Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 3.8
npm

CVE-2026-67334

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

LOW 3.7
npm

CVE-2026-53607

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

LOW 3.7
npm

GHSA-pc2w-4mq8-32qw

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

LOW 3.3
npm

GHSA-464c-974j-9xm6

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

LOW 3.7
npm

CVE-2026-12590

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

LOW 3.7
npm

GHSA-hp3v-mfqw-h74c

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

LOW 2.6
npm

CVE-2022-24719

Forwarding of confidentials headers to third parties in fluture-node

LOW 2.2
npm

CVE-2026-54327

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

LOW 2.0
npm

CVE-2026-46549

NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation

LOW 2.5
npm

CVE-2026-54326

Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass

LOW 3.6
npm

CVE-2026-11330

claude-mem: The computeObservationContentHash Function is Vulnerable to Hash Collision

LOW 3.7
npm

CVE-2026-56349

n8n has a Guardrail Node Bypass

LOW 3.7
npm

CVE-2026-56764

Hono added timing comparison hardening in basicAuth and bearerAuth

LOW 3.2
npm

CVE-2026-49356

@babel/core: Arbitrary File Read via sourceMappingURL Comment

LOW 3.7
npm

CVE-2026-54335

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

LOW 3.1
npm

CVE-2026-49456

Waku has an Open Redirect via `unstable_redirect` Helper

LOW 3.1
npm

CVE-2026-41361

OpenClaw SSRF guard misses four IPv6 special-use ranges

LOW 3.1
npm

CVE-2026-53835

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

LOW 3.7
npm

CVE-2026-2391

qs's arrayLimit bypass in comma parsing allows denial of service

LOW 2.6
npm

CVE-2021-21320

User content sandbox can be confused into opening arbitrary documents

LOW 3.7
npm

CVE-2020-15262

Unprotected dynamically loaded chunks

LOW 3.7
npm

CVE-2021-43862

jquery.terminal self XSS on user input

LOW 3.7
npm

CVE-2021-32696

Passing in a non-string 'html' argument can lead to unsanitized output

LOW 3.7
npm

CVE-2021-43838

Regular Expression Denial of Service (ReDoS) in jsx-slack

LOW 3.1
npm

CVE-2019-16772

Cross-Site Scripting in serialize-to-js

LOW 2.6
npm

CVE-2020-15168

The `size` option isn't honored after following a redirect in node-fetch

LOW 3.7
npm

CVE-2020-4051

Cross-site Scripting in dijit editor's LinkDialog plugin

LOW 3.8
npm

CVE-2026-53809

OpenClaw: Embedded runner policy could be confused by provider aliases

LOW 3.7
npm

CVE-2026-6733

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

LOW 3.7
npm

CVE-2026-11525

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

LOW 3.3
npm

GHSA-9wxg-vf3r-56hc

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

LOW 3.1
npm

CVE-2026-53663

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

LOW 3.7
npm

CVE-2024-9506

ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

LOW 2.5
npm

GHSA-g7r4-m6w7-qqqr

esbuild allows arbitrary file read when running the development server on Windows

LOW 3.7
npm

CVE-2026-44489

Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

LOW 3.5
npm

CVE-2026-48051

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

LOW 3.3
npm

CVE-2026-3449

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

LOW 3.7
npm

CVE-2026-44589

nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)

LOW 3.7
npm

CVE-2026-44582

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

LOW 3.8
npm

CVE-2026-44459

Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()

LOW 3.7
npm

CVE-2026-44572

Next.js's Middleware / Proxy redirects can be cache-poisoned

LOW 3.7
npm

CVE-2026-8026

Flowise: Bcrypt Password Hash Exposure

LOW 3.7
npm

GHSA-6477-wvjj-47v6

Duplicate Advisory: OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders

LOW 3.7
npm

CVE-2026-41333

OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting

LOW 3.7
npm

GHSA-r27j-894h-3w3p

mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile: true`

LOW 3.7
npm

CVE-2026-42040

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

LOW 3.7
npm

CVE-2026-41407

OpenClaw: Shared-secret comparison call sites leaked length information through timing

LOW 3.7
npm

CVE-2026-41913

OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths

LOW 3.7
npm

GHSA-w9f5-8q83-qwpx

Duplicate Advisory: OpenClaw: Fake DeviceToken Bypasses Shared Auth Rate Limiting

LOW 3.2
npm

GHSA-qmq6-f8pr-cx5x

Duplicate Advisory: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

LOW 2.2
npm

CVE-2026-41321

Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4)

LOW 3.5
npm

CVE-2020-15228

Environment Variable Injection in GitHub Actions

LOW 3.8
npm

CVE-2020-4066

Command Injection in Limdu

LOW 3.7
npm

CVE-2026-33877

ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

LOW 3.7
npm

CVE-2026-39321

Parse Server has a login timing side-channel reveals user existence

LOW 3.7
npm

CVE-2026-35648

OpenClaw may have stale policy enforcement for queued node actions

LOW 3.5
npm

CVE-2026-6216

DbGate has cross site scripting via the SVG Icon String Handler component

LOW 3.7
npm

CVE-2026-34166

LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter

LOW 2.8
npm

CVE-2026-34781

Electron: Crash in clipboard.readImage() on malformed clipboard image data

LOW 2.5
npm

CVE-2026-32970

OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode

Ready to move

Start Securing

Free, no credit card | First findings in minutes