Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

HIGH 8.8
npm

CVE-2026-63116

deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes

HIGH 7.5
npm

CVE-2026-62985

request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process

HIGH 7.3
npm

CVE-2026-56681

9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header

HIGH 8.1
npm

CVE-2026-58269

Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`

HIGH 8.2
npm

CVE-2026-91127

File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

HIGH 7.5
npm

CVE-2026-77301

adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)

HIGH 7.5
npm

CVE-2026-92961

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

HIGH 8.2
npm

CVE-2026-86039

libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses

HIGH 7.5
npm

CVE-2026-86038

libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID

HIGH 7.5
npm

CVE-2026-85715

ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion

HIGH 8.8
npm

CVE-2026-63506

Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site

HIGH 8.7
npm

CVE-2026-63459

Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions

HIGH 7.5
npm

CVE-2026-63460

Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends

HIGH 7.5
npm

CVE-2026-92596

Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

HIGH 8.1
npm

CVE-2026-63671

@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration

HIGH 7.5
npm

CVE-2026-59879

Immutable.js `List` 32-bit trie overflow → unrecoverable DoS

HIGH 7.1
npm

CVE-2026-59965

@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission

HIGH 7.0
npm

CVE-2026-68904

node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion

HIGH 7.1
npm

CVE-2026-58200

@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing

HIGH 7.1
npm

CVE-2026-58485

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

HIGH 7.5
npm

CVE-2026-58483

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

HIGH 8.1
npm

GHSA-5648-rgj9-v224

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

HIGH 8.6
npm

CVE-2021-21278

Risk of code injection

HIGH 8.5
npm

CVE-2026-59973

FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix

HIGH 8.8
npm

CVE-2026-59148

@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft

HIGH 7.5
npm

CVE-2026-13676

fast-uri vulnerable to host confusion via failed IDN canonicalization

HIGH 7.5
npm

CVE-2026-59960

@argos-ci/core: CI Branch Name OS Command Injection

HIGH 8.1
npm

GHSA-x7m8-jrm8-hpvx

@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

HIGH 7.5
npm

CVE-2026-73088

Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)

HIGH 7.5
npm

CVE-2026-75975

fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization

HIGH 7.5
npm

CVE-2026-75931

fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references

HIGH 7.5
npm

CVE-2026-69152

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

HIGH 7.1
npm

GHSA-h3hj-cmcx-xc66

Duplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

HIGH 7.5
npm

GHSA-6hqm-hm2v-3p2p

Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

HIGH 7.5
npm

GHSA-68jp-44vc-2x5h

Duplicate Advisory: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

HIGH 7.4
npm

CVE-2026-13697

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

HIGH 7.5
npm

GHSA-39j5-w47m-2gmv

Duplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

HIGH 7.5
npm

CVE-2026-39244

adm-zip: Crafted ZIP file triggers 4GB memory allocation

HIGH 7.5
npm

CVE-2026-73418

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

HIGH 7.5
npm

CVE-2026-50272

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

HIGH 7.5
npm

CVE-2026-59887

linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text

HIGH 7.5
npm

CVE-2026-16221

fast-uri vulnerable to host confusion via literal backslash authority delimiter

HIGH 7.5
npm

CVE-2026-59725

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

HIGH 7.5
npm

CVE-2026-73566

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

HIGH 7.5
npm

CVE-2026-73643

js-yaml: Exponential parsing time in flow collections leads to denial of service

HIGH 7.5
npm

CVE-2026-59874

node-tar: Negative tar entry size causes infinite loop in archive replace

HIGH 8.1
npm

CVE-2026-50143

Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token

HIGH 7.5
npm

CVE-2026-45623

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

HIGH 8.7
npm

CVE-2026-47759

TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes

HIGH 7.5
npm

CVE-2026-13311

shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)

HIGH 8.2
npm

CVE-2026-73650

SVGO removeScripts plugin leaves some executable scripts intact

HIGH 7.5
npm

CVE-2026-59873

node-tar: Decompression/parse DoS via unlimited input

HIGH 7.5
npm

CVE-2026-48712

protobufjs: Denial of service through unbounded Any expansion during JSON conversion

HIGH 7.4
npm

CVE-2026-9697

undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

HIGH 8.7
npm

CVE-2026-47760

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

HIGH 7.1
npm

CVE-2026-82659

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

HIGH 8.1
npm

CVE-2026-56876

extract-zip unvalidated symlink path traversal

HIGH 8.3
npm

CVE-2026-49229

@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens

HIGH 8.2
npm

CVE-2026-46509

@ranfdev/deepobj has a Prototype Pollution vulnerability

HIGH 7.5
npm

CVE-2026-9496

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

Ready to move

Start Securing

Free, no credit card | First findings in minutes