Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.8
npm

CVE-2026-54658

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

CRITICAL 9.8
npm

CVE-2026-69240

Sequelize: SQL Injection (Oracle DB)

CRITICAL 9.1
npm

CVE-2026-53609

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

CRITICAL 10.0
npm

CVE-2026-52887

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

CRITICAL 9.0
npm

CVE-2026-11393

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

CRITICAL 9.1
npm

GHSA-vh45-f885-3848

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

CRITICAL 9.6
npm

GHSA-q6x4-v3qx-85qw

Budibase: SQL Injection via `multipleStatements: true`

CRITICAL 10.0
npm

GHSA-w28w-gp39-m4p6

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

CRITICAL 9.8
npm

CVE-2026-59940

seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

CRITICAL 9.8
npm

GHSA-7gfh-x38p-prh3

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

CRITICAL 9.9
npm

GHSA-rjg6-39jm-rgg4

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

CRITICAL 10.0
npm

GHSA-9qr9-h5gf-34mp

Next.js is vulnerable to RCE in React flight protocol

CRITICAL 9.4
npm

GHSA-p63j-vcc4-9vmv

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

CRITICAL 9.1
npm

CVE-2025-71324

Flowise has an Arbitrary File Read

CRITICAL 9.6
npm

CVE-2026-59891

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

CRITICAL 9.4
npm

CVE-2026-50137

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

CRITICAL 9.1
npm

CVE-2026-4599

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

CRITICAL 9.9
npm

CVE-2026-57138

npm PraisonAI codeMode sandbox escape via Function constructor

CRITICAL 9.8
npm

CVE-2026-57141

PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool

CRITICAL 9.8
npm

CVE-2026-57139

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

CRITICAL 9.4
npm

CVE-2026-57140

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

CRITICAL 9.1
npm

CVE-2026-54316

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

CRITICAL 9.0
npm

CVE-2026-54157

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

CRITICAL 9.1
npm

CVE-2026-53512

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

CRITICAL 9.6
npm

CVE-2026-53513

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

CRITICAL 9.9
npm

CVE-2026-54305

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

CRITICAL 9.9
npm

CVE-2026-44791

n8n Has an XML Node Prototype Pollution Patch Bypass

CRITICAL 9.9
npm

CVE-2026-44789

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

CRITICAL 9.0
npm

CVE-2026-44792

n8n Has a Source Control Pull SQL Injection

CRITICAL 9.1
npm

CVE-2026-56348

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

CRITICAL 9.9
npm

CVE-2026-54310

n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes

CRITICAL 10.0
npm

CVE-2026-54309

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

CRITICAL 9.1
npm

CVE-2023-46233

crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard

CRITICAL 10.0
npm

CVE-2026-59801

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

CRITICAL 9.6
npm

CVE-2026-14722

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

CRITICAL 9.9
npm

CVE-2026-54052

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

CRITICAL 9.1
npm

CVE-2026-53486

Decompress: Archive extraction can create files and links outside of the target directory

CRITICAL 9.6
npm

CVE-2026-54307

n8n: Credential Exfiltration via Permission Bypass

CRITICAL 9.1
npm

CVE-2026-48814

Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests

CRITICAL 9.1
npm

CVE-2026-33807

@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes

CRITICAL 9.1
npm

CVE-2026-6270

@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

CRITICAL 10.0
npm

CVE-2026-47137

vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE

CRITICAL 9.8
npm

CVE-2023-37903

vm2 Sandbox Escape vulnerability

CRITICAL 9.3
npm

CVE-2025-50538

Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel

CRITICAL 9.1
npm

CVE-2025-9287

cipher-base is missing type checks, leading to hash rewind and passing on crafted data

CRITICAL 10.0
npm

CVE-2026-12537

Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

CRITICAL 9.9
npm

CVE-2026-32922

OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE

CRITICAL 10.0
npm

CVE-2025-71338

Flowise allows arbitrary file write to RCE

CRITICAL 9.1
npm

CVE-2025-9288

sha.js is missing type checks leading to hash rewind and passing on crafted data

CRITICAL 9.8
npm

CVE-2025-71334

Flowise has arbitrary file access due to missing chat flow id validation

CRITICAL 9.3
npm

CVE-2023-7080

Arbitrary remote code execution within `wrangler dev` Workers sandbox

CRITICAL 9.1
npm

CVE-2024-1631

agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`

CRITICAL 9.1
npm

GHSA-r5cq-9537-9rpf

Prototype Pollution in mixme

CRITICAL 9.8
npm

CVE-2022-25352

Prototype Pollution in libnested

CRITICAL 9.8
npm

CVE-2020-7674

Improper Input Validation in access-policy

CRITICAL 9.8
npm

CVE-2022-21190

Prototype Pollution in convict

CRITICAL 9.8
npm

CVE-2022-24437

OS Command Injection in git-pull-or-clone

CRITICAL 9.8
npm

CVE-2020-7621

OS Command Injection in strong-nginx-controller

CRITICAL 9.8
npm

CVE-2020-7706

Prototype Pollution in connie-lang

CRITICAL 9.8
npm

CVE-2021-23448

Prototype Pollution in config-handler

Ready to move

Start Securing

Free, no credit card | First findings in minutes