNKNOWN
npm

CVE-2026-69252

Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization

UNKNOWN
npm

CVE-2026-69251

Flowise RCE via TypeORM DataSource

UNKNOWN
npm

CVE-2026-69250

Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration

UNKNOWN
npm

GHSA-2364-jh4q-m9vm

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

Ready to move

Start Securing

Free, no credit card | First findings in minutes