Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 6.3
npm

CVE-2026-70597

Electron: Parent process code-sign check is spoofable

MEDIUM 5.3
npm

CVE-2026-69207

Hono: ReDoS in CORS middleware via Access-Control-Request-Headers

MEDIUM 5.3
npm

CVE-2026-53949

Ghost Content API filter bypass reveals private fields

MEDIUM 4.0
npm

CVE-2026-70595

Ghost: Server-Side Request Forgery Mitigation Issue

MEDIUM 4.3
npm

CVE-2026-70596

Ghost: Cross-Site Scripting in Feature Image Captions

MEDIUM 5.3
npm

CVE-2026-59817

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

MEDIUM 5.3
npm

CVE-2026-53947

Ghost: Member existence leak via magic link sign-in response

MEDIUM 6.7
npm

CVE-2026-70594

Ghost: Session Fixation in Ghost Admin

MEDIUM 6.6
npm

CVE-2026-70593

Ghost: Theme Upload Path Traversal

MEDIUM 5.5
npm

CVE-2026-70592

Ghost: Database Backup Path Traversal

MEDIUM 4.8
npm

CVE-2026-70590

Ghost: Blind Password Hash Disclosure in Ghost Admin API

MEDIUM 4.1
npm

CVE-2026-70591

Ghost: Server-Side Request Forgery in Image Fetching

MEDIUM 5.8
npm

CVE-2026-53944

Ghost: Private IP filtering bypass to make server-side requests to internal services

MEDIUM 5.4
npm

CVE-2026-53946

Ghost: Mobiledoc image-size fetch SSRF

MEDIUM 4.0
npm

CVE-2026-53945

Ghost: Server-side request forgery via DNS rebinding in external request handling

MEDIUM 4.8
npm

CVE-2026-16729

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

MEDIUM 4.8
npm

CVE-2026-16728

undici vulnerable to downstream response desynchronization via retry interceptor

MEDIUM 4.2
npm

CVE-2026-15157

undici vulnerable to CRLF Injection via blob-like body 'type' property

MEDIUM 5.9
npm

CVE-2026-14643

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

MEDIUM 5.0
npm

CVE-2026-70588

Ghost: Cross-Site Scripting in Universal Import

MEDIUM 5.4
npm

CVE-2026-53948

Ghost: File Upload Content-Type Spoofing

MEDIUM 4.8
npm

CVE-2026-70589

Ghost: Archived Offers can be Redeemed

MEDIUM 6.5
npm

GHSA-rwrp-9823-p2xq

Flowise: Incomplete Credential Redaction Exposes Secrets via API

MEDIUM 6.4
npm

CVE-2026-67332

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

MEDIUM 5.3
npm

CVE-2026-67335

Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE

MEDIUM 5.3
npm

CVE-2023-39522

Withdrawn Advisory: Username enumeration attack in goauthentik

MEDIUM 5.4
npm

CVE-2026-53606

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes

MEDIUM 6.9
npm

CVE-2026-53667

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

MEDIUM 6.1
npm

CVE-2026-53666

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

MEDIUM 5.7
npm

GHSA-2rp8-mm9q-fp49

TypeORM: migration:generate template-literal code injection

MEDIUM 5.4
npm

CVE-2026-62324

Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS

MEDIUM 6.2
npm

CVE-2026-68499

re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)

MEDIUM 5.9
npm

CVE-2026-54753

`nx graph` dev server permissive CORS policy

MEDIUM 5.7
npm

CVE-2026-67550

re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)

MEDIUM 4.2
npm

GHSA-xrmj-5g4g-8987

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

MEDIUM 4.3
npm

GHSA-pqh8-p93p-2rx7

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

MEDIUM 6.2
npm

CVE-2026-54561

mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath

MEDIUM 4.8
npm

CVE-2026-59876

protobufjs: Text Format string map parsing can mutate returned map object prototype

MEDIUM 5.3
npm

CVE-2026-59870

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

MEDIUM 6.8
npm

GHSA-x445-f3h2-j279

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

MEDIUM 5.9
npm

GHSA-frvp-7c67-39w9

Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

MEDIUM 6.3
npm

CVE-2026-54705

mathlive's Lack of Escaping of HTML allows for XSS

MEDIUM 6.4
npm

CVE-2026-10732

decompress: Arbitrary File Write via Archive Extraction (Zip Slip)

MEDIUM 6.1
npm

CVE-2026-54663

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

MEDIUM 6.8
npm

CVE-2026-52888

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

MEDIUM 6.8
npm

GHSA-vg6v-j97m-h5xq

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

MEDIUM 4.3
npm

CVE-2026-53781

@steipete/summarize is Vulnerable to Disk Exhaustion via Crafted Media Responses

MEDIUM 5.3
npm

GHSA-r292-9mhp-454m

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

MEDIUM 5.3
npm

CVE-2026-5078

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

MEDIUM 5.9
npm

GHSA-8q49-2h5h-434x

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

MEDIUM 5.6
npm

GHSA-3r53-75j5-3g7j

Quasar: Prototype pollution in the extend() utility

MEDIUM 5.3
npm

GHSA-cr7p-cr3q-h5cm

Budibase: Account Enumeration via Login Lockout Response Differential

MEDIUM 4.9
npm

GHSA-fcrw-f7gg-6g9f

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

MEDIUM 5.7
npm

GHSA-gh4h-34gr-87r7

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

MEDIUM 4.3
npm

GHSA-4qcj-m5wp-jmf4

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

MEDIUM 5.3
npm

CVE-2026-7120

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

MEDIUM 4.6
npm

GHSA-53g2-mvcc-q9x3

Trix: Stored XSS via HTMLParser attribute injection on paste

MEDIUM 6.5
npm

GHSA-664h-wqgq-64gw

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

MEDIUM 4.7
npm

GHSA-38hq-7x33-php4

@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass

MEDIUM 4.3
npm

GHSA-866w-xmhq-wj7x

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

Ready to move

Start Securing

Free, no credit card | First findings in minutes