Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

CRITICAL 9.8
npm

CVE-2026-12866

expr-eval vulnerable to Code Execution

CRITICAL 9.1
npm

CVE-2025-61686

React Router has Path Traversal in File Session Storage

CRITICAL 10.0
npm

CVE-2026-92960

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

CRITICAL 9.4
npm

CVE-2026-76969

@sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)

CRITICAL 9.1
npm

CVE-2026-63472

Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification

CRITICAL 9.8
npm

CVE-2026-61560

@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover

CRITICAL 9.6
npm

CVE-2026-61559

@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

CRITICAL 9.6
npm

CVE-2026-61568

@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

CRITICAL 9.8
npm

GHSA-5w6g-rc45-wvv9

Duplicate Advisory: Flowise OverrideConfig security vulnerability

CRITICAL 10.0
npm

CVE-2026-12537

Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

CRITICAL 9.1
npm

CVE-2026-61534

yayson: Prototype pollution in Store/LegacyStore deserialization

CRITICAL 9.4
npm

CVE-2026-73653

@vitest/browser: Browser Mode provider commands bypass the file-access permission gate

CRITICAL 9.6
npm

GHSA-jpvj-wpmj-h7rv

Supply chain compromise via malicious @cap-js/openapi

CRITICAL 9.6
npm

CVE-2026-47428

Vitest browser mode serves unsanitized otelCarrier query parameter as inline script

CRITICAL 10.0
npm

CVE-2026-45618

LiquidJS is Vulnerable to Remote Code Execution

CRITICAL 9.6
npm KEV

CVE-2026-45321

Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

CRITICAL 10.0
npm

CVE-2026-43898

SandboxJS has a sandbox escape via Function.caller leakage of internal call op

CRITICAL 9.8
npm

CVE-2026-25244

WebdriverIO BrowserStack Service has a Command Injection issue

CRITICAL 9.8
npm

CVE-2026-45772

Turbo: Unexpected local code execution during Yarn Berry detection

CRITICAL 9.8
npm

CVE-2026-6951

simple-git is vulnerable to Remote Code Execution

CRITICAL 9.9
npm

CVE-2026-49252

deepstream is vulnerable to prototype pollution

CRITICAL 9.0
npm

CVE-2026-48150

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

CRITICAL 9.8
npm

CVE-2026-47429

When Vitest UI server is listening, arbitrary file can be read and executed

CRITICAL 10.0
npm

CVE-2026-46412

Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm

CRITICAL 9.6
npm

GHSA-27f5-xjrr-q9ff

Malware in @opensearch-project/opensearch

CRITICAL 9.8
npm

CVE-2026-41242

Arbitrary code execution in protobufjs

CRITICAL 9.1
npm

CVE-2026-33808

@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)

CRITICAL 9.8
npm

CVE-2026-29063

Immutable is vulnerable to Prototype Pollution

CRITICAL 9.6
npm

CVE-2026-31938

jsPDF has HTML Injection in New Window paths

CRITICAL 9.8
npm

CVE-2026-28292

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

CRITICAL 9.8
npm

CVE-2026-33937

Handlebars.js has JavaScript Injection via AST Type Confusion

CRITICAL 9.3
npm

CVE-2026-25896

fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

CRITICAL 10.0
npm

CVE-2026-27597

@enclave-vm/core is vulnerable to Sandbox Escape

CRITICAL 9.1
npm

CVE-2026-27699

Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

CRITICAL 10.0
npm

GHSA-9qr9-h5gf-34mp

Next.js is vulnerable to RCE in React flight protocol

CRITICAL 9.8
npm

CVE-2025-59834

Command Injection in adb-mcp MCP Server

CRITICAL 9.8
npm

CVE-2025-59046

interactive-git-checkout has a Command Injection vulnerability

CRITICAL 9.1
npm

CVE-2025-9287

cipher-base is missing type checks, leading to hash rewind and passing on crafted data

CRITICAL 9.1
npm

CVE-2025-9288

sha.js is missing type checks leading to hash rewind and passing on crafted data

CRITICAL 9.1
npm

CVE-2025-29927

Authorization Bypass in Next.js Middleware

CRITICAL 9.8
npm

CVE-2025-1302

JSONPath Plus allows Remote Code Execution

CRITICAL 9.8
npm

CVE-2024-21534

JSONPath Plus Remote Code Execution (RCE) Vulnerability

CRITICAL 10.0
npm

CVE-2024-47875

DOMpurify has a nesting-based mXSS

CRITICAL 10.0
npm

CVE-2024-38999

jrburke requirejs vulnerable to prototype pollution

CRITICAL 9.8
npm

CVE-2024-39309

ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability

CRITICAL 9.8
npm

CVE-2024-38993

jsonic was discovered to contain a prototype pollution via the function empty.

CRITICAL 9.8
npm

CVE-2024-38996

Prototype pollution in ag-grid-community via the _.mergeDeep function

CRITICAL 9.8
npm

CVE-2024-4146

lunary-ai/lunary allows users unauthorized access to projects

CRITICAL 9.8
npm

CVE-2024-34706

@valtimo/components exposes access token to form.io

CRITICAL 10.0
npm

CVE-2024-32962

xml-crypto vulnerable to XML signature verification bypass due improper verification of signature/signature spoofing

CRITICAL 9.8
npm

CVE-2024-30564

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

CRITICAL 9.1
npm

CVE-2026-53486

Decompress: Archive extraction can create files and links outside of the target directory

CRITICAL 9.8
npm

CVE-2024-21508

mysql2 Remote Code Execution (RCE) via the readCodeFor function

CRITICAL 9.8
npm

CVE-2024-21511

MySQL2 for Node Arbitrary Code Injection

CRITICAL 9.8
npm

CVE-2024-27307

JSONata expression can pollute the "Object" prototype

CRITICAL 9.0
npm

CVE-2024-29027

Server crashes on invalid Cloud Function or Cloud Job name

CRITICAL 10.0
npm

CVE-2024-27298

ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection

CRITICAL 9.8
npm

CVE-2023-32314

vm2 Sandbox Escape vulnerability

CRITICAL 9.3
npm

CVE-2023-26114

code-server vulnerable to Missing Origin Validation in WebSockets

CRITICAL 9.0
npm

CVE-2024-22206

@clerk/nextjs auth() and getAuth() methods vulnerable to insecure direct object reference (IDOR)

Ready to move

Start Securing

Free, no credit card | First findings in minutes