OsVault/npm/bl
npm79 critical

bl

1000 known vulnerabilities · 79 critical · 126 high

CVE-2020-8244MEDIUM

Remote Memory Exposure in bl

Published Sep 2, 2020
CVE-2021-23398MEDIUM

Cross-site scripting in react-bootstrap-table

Published Dec 10, 2021
CVE-2022-25906HIGH

is-http2 vulnerable to Improper Input Validation

Published Feb 1, 2023
GHSA-5vjq-5jmg-39xq

Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance

Published Apr 16, 2026
CVE-2020-7704CRITICAL

linux-cmdline is vulnerable to Prototype Pollution via the constructor

Published May 24, 2022
CVE-2025-13204

expr-eval vulnerable to Prototype Pollution

Published Nov 14, 2025
MAL-2025-1565

Malicious code in tablegen (npm)

Published Feb 28, 2025
CVE-2025-57354

counterpart vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2022-41957HIGH

muhammara and hummus vulnerable to Unchecked Return Value to NULL Pointer Dereference

Published Dec 5, 2022
CVE-2022-36083MEDIUM

JOSE vulnerable to resource exhaustion via specifically crafted JWE

Published Sep 16, 2022
CVE-2022-39287HIGH

tiny-csrf has openly visible CSRF tokens

Published Oct 7, 2022
CVE-2026-25722

Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection

Published Feb 6, 2026
CVE-2025-12758

Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements

Published Nov 27, 2025
GHSA-25wv-8phj-8p7r

OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths

Published Apr 9, 2026
CVE-2026-3635

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

Published Mar 25, 2026
CVE-2022-43441HIGH

sqlite vulnerable to code execution due to Object coercion

Published Mar 13, 2023
MAL-2025-191004

Malicious code in react-native-retriable-fetch (npm)

Published Nov 24, 2025
CVE-2022-41654MEDIUM

ghost vulnerable to unauthorized newsletter modification via improper access controls

Published Nov 28, 2022
CVE-2023-26118MEDIUM

angular vulnerable to regular expression denial of service via the <input type="url"> element

Published Mar 30, 2023
CVE-2021-30246CRITICAL

RSA signature validation vulnerability on maleable encoded message in jsrsasign

Published Apr 16, 2021
CVE-2023-29017CRITICAL

vm2 vulnerable to sandbox escape

Published Apr 7, 2023
CVE-2026-4923

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Published Mar 27, 2026
CVE-2022-41878HIGH

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

Published Nov 9, 2022
GHSA-4rc3-7j7w-m548

liquidjs has a Denial of Service via circular block reference in layout

Published Apr 24, 2026
MAL-2022-5341

Malicious code in pipedrive-embeddable-ringcentral-phone-spa (npm)

Published Jun 20, 2022
CVE-2022-37262HIGH

steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments

Published Sep 16, 2022
CVE-2026-32061

OpenClaw vulnerable to arbitrary file read via $include directive

Published Mar 3, 2026
MAL-2024-12119

Malicious code in stablecoin-aptos (npm)

Published Dec 24, 2024
CVE-2024-27088

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
CVE-2026-25641

@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses

Published Feb 5, 2026
CVE-2022-25973HIGH

mc-kill-port vulnerable to Arbitrary Command Execution via kill function

Published Aug 11, 2022
GHSA-4jpm-cgx2-8h37

Flowise: Sensitive Data Leak in public-chatbotConfig

Published Apr 16, 2026
CVE-2026-28793

TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete

Published Mar 12, 2026
CVE-2023-7078HIGH

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 29, 2023
CVE-2011-4969MEDIUM

jQuery vulnerable to Cross-Site Scripting (XSS)

Published May 14, 2022
CVE-2019-25225MEDIUM

sanitize-html is vulnerable to XSS through incomprehensive sanitization

Published Sep 8, 2025
GHSA-5fw2-mwhh-9947

Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials

Published Apr 17, 2026
CVE-2025-68457

Orejime has executable code in HTML attributes

Published Dec 19, 2025
CVE-2022-25349MEDIUM

materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input

Published May 3, 2022
CVE-2022-37623CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 31, 2022
CVE-2025-57329

web3-core-method is vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2022-39266CRITICAL

isolated-vm has vulnerable CachedDataOptions in API

Published Sep 30, 2022
CVE-2022-36079HIGH

Parse Server vulnerable to brute force guessing of user sensitive data via search patterns

Published Sep 16, 2022
MAL-2025-192139

Malicious code in elf-stats-snowdusted-bauble-104 (npm)

Published Dec 3, 2025
MAL-2026-3282

Malicious code in shopify-draggable (npm)

Published May 4, 2026
CVE-2025-69262

pnpm vulnerable to Command Injection via environment variable substitution

Published Jan 7, 2026
CVE-2023-1001LOW

vxe-table Cross-site Scripting vulnerability

Published May 24, 2024
CVE-2017-20160MEDIUM

express-param vulnerable to Improper Handling of Extra Parameters

Published Dec 31, 2022
CVE-2020-26768MEDIUM

Formstone Vulnerable to Reflected XSS

Published May 24, 2022
CVE-2022-39384MEDIUM

OpenZeppelin Contracts initializer reentrancy may lead to double initialization

Published Dec 14, 2021
CVE-2020-36650MEDIUM

gry vulnerable to Command Injection

Published Jan 11, 2023
CVE-2026-22029

React Router vulnerable to XSS via Open Redirects

Published Jan 8, 2026
CVE-2021-23354MEDIUM

printf vulnerable to Regular Expression Denial of Service (ReDoS)

Published Mar 19, 2021
CVE-2023-31999HIGH

@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state

Published Jul 5, 2023
GHSA-7853-gqqm-vcwx

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools

Published Apr 8, 2026
CVE-2025-53889

Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows

Published Jul 15, 2025
GHSA-7jp6-r74r-995q

OpenClaw: Matrix profile config persistence was reachable from operator.write message tools

Published Apr 17, 2026
CVE-2026-26832

node-tesseract-ocr is vulnerable to OS Command Injection through unsanitized recognize() function parameter

Published Mar 25, 2026
CVE-2020-28433HIGH

node-latex-pdf is susceptible to command injection

Published Aug 3, 2022
CVE-2019-15479MEDIUM

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Published Sep 23, 2019
GHSA-939r-rj45-g2rj

OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins

Published Apr 17, 2026
CVE-2026-29185

Backstage vulnerable to potential reading of SCM URLs using built in token

Published Mar 5, 2026
CVE-2026-25047

deepHas vulnerable to Prototype Pollution via constructor.prototype

Published Jan 29, 2026
CVE-2023-30843HIGH

Hidden fields can be leaked on readable collections in Payload

Published Apr 26, 2023
CVE-2020-26938HIGH

oauth2-server through 3.1.1 vulnerable to Open Redirect

Published Aug 30, 2022
CVE-2024-29194HIGH

OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

Published Mar 25, 2024
MAL-2025-47887

Malicious code in lovable-js (npm)

Published Oct 2, 2025
GHSA-52vj-fvrv-7q82

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

Published Apr 10, 2026
GHSA-5jg4-p4qw-cgfr

@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags

Published Apr 4, 2026
CVE-2023-30541MEDIUM

OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated

Published Apr 17, 2023
GHSA-6f7g-v4pp-r667

Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise

Published Apr 16, 2026
CVE-2026-29607

OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

Published Mar 2, 2026
CVE-2026-26316

OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust

Published Feb 17, 2026
CVE-2021-37916MEDIUM

Joplin vulnerable to Cross-site Scripting in notes

Published May 24, 2022
GHSA-hv93-r4j3-q65f

OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing

Published Feb 17, 2026
GHSA-8783-3wgf-jggf

Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints

Published Apr 16, 2026
CVE-2026-28792

TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

Published Mar 12, 2026
CVE-2024-43788MEDIUM

Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

Published Aug 27, 2024
CVE-2023-28443MEDIUM

directus vulnerable to Insertion of Sensitive Information into Log File

Published Mar 23, 2023
GHSA-c276-fj82-f2pq

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Published Apr 16, 2026
CVE-2026-27970

Angular i18n vulnerable to Cross-Site Scripting

Published Feb 27, 2026
CVE-2022-22984MEDIUM

Snyk plugins vulnerable to Command Injection

Published Nov 30, 2022
CVE-2026-31862

@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters

Published Mar 11, 2026
CVE-2024-56159

Astro's server source code is exposed to the public if sourcemaps are enabled

Published Dec 19, 2024
CVE-2026-34768LOW
Risk: 19.5/100

Electron: Unquoted executable path in app.setLoginItemSettings on Windows

Published Apr 3, 2026
GHSA-gwhp-pf74-vj37

Fastify's connection header abuse enables stripping of proxy-added headers

Published Apr 16, 2026
CVE-2024-43796MEDIUM

express vulnerable to XSS via response.redirect()

Published Sep 10, 2024
CVE-2026-4867

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Published Mar 27, 2026
CVE-2026-28395

OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback

Published Feb 17, 2026
GHSA-m866-6qv5-p2fg

OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Published Mar 31, 2026
GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

Published Apr 6, 2026
CVE-2017-16024MEDIUM

Tmp files readable by other users in sync-exec

Published Nov 9, 2018
CVE-2026-28482

OpenClaw's unsanitized session ID enables path traversal in transcript file operations

Published Feb 18, 2026
CVE-2021-21413HIGH

Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate

Published Apr 6, 2021
CVE-2023-31133HIGH

Ghost vulnerable to information disclosure of private API fields

Published May 3, 2023
CVE-2025-56572

Finance.js vulnerable to DoS via the seekZero() parameter

Published Sep 30, 2025
CVE-2023-42282CRITICAL

NPM IP package incorrectly identifies some private IP addresses as public

Published Feb 8, 2024
CVE-2020-15156MEDIUM

XSS due to lack of CSRF validation for replying/publishing

Published Aug 26, 2020
CVE-2024-41818HIGH

fast-xml-parser vulnerable to ReDOS at currency parsing

Published Jul 29, 2024
CVE-2025-57320

json-schema-editor-visual vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2020-7712HIGH

trentm/json vulnerable to command injection

Published May 6, 2021
CVE-2018-3731HIGH

Path Traversal in public

Published Jul 18, 2018
GHSA-72c6-fx6q-fr5w

@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

Published Apr 16, 2026
CVE-2022-37257CRITICAL

steal vulnerable to Prototype Pollution via requestedVersion variable

Published Sep 16, 2022
CVE-2026-27203

eBay API MCP Server Affected by Environment Variable Injection

Published Feb 19, 2026
CVE-2022-31150MEDIUM

undici before v5.8.0 vulnerable to CRLF injection in request headers

Published Jul 21, 2022
CVE-2022-29823CRITICAL

Feather-Sequelize cleanQuery method vulnerable to Prototype Pollution

Published Oct 26, 2022
CVE-2020-7626CRITICAL

karma-mojo enables OS Command Injection

Published Feb 10, 2022
CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
CVE-2025-69264

pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

Published Jan 7, 2026
CVE-2026-28486

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

Published Mar 2, 2026
CVE-2025-54073

mcp-package-docs vulnerable to command injection in several tools

Published Aug 5, 2025
CVE-2022-25848HIGH

static-dev-server vulnerable to path traversal

Published Nov 29, 2022
CVE-2026-3455

mailparser vulnerable to Cross-site Scripting

Published Mar 3, 2026
CVE-2024-53983

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

Published Dec 2, 2024
CVE-2025-56515

Fiora chat group avatar is vulnerable to XSS via SVG files

Published Oct 1, 2025
CVE-2023-35931LOW

Shescape potential environment variable exposure on Windows with CMD

Published Jun 22, 2023
CVE-2020-19850MEDIUM

Directus API vulnerable to denial of service

Published Apr 4, 2023
CVE-2025-59343

tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball

Published Sep 24, 2025
CVE-2026-33713

n8n has SQL Injection in Data Table Node via orderByColumn Expression

Published Mar 26, 2026
CVE-2026-3449

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

Published Mar 3, 2026
CVE-2022-25907HIGH

ts-deepmerge before 2.0.2 vulnerable to Prototype Pollution

Published Aug 10, 2022
CVE-2020-8137CRITICAL

Code injection in blamer

Published May 6, 2021
CVE-2026-32019

OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard

Published Mar 4, 2026
CVE-2024-43035MEDIUM

Fonoster is vulnerable to directory traversal

Published Mar 5, 2026
GHSA-vr6p-vq2p-6j74

Withdrawn Advisory: LikeC4 has RCE through vulnerable React and Next.js versions

Published Dec 15, 2025
CVE-2026-33943

Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code

Published Mar 26, 2026
CVE-2026-28470

OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes

Published Feb 17, 2026
CVE-2021-4326LOW

Imperative CLI vulnerable to Command Injection

Published Mar 1, 2023
CVE-2021-24044CRITICAL

Access of Resource Using Incompatible Type in Hermes

Published Jan 16, 2022
MAL-2025-47888

Malicious code in lovable-react (npm)

Published Oct 2, 2025
MAL-2024-9320

Malicious code in a-lbum-do-wnload-avai-lable-file-261573-generations-do7io-mdogom (npm)

Published Oct 16, 2024
CVE-2015-6584MEDIUM

DataTable Vulnerable to Cross-Site Scripting

Published Aug 31, 2020
MAL-2024-9334

Malicious code in ava-ilable-down-load-mp3-today-2013-10071-pure-heroine-vldvc-oyqobe (npm)

Published Oct 16, 2024
MAL-2024-9350

Malicious code in do-wnload-available-67250-from-gardens-where-we-feel-secure-1-zuhte-cbguim (npm)

Published Oct 16, 2024
MAL-2024-9351

Malicious code in do-wnload-available-88507-inheaven-dfkvm-eunrso (npm)

Published Oct 16, 2024
MAL-2022-112

Malicious code in @azure-tests/perf-storage-blob-track-1 (npm)

Published Jun 20, 2022
MAL-2024-9359

Malicious code in down-lo-ad-now-zip-mp3-the-whole-love-f2ts8-cblkgz (npm)

Published Oct 16, 2024
CVE-2026-32046

OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser container

Published Mar 3, 2026
MAL-2024-9362

Malicious code in down-load-available-zip-now-365509-chew-the-scenery-ymqd7-xaqqmu (npm)

Published Oct 16, 2024
CVE-2022-3783LOW

node-red-dashboard vulnerable to Cross-site Scripting

Published Nov 1, 2022
CVE-2018-15494CRITICAL

dojox vulnerable to unescaped string injection

Published Oct 15, 2018
CVE-2025-64745

Astro development server error page is vulnerable to reflected Cross-site Scripting

Published Nov 13, 2025
CVE-2022-29247LOW

Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled

Published Jun 16, 2022
CVE-2024-39008CRITICAL

robinweser fast-loops vulnerable to prototype pollution

Published Jul 1, 2024
GHSA-w48f-fwg7-ww6p

@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding

Published Apr 4, 2026
CVE-2022-25893CRITICAL

vm2 vulnerable to Arbitrary Code Execution

Published Dec 21, 2022
CVE-2026-24046

Backstage has a Possible Symlink Path Traversal in Scaffolder Actions

Published Jan 21, 2026
GHSA-48m6-ch88-55mj

Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association

Published Apr 16, 2026
CVE-2025-24010

Websites were able to send any requests to the development server and read the response in vite

Published Jan 21, 2025
CVE-2016-10555MEDIUM

Forgeable Public/Private Tokens in jwt-simple

Published Nov 6, 2018
CVE-2018-16330MEDIUM

Pandao editor.md vulnerable to XSS in IMG attributes

Published Sep 6, 2018
CVE-2024-21485MEDIUM

Dash apps vulnerable to Cross-site Scripting

Published Feb 2, 2024
CVE-2025-7339

on-headers is vulnerable to http response header manipulation

Published Jul 17, 2025
CVE-2020-12827HIGH

MJML vulnerable to path traversal

Published May 24, 2022
CVE-2017-12581HIGH

Electron vulnerable to remote command execution

Published May 17, 2022
CVE-2022-25931HIGH

easy-static-server vulnerable to Directory Traversal

Published Dec 20, 2022
CVE-2026-29063

Immutable is vulnerable to Prototype Pollution

Published Mar 4, 2026
GHSA-5cwg-9f6j-9jvx

Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows

Published Apr 17, 2026
GHSA-5f7h-p83x-5vc2

Duplicate Advisory: OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens

Published Apr 10, 2026
CVE-2023-27495MEDIUM

Bypass of CSRF protection in the presence of predictable userInfo

Published Apr 20, 2023
CVE-2024-45590HIGH

body-parser vulnerable to denial of service when url encoding is enabled

Published Sep 10, 2024
CVE-2026-29606

OpenClaw Twilio voice-call webhook auth bypass when ngrok loopback compatibility is enabled

Published Feb 18, 2026
CVE-2023-41167MEDIUM

@webiny/react-rich-text-renderer vulnerable to insecure rendering of rich text content

Published Aug 24, 2023
CVE-2024-23340MEDIUM

@hono/node-server cannot handle "double dots" in URL

Published Jan 23, 2024
CVE-2023-27474HIGH

directus vulnerable to HTML Injection in Password Reset email to custom Reset URL

Published Mar 7, 2023
CVE-2024-34342HIGH

react-pdf vulnerable to arbitrary JavaScript execution upon opening a malicious PDF with PDF.js

Published May 7, 2024
CVE-2026-32237

@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint

Published Mar 12, 2026
CVE-2019-16777HIGH

npm Vulnerable to Global node_modules Binary Overwrite

Published Dec 13, 2019
CVE-2025-65959

Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'

Published Dec 4, 2025
CVE-2018-25061MEDIUM

rgb2hex vulnerable to inefficient regular expression complexity

Published Dec 31, 2022
CVE-2025-47935

Multer vulnerable to Denial of Service via memory leaks from unclosed streams

Published May 19, 2025
CVE-2026-32008

OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files

Published Mar 3, 2026
CVE-2026-31901

Parse Server vulnerable to user enumeration via email verification endpoint

Published Mar 11, 2026
CVE-2021-32859MEDIUM

Baremetrics date range picker vulnerable to Cross-site Scripting

Published Feb 21, 2023
GHSA-96qw-h329-v5rg

Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles

Published Jan 8, 2026
CVE-2025-1692

MongoDB Shell may be susceptible to control character injection via pasting

Published Feb 27, 2025
CVE-2023-25813CRITICAL

Sequelize vulnerable to SQL Injection via replacements

Published Feb 22, 2023
CVE-2026-30854

Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled

Published Mar 9, 2026
CVE-2024-6783

vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)

Published Jul 23, 2024
CVE-2022-35131CRITICAL

Joplin is vulnerable to arbitrary code execution

Published Jul 26, 2022
CVE-2026-25142

SandboxJS Vulnerable to Prototype Pollution -> Sandbox Escape -> RCE

Published Feb 2, 2026
CVE-2023-26920MEDIUM

fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name

Published Jun 13, 2023
CVE-2022-25926HIGH

window-control vulnerable to Command Injection due to improper input sanitization

Published Jan 4, 2023
CVE-2024-36423MEDIUM

Flowise Cross-site Scripting in /api/v1/public-chatflows/id

Published Aug 5, 2024
CVE-2023-26132HIGH

dottie vulnerable to Prototype Pollution

Published Jun 10, 2023
CVE-2022-31108MEDIUM

Possible inject arbitrary `CSS` into the generated graph affecting the container HTML

Published Jul 5, 2022
CVE-2025-53885

Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged

Published Jul 15, 2025
CVE-2024-21490HIGH

angular vulnerable to super-linear runtime due to backtracking

Published Feb 10, 2024
CVE-2022-23458MEDIUM

Toast UI Grid vulnerable to Cross-site Scripting

Published Sep 23, 2022
CVE-2025-68273

Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints

Published Jan 2, 2026
CVE-2022-35961HIGH

OpenZeppelin Contracts vulnerable to ECDSA signature malleability

Published Aug 18, 2022
CVE-2022-25646MEDIUM

x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting

Published Aug 31, 2022
CVE-2025-55284

Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code

Published Aug 18, 2025
CVE-2023-1283CRITICAL

builderio/qwik is vulnerable to code injection

Published Mar 9, 2023
CVE-2025-53355

MCP Server Kubernetes vulnerable to command injection in several tools

Published Jul 8, 2025
CVE-2022-29256MEDIUM

sharp vulnerable to Command Injection in post-installation over build environment

Published Jun 1, 2022
CVE-2021-29446MEDIUM

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-cjs-runtime

Published Apr 19, 2021
CVE-2025-55294

screenshot-desktop vulnerable to command Injection via `format` option

Published Aug 19, 2025
CVE-2022-37614CRITICAL

mockery is vulnerable to prototype pollution

Published Oct 12, 2022
CVE-2024-21523HIGH

images vulnerable to Denial of Service

Published Jul 10, 2024
CVE-2024-38999CRITICAL

jrburke requirejs vulnerable to prototype pollution

Published Jul 1, 2024
CVE-2021-4264MEDIUM

dustjs-linkedin vulnerable to Prototype Pollution

Published Dec 21, 2022
CVE-2026-29783

GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution

Published Mar 6, 2026
CVE-2022-39386HIGH

fastify/websocket vulnerable to uncaught exception via crash on malformed packet

Published Nov 7, 2022
MAL-2022-1150

Malicious code in async-problem (npm)

Published Jun 20, 2022
GHSA-xjr7-3c3g-m763

Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file

Published Jan 13, 2026
CVE-2026-24778

Ghost vulnerable to XSS via malicious Portal preview links

Published Jan 28, 2026
MAL-2022-1378

Malicious code in azure-storage-blob-changefeed (npm)

Published Jun 20, 2022
CVE-2022-35923HIGH

v8n vulnerable to Inefficient Regular Expression Complexity

Published Oct 7, 2022
CVE-2023-34232HIGH

Snowflake NodeJS Driver vulnerable to Command Injection

Published Jun 9, 2023
GHSA-xv56-3wq5-9997

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

Published Jan 13, 2026
CVE-2022-21802MEDIUM

grapesjs before 0.19.5 vulnerable to Cross-site Scripting

Published Jul 26, 2022
CVE-2025-54066

DiracX-Web is vulnerable to attack through an Open Redirect on its login page

Published Jul 17, 2025
MAL-2022-158

Malicious code in @buzzblocks/fetlife-assets (npm)

Published Jun 20, 2022
CVE-2021-23445LOW

Cross site scripting in datatables.net

Published Sep 29, 2021
CVE-2025-68278

tinacms is vulnerable to arbitrary code execution

Published Dec 18, 2025
CVE-2025-69874

nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()

Published Feb 11, 2026
CVE-2025-3193

algoliasearch-helper is vulnerable to Prototype Pollution in _merge()

Published Sep 27, 2025
GHSA-59xv-588h-2vmm

@saltcorn/data vulnerable to SQL Injection via jsexprToSQL Literal Handler

Published Apr 10, 2026
CVE-2021-29444MEDIUM

Padding Oracle Attack due to Observable Timing Discrepancy in jose-browser-runtime

Published Apr 19, 2021
CVE-2021-25915CRITICAL

Changeset vulnerable to prototype pollution

Published May 24, 2022
CVE-2025-55346

Flowise vulnerable to RCE via Dynamic function constructor injection

Published Oct 6, 2025
CVE-2024-46976

@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection

Published Sep 17, 2024
CVE-2021-23346MEDIUM

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

Published Mar 18, 2021
CVE-2015-10005LOW

markdown-it vulnerable to Inefficient Regular Expression Complexity

Published Dec 27, 2022
CVE-2022-1291MEDIUM

Cross-site Scripting in tableexport.jquery.plugin

Published Apr 11, 2022
CVE-2026-25762

AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection

Published Feb 6, 2026
CVE-2014-10065MEDIUM

Content Injection in remarkable

Published Aug 31, 2020
CVE-2025-54139

HAX CMS application pages vulnerable to clickjacking

Published Jul 21, 2025
GHSA-w8hx-hqjv-vjcq

Paperclip: Malicious skills able to exfiltrate and destroy all user data

Published Apr 16, 2026
CVE-2025-67750

Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule

Published Dec 12, 2025
CVE-2025-7338

Multer vulnerable to Denial of Service via unhandled exception from malformed request

Published Jul 17, 2025
GHSA-fmh4-wr37-44fp

React Server Components are Vulnerable to RCE

Published Dec 3, 2025
GHSA-wqq3-wfmp-v85g

Mojic: Observable Timing Discrepancy in HMAC Verification

Published Apr 16, 2026
CVE-2025-30222

Shescape has potential environment variable exposure on Windows with CMD

Published Mar 26, 2025
CVE-2026-33663

n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition

Published Mar 25, 2026
CVE-2024-43799MEDIUM

send vulnerable to template injection that can lead to XSS

Published Sep 10, 2024
GHSA-x428-ghpx-8j92

@fastify/static vulnerable to route guard bypass via encoded path separators

Published Apr 16, 2026
CVE-2026-25153

@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks

Published Feb 2, 2026
CVE-2026-3304

Multer vulnerable to Denial of Service via incomplete cleanup

Published Mar 1, 2026
CVE-2016-1000235

fuelux vulnerable to Cross-Site Scripting in Pillbox feature

Published Sep 1, 2020
GHSA-5c6j-r48x-rmvq

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Published Feb 28, 2026
GHSA-mf5g-6r6f-ghhm

OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token

Published Mar 29, 2026
CVE-2025-1693

MongoDB Shell may be susceptible to control character Injection via shell output

Published Feb 27, 2025
MAL-2024-9348

Malicious code in do-wnload-available-5935-dear-9fef6-bjowel (npm)

Published Oct 16, 2024
CVE-2025-57283

BrowserStack Local vulnerable to Command Injection through logfile variable

Published Jan 28, 2026
MAL-2022-1269

Malicious code in azure-arm-postgresql-flexible-samples-js (npm)

Published Jun 20, 2022
CVE-2026-30916

Withdrawn Advisory: Shescape has possible misidentification of shell due to link chains

Published Mar 7, 2026
MAL-2025-40

Malicious code in solana-stable-web-huks (npm)

Published Jan 10, 2025
CVE-2024-54134

Modified package published to npm, containing malware that exfiltrates private key material

Published Dec 4, 2024
CVE-2018-7560HIGH

AWS Lambda parser is vulnerable to Regular Expression Denial of Service

Published Mar 5, 2018
CVE-2026-26862

CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage

Published Feb 27, 2026
MAL-2024-8856

Malicious code in roblox-tracer (npm)

Published Sep 10, 2024
MAL-2025-192346

Malicious code in non-modular-buildable (npm)

Published Dec 5, 2025
GHSA-5gjc-grvm-m88j

OpenClaw: Memory dreaming config persistence was reachable from operator.write commands

Published Apr 17, 2026
CVE-2025-52662

Nuxt DevTools vulnerable to cross-site scripting (XSS)

Published Nov 7, 2025
MAL-2022-1321

Malicious code in azure-data-tables-js (npm)

Published Jun 20, 2022
MAL-2022-1322

Malicious code in azure-data-tables-ts (npm)

Published Jun 20, 2022
CVE-2022-25844MEDIUM

angular vulnerable to regular expression denial of service (ReDoS)

Published May 3, 2022
CVE-2014-8881

Regular Expression Denial of Service in bleach

Published Sep 1, 2020
CVE-2025-4759

lockfile-lint-api Vulnerable to Incorrect Behavior Order

Published May 16, 2025
GHSA-m6fx-m8hc-572m

OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders

Published Apr 3, 2026
MAL-2025-192600

Malicious code in tailwind-variables (npm)

Published Dec 16, 2025
CVE-2022-37260HIGH

steal vulnerable to Regular Expression Denial of Service via input variable

Published Sep 16, 2022
CVE-2025-11285

MCPHub's ServerController is vulnerable to Command Injection

Published Oct 5, 2025
CVE-2025-31119

generator-jhipster-entity-audit vulnerable to Unsafe Reflection when having Javers selected as Entity Audit Framework

Published Apr 4, 2025
CVE-2022-31160MEDIUM

jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label

Published Jul 18, 2022
CVE-2025-59828

Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions

Published Sep 24, 2025
CVE-2026-30966

Parse Server has role escalation and CLP bypass via direct `_Join` table write

Published Mar 11, 2026
MAL-2025-191389

Malicious code in axios-cancelable (npm)

Published Nov 25, 2025
CVE-2021-30074MEDIUM

Docsify vulnerable to cross-site scripting due to mishandled encoding

Published May 24, 2022
CVE-2026-27191

Feathers has an open redirect in OAuth callback enables account takeover

Published Feb 19, 2026
CVE-2017-16035HIGH

hubl-server downloads resources over HTTP

Published Jul 24, 2018
GHSA-pqhr-mp3f-hrpp

Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters

Published Mar 31, 2026
CVE-2022-3224MEDIUM

parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing

Published Sep 16, 2022
MAL-2026-32

Malicious code in blobhunter-depconf-poc (npm)

Published Jan 4, 2026
CVE-2021-33420CRITICAL

replicator vulnerable to Deserialization of Untrusted Data

Published Dec 15, 2022
CVE-2025-57348

node-cube vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2026-32896

OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)

Published Mar 3, 2026
CVE-2026-28398

NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells

Published Mar 3, 2026
GHSA-8wc6-vgrq-x6cf

Child processes spawned by Renovate incorrectly have full access to environment variables

Published Feb 13, 2026
CVE-2018-1000136HIGH

Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration

Published Mar 26, 2018
CVE-2023-3691LOW

layui vulnerable to cross-site scripting

Published Jul 16, 2023
CVE-2026-33749

n8n Vulnerable to XSS via Binary Data Inline HTML Rendering

Published Mar 26, 2026
CVE-2026-29086

Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()

Published Mar 4, 2026
CVE-2026-31856

Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL

Published Mar 11, 2026
MAL-2022-1609

Malicious code in blobindexfunc (npm)

Published Jun 20, 2022
CVE-2020-7771HIGH

Prototype Pollution in asciitable.js

Published Apr 13, 2021
MAL-2022-1610

Malicious code in block-utxos (npm)

Published Jun 20, 2022
MAL-2022-1618

Malicious code in blockcypher-adapter (npm)

Published Jun 20, 2022
CVE-2023-26492MEDIUM

Directus vulnerable to Server-Side Request Forgery On File Import

Published Mar 3, 2023
MAL-2022-1620

Malicious code in blockly-devtools (npm)

Published Jun 20, 2022
MAL-2022-1622

Malicious code in blocks-cloud (npm)

Published Jun 20, 2022
MAL-2022-1624

Malicious code in blockstream-adapter (npm)

Published Jun 20, 2022
CVE-2024-47762

Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend

Published Oct 3, 2024
CVE-2012-6662MEDIUM

jquery-ui Tooltip widget vulnerable to XSS

Published Oct 24, 2017
CVE-2026-24133

jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder

Published Feb 2, 2026
CVE-2025-9611

Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools

Published Jan 7, 2026
CVE-2026-22686

enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain

Published Jan 14, 2026
CVE-2026-27578

n8n Vulnerable to Stored XSS via Various Nodes

Published Feb 25, 2026
CVE-2023-42399MEDIUM

Jodit Editor vulnerable to cross-site scripting

Published Sep 19, 2023
CVE-2020-36851

cors-anywhere vulnerable to server-side request forgery

Published Sep 25, 2025
GHSA-7wv4-cc7p-jhxc

OpenClaw: Workspace .env could inject OpenClaw runtime-control variables

Published Apr 17, 2026
CVE-2020-15174HIGH

Unpreventable top-level navigation

Published Oct 6, 2020
CVE-2026-2366

Keycloak vulnerable to authorization bypass via the Admin API

Published Mar 12, 2026
CVE-2019-0542HIGH

xterm vulnerable to remote code execution

Published Jan 14, 2019
CVE-2020-7613HIGH

Clamscan vulnerable to command injection

Published May 24, 2022
CVE-2022-37621CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 29, 2022
CVE-2022-37611CRITICAL

tschaub gh-pages vulnerable to prototype pollution

Published Oct 12, 2022
CVE-2024-21532HIGH

ggit is vulnerable to Command Injection via the fetchTags(branch) API

Published Oct 8, 2024
CVE-2024-28181HIGH

TurboBoost Commands vulnerable to arbitrary method invocation

Published Mar 15, 2024
GHSA-72gr-qfp7-vwhw

h3: Double Decoding in `serveStatic` Bypasses `resolveDotSegments` Path Traversal Protection via `%252e%252e`

Published Mar 20, 2026
CVE-2017-15879HIGH

Keystone is vulnerable to CSV injection

Published Nov 16, 2017
CVE-2019-11004MEDIUM

Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation

Published Apr 9, 2019
CVE-2018-16480MEDIUM

Tnantoka/public XSS Vulnerability

Published Feb 7, 2019
CVE-2022-41713MEDIUM

deep-object-diff vulnerable to Prototype Pollution

Published Nov 4, 2022
CVE-2024-55565

Predictable results in nanoid generation when given non-integer values

Published Dec 9, 2024
CVE-2023-26102HIGH

rangy vulnerable to Prototype Pollution

Published Feb 24, 2023
CVE-2026-32878

Parse Server vulnerable to schema poisoning via prototype pollution in deep copy

Published Mar 17, 2026
CVE-2020-28435CRITICAL

ffmpeg-sdk vulnerable to OS Command Injection

Published Jul 26, 2022
CVE-2018-14040MEDIUM

Bootstrap vulnerable to Cross-Site Scripting (XSS)

Published May 13, 2022
CVE-2026-1513

billboard.js is vulnerable to XSS during chart option binding

Published Jan 28, 2026
CVE-2026-25957

Cube Core is vulnerable to Denial of Service (DoS) via crafted request

Published Feb 10, 2026
CVE-2025-70058

yapi disables TLS/SSL certificate validation via rejectUnauthorized: false in Axios HTTPS agent

Published Feb 23, 2026
CVE-2026-21877

n8n Vulnerable to RCE via Arbitrary File Write

Published Jan 6, 2026
CVE-2019-10745HIGH

assign-deep Vulnerable to Prototype Pollution

Published Aug 21, 2019
GHSA-v38x-c887-992f

Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability

Published Apr 18, 2026
CVE-2025-66028

OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

Published Nov 25, 2025
CVE-2025-57324

parse is vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2025-57327

spmrc vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2016-1000230

XSS in client rendered block templates in rendr

Published Sep 1, 2020
GHSA-68qg-g8mg-6pr7

paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass

Published Apr 10, 2026
CVE-2020-28277CRITICAL

dset vulnerable to prototype pollution

Published May 24, 2022
CVE-2025-61140

JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js

Published Jan 28, 2026
GHSA-rp42-5vxx-qpwr

basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()

Published Apr 16, 2026
CVE-2023-49798MEDIUM

OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4

Published Dec 12, 2023
CVE-2025-59471

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

Published Jan 27, 2026
CVE-2026-25521

locutus is vulnerable to Prototype Pollution

Published Feb 2, 2026
CVE-2025-53818

GitHub Kanban MCP Server vulnerable to Command Injection

Published Jul 15, 2025
MAL-2022-2102

Malicious code in com.unity.scriptablebuildpipeline (npm)

Published Jun 20, 2022
CVE-2022-23474MEDIUM

Editor.js vulnerable to Code Injection

Published Aug 5, 2024
GHSA-9ppg-jx86-fqw7

Unauthorized npm publish of cline@2.3.0 with modified postinstall script

Published Feb 19, 2026
CVE-2026-30965

Parse Server vulnerable to session token exfiltration via `redirectClassNameForKey` query parameter

Published Mar 11, 2026
MAL-2022-2698

Malicious code in eleventy-high-performance-blog (npm)

Published Jun 20, 2022
CVE-2025-27097

Cache variables with the operations when transforms exist on the root level even if variables change in the further requests with the same operation

Published Oct 10, 2023
CVE-2023-34104HIGH

fast-xml-parser vulnerable to Regex Injection via Doctype Entities

Published Jun 6, 2023
CVE-2024-31621HIGH

Flowise vulnerable to code injection via api/v1

Published Apr 29, 2024
CVE-2017-1000189HIGH

ejs vulnerable to DoS due to weak input validation

Published Mar 5, 2018
CVE-2022-42496CRITICAL

nadesiko3 vulnerable to OS Command Injection

Published Dec 5, 2022
CVE-2022-37265CRITICAL

steal vulnerable to Prototype Pollution via alias variable

Published Sep 21, 2022
CVE-2022-31129HIGH

Moment.js vulnerable to Inefficient Regular Expression Complexity

Published Jul 6, 2022
CVE-2020-28447CRITICAL

xopen is vulnerable to OS Command Injection in Exported Function xopen(filepath)

Published Jul 26, 2022
MAL-2022-4215

Malicious code in koop-componentenbibliotheek (npm)

Published Jun 20, 2022
CVE-2022-36031MEDIUM

Directus vulnerable to unhandled exception on illegal filename_disk value

Published Aug 30, 2022
CVE-2021-33360CRITICAL

stoqey/gnuplot is vulnerable to command injection

Published Mar 10, 2023
CVE-2018-25053MEDIUM

Json2html vulnerable to cross-site scripting

Published Dec 28, 2022
CVE-2023-26122HIGH

safe-eval vulnerable to Sandbox Bypass due to improper input sanitization

Published Apr 11, 2023
CVE-2021-3820HIGH

inflect vulnerable to Inefficient Regular Expression Complexity

Published Sep 29, 2021
CVE-2023-22491HIGH

gatsby-transformer-remark has possible unsanitized JavaScript code injection

Published Jan 11, 2023
CVE-2025-68130

tRPC has possible prototype pollution in `experimental_nextAppDirCaller`

Published Dec 16, 2025
CVE-2019-10761HIGH

vm2 before 3.6.11 vulnerable to sandbox escape

Published Jul 14, 2022
GHSA-xq8g-hgh6-87hv

OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing

Published Mar 27, 2026
CVE-2026-34825
Risk: 0.01/100

NocoBase Has SQL Injection via template variable substitution in workflow SQL node

Published Apr 1, 2026
CVE-2025-65964

n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook

Published Dec 8, 2025
CVE-2026-31828

Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction

Published Mar 11, 2026
GHSA-xrrh-p7f2-27vm

decolua 9router vulnerable to authorization bypass

Published Apr 9, 2026
CVE-2022-35954MEDIUM

@actions/core has Delimiter Injection Vulnerability in exportVariable

Published Aug 18, 2022
MAL-2022-1329

Malicious code in azure-eventhubs-checkpointstore-blob (npm)

Published Jun 20, 2022
MAL-2022-1628

Malicious code in bluebird.node (npm)

Published Dec 7, 2022
CVE-2017-18197CRITICAL

mxGraph vulnerable to XXE attacks

Published May 14, 2022
GHSA-7rx3-28cr-v5wh

Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry

Published Mar 29, 2026
CVE-2019-1020012HIGH

Parse Server before v3.4.1 vulnerable to Denial of Service

Published Jun 13, 2019
GHSA-xrxf-jgv3-qmrm

OpenAI Codex CLI enables code execution through malicious MCP (Model Context Protocol) configuration files

Published Apr 14, 2026
MAL-2022-4565

Malicious code in meshblu-connector-arc-thermometer (npm)

Published Jun 20, 2022
CVE-2021-39134HIGH

@npmcli/arborist vulnerable to UNIX Symbolic Link (Symlink) Following

Published Aug 31, 2021
MAL-2022-4652

Malicious code in moble (npm)

Published Aug 30, 2022
CVE-2023-22621HIGH

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

Published Apr 19, 2023
CVE-2026-24047

@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass

Published Jan 21, 2026
CVE-2024-29415HIGH

ip SSRF improper categorization in isPublic

Published Jun 2, 2024
MAL-2022-1612

Malicious code in blockchain-com (npm)

Published Jun 20, 2022
CVE-2026-4258

sjcl is missing point-on-curve validation in sjcl.ecc.basicKey.publicKey

Published Mar 17, 2026
CVE-2026-2178

xcode-mcp-server vulnerable to Command Injection

Published Feb 8, 2026
CVE-2026-35214HIGH
Risk: 43.53/100

Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write

Published Apr 4, 2026
CVE-2022-37617CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 12, 2022
CVE-2018-16485MEDIUM

m-server Vulnerable to Directory Traversal

Published Feb 18, 2019
CVE-2023-26133HIGH

progressbar.js vulnerable to Prototype Pollution

Published Jun 12, 2023
MAL-2022-1320

Malicious code in azure-data-tables (npm)

Published Jun 20, 2022
CVE-2026-25631

n8n's domain allowlist bypass enables credential exfiltration

Published Feb 4, 2026
MAL-2022-2051

Malicious code in com.tunnelbear.blocker (npm)

Published Jun 20, 2022
CVE-2023-29641MEDIUM

editor.md vulnerable to Cross-site Scripting

Published May 1, 2023
MAL-2022-1377

Malicious code in azure-storage-blob (npm)

Published Jun 20, 2022
MAL-2022-1629

Malicious code in bluejeans-api-rest-meetings (npm)

Published Jun 20, 2022
CVE-2020-28434CRITICAL

gitblame susceptible to command injection

Published Aug 3, 2022
CVE-2024-29900HIGH

@electron/packager's build process memory potentially leaked into final executable

Published Mar 29, 2024
CVE-2025-57328

toggle-array vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2022-31180CRITICAL

Shescape vulnerable to insufficient escaping of whitespace

Published Jul 15, 2022
MAL-2022-1830

Malicious code in carousel-enabledx (npm)

Published Jun 20, 2022
CVE-2026-24842

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

Published Jan 28, 2026
GHSA-36cp-mh65-x882

Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling

Published Apr 10, 2026
CVE-2022-39288HIGH

fastify vulnerable to denial of service via malicious Content-Type

Published Oct 11, 2022
GHSA-36j9-mx87-2cff

Renovate vulnerable to arbitrary command injection via hermit manager and maliciously named dependencies

Published Jan 13, 2026
MAL-2023-1073

Malicious code in blackberry (npm)

Published Aug 9, 2023
CVE-2021-3647MEDIUM

URIjs Vulnerable to Hostname spoofing via backslashes in URL

Published Jul 19, 2021
GHSA-36jr-mh4h-2g58

d3-color vulnerable to ReDoS

Published Sep 29, 2022
CVE-2019-12043MEDIUM

Cross-site Scripting in remarkable

Published May 29, 2019
CVE-2019-10807CRITICAL

Improper Neutralization of Special Elements used in an OS Command in Blamer

Published May 24, 2022
CVE-2026-29184

@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass

Published Mar 5, 2026
GHSA-8rh7-6779-cjqq

OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover

Published Apr 1, 2026
MAL-2022-4869

Malicious code in noblox.js-addons (npm)

Published Jun 20, 2022
CVE-2026-4598

jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs

Published Mar 23, 2026
GHSA-3f44-xw83-3pmg

Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file

Published Jan 13, 2026
CVE-2025-68150

Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter

Published Dec 16, 2025
MAL-2024-10245

Malicious code in blueconic (npm)

Published Oct 28, 2024
MAL-2022-4871

Malicious code in noblox.js-promise (npm)

Published Jun 20, 2022
CVE-2024-38372LOW

Undici vulnerable to data leak when using response.arrayBuffer()

Published Jul 9, 2024
CVE-2020-28272CRITICAL

keyget vulnerable to prototype pollution

Published May 24, 2022
GHSA-3jc6-6r48-v6qf

Deep Merge is Vulnerable to Prototype Pollution Through Lack of Sanitization

Published Apr 20, 2026
MAL-2024-11024

Malicious code in uid2-publisher (npm)

Published Nov 26, 2024
MAL-2023-1029

Malicious code in bluehost-wordpress-plugin (npm)

Published Aug 1, 2023
GHSA-3p2x-hjxj-c7rv

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 21, 2026
GHSA-8mpm-q7mh-8fvh

Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)

Published Mar 18, 2026
CVE-2026-22820

Outray cli is vulnerable to race conditions in tunnels creation

Published Jan 13, 2026
CVE-2025-53107

@cyanheads/git-mcp-server vulnerable to command injection in several tools

Published Jun 30, 2025
GHSA-f228-chmx-v6j6

Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.

Published Apr 16, 2026
CVE-2022-37603HIGH

loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable

Published Oct 14, 2022
MAL-2022-2703

Malicious code in elitabl2 (npm)

Published Aug 19, 2022
CVE-2017-1000228CRITICAL

ejs is vulnerable to remote code execution due to weak input validation

Published Nov 30, 2017
CVE-2022-23461MEDIUM

Jodit Editor vulnerable to Cross-site Scripting

Published Sep 25, 2022
MAL-2023-8415

Malicious code in bonded-stablecoin (npm)

Published Nov 1, 2023
CVE-2026-28399

NocoDB Vulnerable to SQL Injection via DATEADD Formula

Published Mar 3, 2026
MAL-2022-4873

Malicious code in noblox.js-proxies (npm)

Published Jun 20, 2022
MAL-2024-11018

Malicious code in web_enhance_sap-stable (npm)

Published Nov 27, 2024
CVE-2019-10803CRITICAL

push-dir Enables OS Command Injection

Published Feb 9, 2022
MAL-2022-4874

Malicious code in noblox.js-proxy (npm)

Published Jun 20, 2022
CVE-2025-68619

Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package

Published Jan 2, 2026
CVE-2024-34243MEDIUM

Konga is vulnerable to Cross Site Scripting (XSS) attacks

Published May 14, 2024
GHSA-42mx-vp8m-j7qh

OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup

Published Apr 7, 2026
MAL-2024-134

Malicious code in oscompatible (npm)

Published Jan 18, 2024
CVE-2026-32728

Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries

Published Mar 16, 2026
CVE-2025-1691

MongoDB Shell may be susceptible to Control Character Injection via autocomplete

Published Feb 27, 2025
MAL-2022-807

Malicious code in absorblms (npm)

Published Jul 21, 2022
MAL-2023-529

Malicious code in instant_verb_tables_roxanne_burns_pdf___hot___uy4 (npm)

Published May 9, 2023
CVE-2022-38639MEDIUM

Markdown-Nice v1.8.22 vulnerable to Cross-site Scripting

Published Sep 10, 2022
CVE-2023-36475CRITICAL

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

Published Jun 30, 2023
CVE-2026-33532

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Published Mar 25, 2026
GHSA-98ch-45wp-ch47

OpenClaw: Windows-compatible env override keys could bypass system.run approval binding

Published Apr 7, 2026
CVE-2022-24377HIGH

cycle-import-check vulnerable to Command Injection

Published Dec 14, 2022
CVE-2024-23724CRITICAL

Ghost has possible Cross-site Scripting issue

Published Feb 11, 2024
CVE-2023-39532CRITICAL

SES's dynamic import and spread operator provides possible path to arbitrary exfiltration and execution

Published Aug 9, 2023
MAL-2023-215

Malicious code in criteo-static-variables-datasource (npm)

Published Jun 24, 2023
MAL-2022-931

Malicious code in ali-react-table-monorepo (npm)

Published Jun 20, 2022
CVE-2024-38985CRITICAL

depath and cool-path vulnerable to Prototype Pollution via `set()` Method

Published Mar 28, 2025
CVE-2025-58754

Axios is vulnerable to DoS attack through lack of data size check

Published Sep 11, 2025
CVE-2018-1000118HIGH

Electron protocol handler browser vulnerable to Command Injection

Published Mar 26, 2018
MAL-2022-4350

Malicious code in loblaws-mkt-bundle (npm)

Published Jun 20, 2022
CVE-2020-28168MEDIUM

Axios vulnerable to Server-Side Request Forgery

Published Jan 4, 2021
GHSA-4w7m-58cg-cmff

OpenClaw: Leaf subagents could steer sibling sessions across sandbox boundaries

Published Mar 13, 2026
MAL-2023-1039

Malicious code in storyblok-bridge (npm)

Published Aug 1, 2023
GHSA-8g75-q649-6pv6

OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 12, 2026
CVE-2025-14874

Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion

Published Dec 18, 2025
MAL-2024-9329

Malicious code in alb-um-availa-ble-zip-mp3-file-38068-its-all-about-to-change-rnonb-pzjjbh (npm)

Published Oct 16, 2024
MAL-2024-9363

Malicious code in down-load-available-zip-now-6092-expensive-shit-dzpv2-hzbnea (npm)

Published Oct 16, 2024
CVE-2019-11002MEDIUM

Materialize-css vulnerable to Cross-site Scripting in tooltip component

Published Apr 9, 2019
CVE-2021-26505CRITICAL

MrSwitch hello.js vulnerable to prototype pollution

Published Aug 11, 2023
MAL-2024-9391

Malicious code in new-al-bum-av-ailable-broken-social-scene-8of7p-zaeaqb (npm)

Published Oct 16, 2024
CVE-2022-25912HIGH

simple-git vulnerable to Remote Code Execution when enabling the ext transport protocol

Published Dec 6, 2022
CVE-2022-27103MEDIUM

element-plus vulnerable to cross-site scripting (XSS) via el-table-column

Published Apr 26, 2022
CVE-2023-40028MEDIUM

Ghost vulnerable to arbitrary file read via symlinks in content import

Published Aug 15, 2023
CVE-2022-25892HIGH

muhammara and hummus vulnerable to denial of service by NULL pointer dereference

Published Nov 1, 2022
CVE-2023-40027LOW

When `ui.isAccessAllowed` is `undefined`, the `adminMeta` GraphQL query is publicly accessible

Published Aug 15, 2023
MAL-2025-1057

Malicious code in action-npm-publish (npm)

Published Feb 3, 2025
CVE-2026-24771

Hono vulnerable to XSS through ErrorBoundary component

Published Jan 28, 2026
GHSA-59xc-5v89-r7pr

Duplicate Advisory: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token

Published Apr 10, 2026
MAL-2022-6721

Malicious code in ua-publication-manager (npm)

Published Jul 21, 2022
CVE-2025-62374

Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs

Published Oct 14, 2025
CVE-2024-21509MEDIUM

mysql2 vulnerable to Prototype Poisoning

Published Apr 10, 2024
GHSA-gqqj-85qm-8qhf

Paperclip: codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email

Published Apr 16, 2026
CVE-2022-25759CRITICAL

convert-svg-core vulnerable to remote code injection

Published Jul 23, 2022
CVE-2025-65099

Claude Code vulnerable to command execution prior to startup trust dialog

Published Nov 19, 2025
CVE-2022-29822CRITICAL

feathers-sequelize vulnerable to SQL injection due to improper parameter filtering

Published Oct 26, 2022
CVE-2018-9206CRITICAL

Unrestricted Upload of File with Dangerous Type in blueimp-file-upload

Published Oct 22, 2018
CVE-2024-38356MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

Published Jun 19, 2024
MAL-2025-190814

Malicious code in @ensdomains/unruggable-gateways (npm)

Published Nov 24, 2025
GHSA-gw32-9rmw-qwww

svelte is vulnerable to XSS with textarea bind:value

Published Jan 16, 2026
CVE-2023-26155HIGH

node-qpdf vulnerable to command injection

Published Oct 14, 2023
CVE-2024-57085

@stryker-mutator/util vulnerable to Prototype Pollution

Published Feb 6, 2025
CVE-2023-26109HIGH

node-bluetooth-serial-port is vulnerable to Buffer Overflow via the findSerialPortChannel

Published Mar 9, 2023
CVE-2016-7103MEDIUM

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Published Oct 24, 2017
CVE-2022-39239MEDIUM

@netlify/ipx vulnerable to Full Response SSRF and Stored XSS via Cache Poisoning and Improper Host Validation

Published Sep 21, 2022
MAL-2022-6537

Malicious code in text-ytabl (npm)

Published Aug 19, 2022
CVE-2018-16462CRITICAL

Command Injection in apex-publish-static-files

Published Nov 1, 2018
MAL-2025-1190

Malicious code in uniform-reliable-broadcast (npm)

Published Feb 3, 2025
GHSA-cwq8-6f96-g3q4

OpenClaw: Security Scan Failure Does Not Block Plugin Installation (Fail-Open)

Published Apr 2, 2026
GHSA-j42q-r6qx-xrfp

Duplicate Advisory: OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName

Published Apr 10, 2026
MAL-2025-191210

Malicious code in @dev-blinq/ai-qa-logic (npm)

Published Nov 25, 2025
GHSA-j452-xhg8-qg39

Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution

Published Apr 15, 2026
CVE-2025-57317

apidoc-core is vulnerable to prototype pollution

Published Sep 25, 2025
MAL-2025-1505

Malicious code in storyblok-rich-text-astro-renderer-workspace (npm)

Published Feb 20, 2025
CVE-2022-25883MEDIUM

semver vulnerable to Regular Expression Denial of Service

Published Jun 21, 2023
GHSA-jccr-rrw2-vc8h

OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure

Published Mar 31, 2026
CVE-2021-41264CRITICAL

UUPSUpgradeable vulnerability in @openzeppelin/contracts

Published Sep 15, 2021
CVE-2018-3747MEDIUM

Cross-Site Scripting in public

Published Oct 10, 2018
CVE-2025-29774

xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References

Published Mar 14, 2025
CVE-2021-3777HIGH

tmpl vulnerable to Inefficient Regular Expression Complexity which may lead to resource exhaustion

Published Sep 20, 2021
CVE-2026-26831

textract is vulnerable to OS Command Injection

Published Mar 25, 2026
CVE-2025-68668

n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node

Published Dec 26, 2025
GHSA-jjgj-cpp9-cvpv

OpenClaw Vulnerable to Local File Exfiltration via MCP Tool Result MEDIA: Directive Injection

Published Mar 4, 2026
CVE-2017-16184HIGH

Directory Traversal in scott-blanch-weather-app

Published Sep 1, 2020
CVE-2026-30951

Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type

Published Mar 11, 2026
CVE-2025-68620

Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling

Published Jan 2, 2026
CVE-2024-47819

Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section

Published Oct 22, 2024
CVE-2025-27152

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

Published Mar 7, 2025
GHSA-9r75-g2cr-3h76

Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens

Published Mar 6, 2026
GHSA-fv94-qvg8-xqpw

OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host

Published Apr 2, 2026
CVE-2019-8331MEDIUM

Bootstrap Vulnerable to Cross-Site Scripting

Published Feb 22, 2019
CVE-2022-21186CRITICAL

@acrontum/filesystem-template vulnerable to Command Injection due to fetchRepo API missing sanitization

Published Aug 6, 2022
CVE-2018-25058MEDIUM

Twitter-Post-Fetcher vulnerable to Use of Web Link to Untrusted Target with window.opener Access

Published Dec 29, 2022
MAL-2023-8704

Malicious code in blingbling-dasda (npm)

Published Dec 16, 2023
CVE-2022-39202MEDIUM

matrix-appservice-irc vulnerable to IRC mode parameter confusion

Published Sep 15, 2022
CVE-2021-3645CRITICAL

merge vulnerable to Prototype Pollution

Published Sep 13, 2021
MAL-2024-7332

Malicious code in @zitterorg/probable-octo (npm)

Published Jul 4, 2024
CVE-2026-27148

Storybook Dev Server is Vulnerable to WebSocket Hijacking

Published Feb 26, 2026
MAL-2024-10335

Malicious code in pupeteer-extra-plugin-adblocker (npm)

Published Nov 4, 2024
MAL-2024-10560

Malicious code in immutable-axelar-bridge (npm)

Published Nov 7, 2024
CVE-2022-39350MEDIUM

@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details

Published Oct 25, 2022
CVE-2022-21165CRITICAL

Font-Converter Vulnerable to Arbitrary Command Injection

Published Aug 29, 2022
CVE-2020-7633CRITICAL

apiconnect-cli-plugins vulnerable to OS Command Injection

Published May 24, 2021
CVE-2026-25593

OpenClaw vulnerable to Unauthenticated Local RCE via WebSocket config.apply

Published Feb 4, 2026
CVE-2018-9861MEDIUM

Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)

Published May 14, 2022
GHSA-c447-w54g-f55j

Duplicate Advisory: OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion

Published Mar 29, 2026
GHSA-p464-m8x6-vhv8

OpenClaw: MS Teams webhook parses body before JWT validation, enabling unauthenticated resource exhaustion

Published Apr 3, 2026
MAL-2024-8676

Malicious code in @diotoborg/veniam-blanditiis-sit (npm)

Published Sep 2, 2024
CVE-2017-1000170HIGH

jqueryFileTree vulnerable to Directory Traversal

Published May 13, 2022
CVE-2023-3620MEDIUM

tarteaucitron.js vulnerable to Cross-site Scripting

Published Jul 11, 2023
CVE-2026-23515

Signal K set-system-time plugin vulnerable to RCE - Command Injection

Published Feb 2, 2026
CVE-2025-28269

js-object-utilities Vulnerable to Prototype Pollution

Published Apr 7, 2025
CVE-2026-22866

ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Validation

Published Feb 25, 2026
CVE-2025-12919

EverShop is vulnerable to Unauthorized Order Information Access (IDOR)

Published Nov 9, 2025
MAL-2024-8889

Malicious code in ably-engineering (npm)

Published Sep 17, 2024
GHSA-f5mf-3r52-r83w

OpenClaw's Zalouser allowlist authorization matched mutable group names by default

Published Mar 13, 2026
CVE-2021-4231LOW

Angular vulnerable to Cross-site Scripting

Published May 27, 2022
MAL-2022-705

Malicious code in @visiology-public-utilities/language-utils (npm)

Published Jun 1, 2022
MAL-2024-8213

Malicious code in @diotoborg/debitis-blanditiis-dolore (npm)

Published Sep 2, 2024
CVE-2026-34404
Risk: 0.02/100

Nuxt OG Image is vulnerable to Denial of Service via unbounded image dimensions

Published Mar 31, 2026
CVE-2024-12905HIGH

tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File

Published Mar 27, 2025
MAL-2024-8389

Malicious code in @diotoborg/iusto-blanditiis-reiciendis (npm)

Published Sep 2, 2024
CVE-2020-7638MEDIUM

confinit vulnerable to prototype pollution

Published Apr 7, 2020
CVE-2025-64430

Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format

Published Nov 5, 2025
CVE-2026-24884

Compressing Vulnerable to Arbitrary File Write via Symlink Extraction

Published Feb 3, 2026
CVE-2023-26110HIGH

node-bluetooth is vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation

Published Mar 9, 2023
MAL-2024-9330

Malicious code in alb-um-availa-ble-zip-mp3-file-46046-radical-connector-m2ydd-nirtvy (npm)

Published Oct 16, 2024
MAL-2024-9331

Malicious code in alb-um-availa-ble-zip-mp3-file-85058-bright-phoebus-dboqy-oraqvx (npm)

Published Oct 16, 2024
MAL-2024-9332

Malicious code in alb-um-availa-ble-zip-mp3-file-a-river-aint-too-much-to-love-0u85h-vysnxq (npm)

Published Oct 16, 2024
MAL-2024-9341

Malicious code in avail-able-albu-m-down-load-15496-morning-view-pbn51-tjmcxv (npm)

Published Oct 16, 2024
GHSA-cg7q-fg22-4g98

OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables

Published Apr 3, 2026
CVE-2026-29053

Ghost Vulnerable to Remote Code Execution via Malicious Themes

Published Mar 3, 2026
CVE-2022-25887MEDIUM

Sanitize-html Vulnerable To REDoS Attacks

Published Aug 31, 2022
CVE-2023-30589HIGH

llhttp vulnerable to HTTP request smuggling

Published Jul 1, 2023
MAL-2024-9387

Malicious code in new-al-bum-av-ailable-2014-15374-tourniquets-hacksaws-and-graves-53p3g-eabxqr (npm)

Published Oct 16, 2024
CVE-2023-34093MEDIUM

Making all attributes on a content-type public without noticing it

Published Jul 25, 2023
CVE-2026-27829

Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

Published Feb 25, 2026
CVE-2016-1000241

Cross-Site Scripting (XSS) in pivottable

Published Sep 1, 2020
CVE-2022-24858MEDIUM

NextAuth.js default redirect callback vulnerable to open redirects

Published Apr 22, 2022
GHSA-cjq8-m7wj-xmq9

Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 21, 2026
CVE-2024-43800MEDIUM

serve-static vulnerable to template injection that can lead to XSS

Published Sep 10, 2024
MAL-2024-9198

Malicious code in updated-script-roblox-muscle-legends-script-e3lrsz (npm)

Published Oct 9, 2024
MAL-2025-1024

Malicious code in bloomr-ts (npm)

Published Feb 3, 2025
MAL-2024-3

Malicious code in hubl-parser (npm)

Published Jan 1, 2024
MAL-2024-10611

Malicious code in blockypher (npm)

Published Nov 12, 2024
CVE-2023-27481MEDIUM

Directus vulnerable to extraction of password hashes through export querying

Published Mar 8, 2023
CVE-2025-66030

node-forge is vulnerable to ASN.1 OID Integer Truncation

Published Nov 26, 2025
MAL-2025-1025

Malicious code in blynk-ide (npm)

Published Feb 3, 2025
CVE-2025-8022

bun vulnerable to OS Command Injection

Published Jul 23, 2025
CVE-2025-57321

magix-combine-ex vulnerable to prototype pollution

Published Sep 24, 2025
GHSA-crh9-3gjh-m6gc

api-lab-mcp vulnerable to SSRF

Published Apr 9, 2026
CVE-2023-26158HIGH

mockjs vulnerable to Prototype Pollution via the Util.extend function

Published Dec 8, 2023
CVE-2017-16042CRITICAL

Growl before 1.10.0 vulnerable to Command Injection

Published Jun 8, 2018
CVE-2022-25644CRITICAL

@pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution

Published Aug 29, 2022
CVE-2014-10064HIGH

Denial-of-Service Extended Event Loop Blocking in qs

Published Oct 9, 2018
CVE-2026-27597

@enclave-vm/core is vulnerable to Sandbox Escape

Published Feb 25, 2026
CVE-2023-26108LOW

@nestjs/core vulnerable to Information Exposure via StreamableFile pipe

Published Mar 6, 2023
MAL-2022-806

Malicious code in ablofmyskjtnzdxk (npm)

Published Jul 11, 2022
CVE-2022-35917MEDIUM

Solana Pay Vulnerable to Weakness in Transfer Validation Logic

Published Aug 6, 2022
MAL-2024-10961

Malicious code in eager-blog (npm)

Published Nov 26, 2024
CVE-2026-29091

locutus call_user_func_array vulnerable to Remote Code Execution (RCE) due to Code Injection

Published Mar 4, 2026
CVE-2023-29529MEDIUM

matrix-js-sdk vulnerable to invisible eavesdropping in group calls

Published Apr 14, 2023
GHSA-qvr7-g57c-mrc7

OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode

Published Mar 13, 2026
GHSA-r4c2-gq3j-7rpj

Duplicate Advisory: OpenClaw: Telegram Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Secret

Published Apr 10, 2026
MAL-2024-9206

Malicious code in working-today--roblox-rise-of-nations-script-8ayh1b (npm)

Published Oct 9, 2024
CVE-2025-1756

mongosh vulnerable to local privilege escalation

Published Feb 27, 2025
MAL-2024-9321

Malicious code in a-lbum-do-wnload-avai-lable-file-6460-vauxhall-and-i-tc5nk-jqhvlk (npm)

Published Oct 16, 2024
MAL-2024-9322

Malicious code in a-lbum-do-wnload-avai-lable-file-volta-j48ol-zfpbbc (npm)

Published Oct 16, 2024
GHSA-rc8f-r29c-chr6

Duplicate Advisory: OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing

Published Apr 10, 2026
CVE-2021-23352HIGH

Madge vulnerable to command injection

Published Mar 12, 2021
CVE-2026-34220CRITICAL
Risk: 49.01/100

MikroORM is vulnerable to SQL Injection via specially crafted object

Published Mar 29, 2026
CVE-2025-46653

Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

Published Apr 26, 2025
CVE-2021-4260MEDIUM

Oils JS vulnerable to Open Redirect

Published Dec 19, 2022
CVE-2025-59159

SillyTavern Web Interface Vulnerable DNS Rebinding

Published Oct 6, 2025
CVE-2026-31861

@siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes

Published Mar 10, 2026
MAL-2024-9389

Malicious code in new-al-bum-av-ailable-35600-lived-to-tell-bt7g4-oftaau (npm)

Published Oct 16, 2024
MAL-2024-956

Malicious code in hub-blockly (npm)

Published Feb 2, 2024
CVE-2022-2564CRITICAL

automattic/mongoose vulnerable to Prototype pollution via Schema.path

Published Jul 29, 2022
CVE-2026-21858

n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling

Published Jan 7, 2026
CVE-2026-2359

Multer vulnerable to Denial of Service via resource exhaustion

Published Mar 1, 2026
MAL-2023-1044

Malicious code in noblox.js-vps (npm)

Published Aug 2, 2023
CVE-2022-42743MEDIUM

deep-parse-json vulnerable to Prototype Pollution

Published Nov 4, 2022
CVE-2017-1000427MEDIUM

Marked vulnerable to XSS from data URIs

Published Jan 4, 2018
MAL-2025-1166

Malicious code in paytm-blink-checkout-vue3-example (npm)

Published Feb 3, 2025
CVE-2025-57319

Withdrawn Advisory: fast-redact vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2024-21522HIGH

audify vulnerable to Improper Validation of Array Index

Published Jul 10, 2024
GHSA-w47f-j8rh-wx87

Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs

Published Apr 17, 2026
CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Published Nov 7, 2025
CVE-2023-50481HIGH

blinksocks has weak encryption algorithms

Published Dec 21, 2023
CVE-2025-66202

Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

Published Dec 8, 2025
CVE-2023-26114HIGH

code-server vulnerable to Missing Origin Validation in WebSockets

Published Mar 23, 2023
CVE-2020-28469MEDIUM

glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex

Published Jun 7, 2021
CVE-2021-25944CRITICAL

deep-defaults vulnerable to prototype pollution

Published May 24, 2022
GHSA-wx4p-jr66-jfp9

@nor2/heim-mcp vulnerable to command injection

Published Apr 6, 2026
CVE-2021-20088HIGH

mootools-more vulnerable to prototype pollution

Published May 24, 2022
CVE-2022-24304

Mongoose Vulnerable to Prototype Pollution in Schema Object

Published Aug 27, 2022
CVE-2018-13863HIGH

js-bson vulnerable to REDoS

Published Sep 17, 2018
MAL-2025-48200

Malicious code in redirect-nzoblt (npm)

Published Oct 9, 2025
CVE-2025-56265

N8N's Chat Trigger component is vulnerable to XSS

Published Sep 8, 2025
GHSA-g3qj-j598-cxmq

fido2-lib is vulnerable to DoS via cbor-extract heap buffer over-read in CBOR attestation parsing

Published Mar 24, 2026
CVE-2026-4092

@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script

Published Mar 13, 2026
CVE-2022-37264CRITICAL

steal vulnerable to Prototype Pollution via optionName variable

Published Sep 16, 2022
MAL-2025-191207

Malicious code in @commute/bloom (npm)

Published Nov 25, 2025
GHSA-8fgx-wgvr-pcx8

Zod jsVideoUrlParser vulnerable to ReDoS in util.js

Published Apr 10, 2026
CVE-2025-10097

SimStudioAI: A function in route.ts is vulnerable to Code Injection

Published Sep 8, 2025
CVE-2021-42057HIGH

Obsidian Dataview vulnerable to code injection due to unsafe eval

Published May 24, 2022
MAL-2025-191253

Malicious code in @oku-ui/collapsible (npm)

Published Nov 25, 2025
MAL-2023-207

Malicious code in coolblue-assets (npm)

Published Jan 10, 2023
CVE-2026-30948

Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload

Published Mar 11, 2026
CVE-2023-40014MEDIUM

OpenZeppelin Contracts vulnerable to Improper Escaping of Output

Published Aug 11, 2023
CVE-2024-21524HIGH

node-stringbuilder vulnerable to Out-of-bounds Read

Published Jul 10, 2024
CVE-2025-48997

Multer vulnerable to Denial of Service via unhandled exception

Published Jun 5, 2025
CVE-2022-25929MEDIUM

Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users

Published Dec 21, 2022
CVE-2022-35942CRITICAL

loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter

Published Aug 11, 2022
CVE-2026-4926

path-to-regexp vulnerable to Denial of Service via sequential optional groups

Published Mar 27, 2026
CVE-2026-22037

@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)

Published Jan 20, 2026
MAL-2024-1268

Malicious code in bluepurellwalker (npm)

Published Apr 16, 2024
CVE-2023-2583CRITICAL

jsreport vulnerable to code injection

Published May 8, 2023
MAL-2022-125

Malicious code in @blockpro/render (npm)

Published Jun 20, 2022
CVE-2025-62595

Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic

Published Oct 21, 2025
MAL-2024-8851

Malicious code in core-roblox-utilities (npm)

Published Sep 9, 2024
MAL-2024-8852

Malicious code in roblox-badges (npm)

Published Sep 9, 2024
CVE-2026-32635

Angular vulnerable to XSS in i18n attribute bindings

Published Mar 13, 2026
CVE-2018-3783CRITICAL

Privilege Escalation due to Blind NoSQL Injection in flintcms

Published Aug 21, 2018
MAL-2025-4937

Malicious code in hijack_publish (npm)

Published Jun 12, 2025
CVE-2026-25055

n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node

Published Feb 4, 2026
CVE-2022-25967HIGH

Eta vulnerable to Code Injection via templates rendered with user-defined data

Published Jan 30, 2023
CVE-2022-41879HIGH

Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks

Published Nov 10, 2022
MAL-2024-9205

Malicious code in working-today--find-the-simpsons-171-script-roblox-4zlhl1 (npm)

Published Oct 9, 2024
MAL-2025-2163

Malicious code in alexpavlov--jquery-suggestable (npm)

Published Mar 5, 2025
CVE-2020-36618MEDIUM

FurqanSoftware/node-whois vulnerable to Prototype Pollution

Published Dec 19, 2022
CVE-2022-36067CRITICAL

vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host

Published Sep 28, 2022
CVE-2023-4863HIGH

libwebp: OOB write in BuildHuffmanTable

Published Sep 12, 2023
MAL-2024-1483

Malicious code in @juiggitea/ratione-reiciendis-mollitia-blanditiis (npm)

Published Jun 3, 2024
MAL-2024-1501

Malicious code in @juiggitea/voluptatem-quos-blanditiis (npm)

Published Jun 3, 2024
MAL-2024-9360

Malicious code in down-load-available-zip-now-23630-non-stop-je-te-plie-en-deux-6jxm0-xjqkwj (npm)

Published Oct 16, 2024
MAL-2024-9361

Malicious code in down-load-available-zip-now-35816-laughter-lust-jih3q-fajkvi (npm)

Published Oct 16, 2024
MAL-2022-1607

Malicious code in blank-ts-repo (npm)

Published Jun 20, 2022
MAL-2022-1617

Malicious code in blockchair-adapter (npm)

Published Jun 20, 2022
MAL-2022-1619

Malicious code in blockfi (npm)

Published Jun 20, 2022
MAL-2022-1621

Malicious code in blockly-samples (npm)

Published Jun 20, 2022
MAL-2022-1630

Malicious code in blueprintjs-monorepo (npm)

Published Jun 20, 2022
MAL-2025-191986

Malicious code in elf-stats-mulled-bauble-252 (npm)

Published Dec 3, 2025
MAL-2025-192133

Malicious code in elf-stats-silvered-bauble-482 (npm)

Published Dec 3, 2025
CVE-2025-3197

expand-object Vulnerable to Prototype Pollution via the expand() Function

Published Apr 4, 2025
MAL-2026-2631

Malicious code in babel-plugin-blocks (npm)

Published Apr 13, 2026
CVE-2023-38504HIGH

DoS vulnerability for apps with sockets enabled

Published Jul 27, 2023
CVE-2025-47204

Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data

Published May 13, 2025
CVE-2023-34235HIGH

Leaking sensitive user information still possible by filtering on private with prefix fields

Published Jul 25, 2023
MAL-2022-3557

Malicious code in handsontable-examples (npm)

Published May 31, 2022
CVE-2026-33732

srvx is vulnerable to middleware bypass via absolute URI in request line

Published Mar 26, 2026
CVE-2024-28176MEDIUM

jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext

Published Mar 7, 2024
CVE-2018-16460CRITICAL

ps Enables OS Command Injection

Published Sep 17, 2018
MAL-2022-1611

Malicious code in blockchain-classic-wallet (npm)

Published Jun 20, 2022
GHSA-pfv5-rpcw-x34x

Duplicate Advisory: OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

Published Mar 19, 2026
MAL-2025-190987

Malicious code in prime-one-table (npm)

Published Nov 24, 2025
MAL-2026-1662

Malicious code in blob-internal-security-test-f63eabf7 (npm)

Published Mar 18, 2026
CVE-2020-28502HIGH

xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection

Published May 4, 2021
CVE-2025-10894

Malicious versions of Nx were published

Published Aug 27, 2025
CVE-2020-1911CRITICAL

Access of Resource Using Incompatible Type in Facebook Hermes

Published May 24, 2022
MAL-2026-2959

Malicious code in internal_insights_enabled (npm)

Published Apr 20, 2026
CVE-2024-29504HIGH

Summernote vulnerable to cross-site scripting

Published Apr 11, 2024
CVE-2022-35948MEDIUM

Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type

Published Aug 18, 2022
CVE-2022-45598MEDIUM

Joplin Desktop App vulnerable to Cross-site Scripting

Published Jan 31, 2023
CVE-2025-9862

Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark

Published Sep 15, 2025
MAL-2022-2424

Malicious code in dep-incompatible (npm)

Published Sep 12, 2022
MAL-2022-5028

Malicious code in ofblhekwgqynjxvp (npm)

Published Jul 11, 2022
CVE-2025-68115

Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables

Published Dec 16, 2025
GHSA-fpw4-p57j-hqmq

Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization

Published Apr 16, 2026
CVE-2026-24763

OpenClaw/Clawdbot Docker Execution has Authenticated Command Injection via PATH Environment Variable

Published Feb 2, 2026
CVE-2025-55182

React Server Components are Vulnerable to RCE

Published Dec 3, 2025
MAL-2025-3546

Malicious code in blur-plugins (npm)

Published Apr 30, 2025
MAL-2026-2452

Malicious code in strapi-plugin-blurhash (npm)

Published Apr 3, 2026
CVE-2026-22775

devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse

Published Jan 15, 2026
CVE-2025-58751

Vite middleware may serve files starting with the same name with the public directory

Published Sep 9, 2025
CVE-2026-25224

Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream

Published Feb 2, 2026
CVE-2022-37602CRITICAL

Grunt-karma vulnerable to prototype pollution

Published Oct 14, 2022
CVE-2020-26302HIGH

is_js vulnerable to Regular Expression Denial of Service

Published Jul 6, 2023
MAL-2026-1661

Malicious code in blackstone-core (npm)

Published Mar 18, 2026
CVE-2026-32846

OpenClaw is vulnerable to Path Traversal through path validation bypass

Published Mar 26, 2026
CVE-2023-26139HIGH

underscore-keypath vulnerable to Prototype Pollution

Published Aug 1, 2023
CVE-2026-24048

Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`

Published Jan 21, 2026
MAL-2025-269

Malicious code in aem-react-editable-components (npm)

Published Jan 21, 2025
CVE-2026-31871

Parse Server vulnerable to SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL

Published Mar 11, 2026
CVE-2026-32058

OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 2, 2026
CVE-2022-21169HIGH

express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute

Published Sep 27, 2022
CVE-2022-1726MEDIUM

Cross-site Scripting in bootstrap-table

Published May 17, 2022
CVE-2022-4942LOW

eslint-detailed-reporter vulnerable to cross-site scripting

Published Apr 20, 2023
CVE-2023-23623HIGH

Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled

Published Sep 6, 2023
CVE-2025-15061

figma-developer-mcp vulnerable to command injection in get_figma_data tool

Published Sep 30, 2025
CVE-2021-4307MEDIUM

Baobab vulnerable to Prototype Pollution

Published Jan 7, 2023
MAL-2025-3089

Malicious code in accessible-textbook-demo (npm)

Published Apr 3, 2025
CVE-2022-44310HIGH

ecdh vulnerable to Exposure of Resource to Wrong Sphere

Published Feb 24, 2023
MAL-2026-2606

Malicious code in mdb-react-sortable (npm)

Published Apr 13, 2026
MAL-2025-328

Malicious code in adblock-resources (npm)

Published Jan 22, 2025
CVE-2023-26121HIGH

safe-eval vulnerable to Prototype Pollution via the safeEval function

Published Apr 11, 2023
CVE-2021-23446HIGH

Inefficient Regular Expression Complexity in handsontable

Published Sep 30, 2021
CVE-2022-4111MEDIUM

ToolJet is vulnerable to Denial of Service (DoS)

Published Nov 22, 2022
MAL-2022-3488

Malicious code in gruntcontriblean (npm)

Published Aug 19, 2022
GHSA-hrwm-hgmj-7p9c

@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes

Published Apr 16, 2026
MAL-2024-11030

Malicious code in bll-cerberus (npm)

Published Nov 27, 2024
CVE-2017-1000188MEDIUM

mde ejs vulnerable to XSS

Published Nov 30, 2017
MAL-2024-11114

Malicious code in vs-table-plugins-antd (npm)

Published Nov 27, 2024
CVE-2022-36010CRITICAL

React Editable Json Tree vulnerable to arbitrary code execution via function parsing

Published Aug 18, 2022
GHSA-j44m-5v8f-gc9c

Flowise is vulnerable to arbitrary file exposure through its ReadFileTool

Published Oct 10, 2025
CVE-2025-68697

Self-hosted n8n has Legacy Code node that enables arbitrary file read/write

Published Dec 26, 2025
MAL-2025-3812

Malicious code in aads-blog (npm)

Published May 15, 2025
GHSA-jc5m-wrp2-qq38

Flowise Vulnerable to PII Disclosure on Unauthenticated Forgot Password Endpoint

Published Mar 5, 2026
CVE-2018-1000534MEDIUM

Joplin Vulnerable to Cross-site Scripting in Note Content

Published May 14, 2022
CVE-2022-36084CRITICAL

cruddl vulnerable to ArangoDB Query Language (AQL) injection through flexSearch

Published Sep 16, 2022
CVE-2021-23472LOW

Cross-site Scripting in bootstrap-table

Published Nov 8, 2021
GHSA-mw7w-g3mg-xqm7

OpenClaw: BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events

Published Mar 27, 2026
CVE-2026-34363MEDIUM
Risk: 26.51/100

LiveQuery protected field leak via shared mutable state across concurrent subscribers

Published Mar 30, 2026
CVE-2026-28480

OpenClaw Telegram allowlist authorization accepted mutable usernames

Published Feb 18, 2026
GHSA-52q4-3xjc-6778

OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName

Published Mar 29, 2026
CVE-2021-23413MEDIUM

jszip Vulnerable to Prototype Pollution

Published Aug 10, 2021
CVE-2020-36629MEDIUM

SimbCo httpster vulnerable to Path Traversal

Published Dec 25, 2022
MAL-2026-2781

Malicious code in minecraft_image_to_blocks (npm)

Published Apr 16, 2026
CVE-2022-41710MEDIUM

Markdownify has Files or Directories Accessible to External Parties

Published Nov 4, 2022
CVE-2022-25881MEDIUM

http-cache-semantics vulnerable to Regular Expression Denial of Service

Published Jan 31, 2023
GHSA-q7jf-gf43-6x6p

Hono vulnerable to Vary Header Injection leading to potential CORS Bypass

Published Oct 24, 2025
GHSA-pr96-94w5-mx2h

@fastify/static vulnerable to path traversal in directory listing

Published Apr 16, 2026
CVE-2026-32025

OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains

Published Mar 3, 2026
CVE-2020-28437CRITICAL

heroku-env susceptible to command injection

Published Aug 3, 2022
CVE-2026-32030

OpenClaw vulnerable to sensitive file disclosure via stageSandboxMedia

Published Mar 3, 2026
CVE-2017-1000491MEDIUM

Shiba vulnerable to XSS leading to code execution

Published May 14, 2022
MAL-2022-5293

Malicious code in perf-storage-blob (npm)

Published Jun 20, 2022
CVE-2026-4800HIGH
Risk: 40.53/100

lodash vulnerable to Code Injection via `_.template` imports key names

Published Apr 1, 2026
CVE-2020-7788HIGH

ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse

Published Dec 10, 2020
CVE-2026-26324

OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)

Published Feb 17, 2026
CVE-2025-3573

jquery-validation vulnerable to Cross-site Scripting

Published Apr 15, 2025
GHSA-v6ph-xcq9-qxxj

mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications

Published Apr 8, 2026
GHSA-v3qc-wrwx-j3pw

OpenClaw: Agentic Consent Bypass — LLM Agent Can Silently Disable Exec Approval via `config.patch`

Published Apr 3, 2026
CVE-2023-48219MEDIUM

TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes

Published Nov 15, 2023
GHSA-vcx4-4qxg-mfp4

OpenClaw: Telegram Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Secret

Published Mar 27, 2026
CVE-2026-32063

OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)

Published Mar 3, 2026
CVE-2024-42640CRITICAL

angular-base64-upload vulnerable to unauthenticated remote code execution

Published Oct 11, 2024
CVE-2023-37905MEDIUM

ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor

Published Jul 10, 2023
CVE-2017-16076HIGH

Hijacked Environment Variables in proxy.js

Published Aug 29, 2018
CVE-2022-25896MEDIUM

Passport vulnerable to session regeneration when a users logs in or out

Published Jul 2, 2022
CVE-2026-25651

client-certificate-auth Vulnerable to Open Redirect via Host Header Injection in HTTP-to-HTTPS redirect

Published Feb 6, 2026
CVE-2020-28422MEDIUM

git-archive vulnerable to Command Injection via exports function

Published Jul 26, 2022
CVE-2024-9148

Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting

Published Sep 25, 2024
GHSA-v9ww-2j6r-98q6

@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option

Published Apr 16, 2026
CVE-2016-10549MEDIUM

Sails before 0.12.7 vulnerable to Broken CORS

Published Feb 18, 2019
GHSA-vfw7-6rhc-6xxg

OpenClaw Has Incomplete Fix for CVE-2026-4039: CLI Backend Environment Variable Injection via Workspace Config

Published Apr 7, 2026
GHSA-vh4c-j2xv-9pv9

Duplicate Advisory: OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)

Published Mar 21, 2026
CVE-2026-28292

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

Published Mar 10, 2026
MAL-2022-1026

Malicious code in anyblock-adapter (npm)

Published Jun 20, 2022
MAL-2022-5008

Malicious code in obloq (npm)

Published Jun 20, 2022
MAL-2022-1606

Malicious code in blank-ts-monorepo (npm)

Published Jun 20, 2022
MAL-2022-1616

Malicious code in blockchain.com-adapter (npm)

Published Jun 20, 2022
CVE-2020-28459HIGH

markdown-it-decorate vulnerable to cross-site scripting (XSS)

Published Jul 19, 2022
MAL-2022-5013

Malicious code in octavius-public (npm)

Published Jun 20, 2022
CVE-2020-28458HIGH

datatables.net vulnerable to Prototype Pollution due to incomplete fix

Published Dec 17, 2020
CVE-2023-26106HIGH

dot-lens vulnerable to Prototype Pollution

Published Mar 6, 2023
MAL-2022-5514

Malicious code in public-method-library (npm)

Published Jun 20, 2022
MAL-2022-5516

Malicious code in publicrepoui (npm)

Published Jun 20, 2022
CVE-2025-68113

ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

Published Dec 16, 2025
CVE-2026-31868

Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types

Published Mar 11, 2026
CVE-2020-7608MEDIUM

yargs-parser Vulnerable to Prototype Pollution

Published Sep 4, 2020
CVE-2023-48309MEDIUM

Possible user mocking that bypasses basic authentication

Published Nov 20, 2023
MAL-2023-8690

Malicious code in blockchain-transactions (npm)

Published Dec 12, 2023
GHSA-v8w9-8mx6-g223

Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })

Published Mar 11, 2026
MAL-2022-4348

Malicious code in loblaw_common (npm)

Published Jun 20, 2022
GHSA-7977-c43c-xpwj

OpenClaw is vulnerable to validation bypass through GNU long-option abbreviations in allowlist mode

Published Feb 27, 2026
GHSA-vfp4-8x56-j7c5

OpenClaw: Exec environment denylist missed high-risk interpreter startup variables

Published Apr 17, 2026
CVE-2025-66648

`vega-functions` vulnerable to Cross-site Scripting via `setdata` function

Published Jan 5, 2026
CVE-2025-14284

@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)

Published Dec 9, 2025
CVE-2020-15228LOW

Environment Variable Injection in GitHub Actions

Published Oct 1, 2020
MAL-2022-6422

Malicious code in taxjar-blog (npm)

Published Jun 20, 2022
CVE-2026-25723

Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions

Published Feb 6, 2026
MAL-2023-151

Malicious code in caas-assembly (npm)

Published Mar 31, 2023
MAL-2024-9284

Malicious code in timeline-airtable (npm)

Published Oct 12, 2024
CVE-2022-23340CRITICAL

Joplin Vulnerable to Code Injection

Published Feb 9, 2022
CVE-2020-7676MEDIUM

Angular vulnerable to Cross-site Scripting

Published Jun 18, 2020
CVE-2022-25863HIGH

Unsanitized JavaScript code injection possible in gatsby-plugin-mdx

Published Jun 3, 2022
CVE-2022-25940HIGH

lite-server vulnerable to Denial of Service

Published Dec 20, 2022
CVE-2024-4367HIGH

PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF

Published May 7, 2024
MAL-2025-1067

Malicious code in blocto (npm)

Published Feb 3, 2025
CVE-2026-29186

TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution

Published Mar 5, 2026
CVE-2019-20174MEDIUM

auth0-lock vulnerable to XSS via unsanitized placeholder property

Published Jan 31, 2020
CVE-2025-66414

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Published Dec 2, 2025
MAL-2022-5702

Malicious code in readabl-steam (npm)

Published Aug 19, 2022
MAL-2023-77

Malicious code in actblue-contributions (npm)

Published May 25, 2023
CVE-2026-33751

n8n Vulnerable to LDAP Filter Injection in LDAP Node

Published Mar 26, 2026
CVE-2026-32918

`OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 13, 2026
MAL-2024-11779

Malicious code in blacky-sheppoing (npm)

Published Dec 11, 2024
CVE-2025-13466

body-parser is vulnerable to denial of service when url encoding is used

Published Nov 25, 2025
CVE-2022-25875MEDIUM

Svelte vulnerable to XSS when using objects during server-side rendering

Published Jul 13, 2022
CVE-2026-26833

thumbler allows OS Command Injection

Published Mar 25, 2026
MAL-2025-190722

Malicious code in @ensdomains/blacklist (npm)

Published Nov 24, 2025
CVE-2026-32043

OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 3, 2026
CVE-2024-21525HIGH

node-twain vulnerable to Improper Check or Handling of Exceptional Conditions

Published Jul 10, 2024
CVE-2026-26801

pdfmake is vulnerable to server-side request forgery (SSRF)

Published Mar 10, 2026
CVE-2026-29085

Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()

Published Mar 4, 2026
MAL-2025-191183

Malicious code in @alexadark/gatsby-theme-wordpress-blog (npm)

Published Nov 25, 2025
CVE-2022-32210MEDIUM

ProxyAgent vulnerable to MITM

Published Jun 17, 2022
MAL-2026-939

Malicious code in ably-forks (npm)

Published Feb 19, 2026
CVE-2018-3735MEDIUM

bracket-template vulnerable to reflected XSS

Published Jul 27, 2018
CVE-2025-57318

csvjson vulnerable to prototype injection

Published Sep 24, 2025
GHSA-xqv9-qr76-hfq2

@elgentos/magento2-dev-mcp vulnerable to command injection

Published Apr 6, 2026
CVE-2023-43646HIGH

Chaijs/get-func-name vulnerable to ReDoS

Published Sep 27, 2023
CVE-2022-31151LOW

undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect

Published Jul 21, 2022
CVE-2026-27837

dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()

Published Feb 26, 2026
CVE-2026-0824

QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting

Published Jan 10, 2026
GHSA-xffm-g5w8-qvg7

@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser

Published Jul 18, 2025
GHSA-xhq5-45pm-2gjr

OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens

Published Mar 26, 2026
MAL-2024-1207

Malicious code in payable-js-ipg-sdk (npm)

Published Apr 8, 2024
CVE-2025-57325

rollbar vulnerable to prototype pollution

Published Oct 20, 2025
MAL-2025-4089

Malicious code in human-readable-time-formatter (npm)

Published May 21, 2025
MAL-2024-1565

Malicious code in aws-public (npm)

Published Jun 11, 2024
CVE-2025-69256

serverless MCP Server vulnerable to Command Injection in list-projects tool

Published Dec 31, 2025
CVE-2020-28471HIGH

Properties-Reader before v2.2.0 vulnerable to prototype pollution

Published Jul 19, 2022
CVE-2025-15056

Quill is vulnerable to XSS via HTML export feature

Published Jan 13, 2026
CVE-2019-13127MEDIUM

mxGraph vulnerable to cross-site scripting in color field

Published May 24, 2022
CVE-2020-28279CRITICAL

flattenizer vulnerable to prototype pollution

Published May 24, 2022
CVE-2017-1000424MEDIUM

Electron vulnerable to URL spoofing via PDFium

Published May 13, 2022
CVE-2026-34950CRITICAL
Risk: 62.39/100

fast-jwt: Incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key

Published Apr 2, 2026
MAL-2022-100

Malicious code in @azure-tests/perf-data-tables (npm)

Published Jun 20, 2022
GHSA-vvjj-xcjg-gr5g

Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)

Published Apr 8, 2026
CVE-2026-27739

Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

Published Feb 25, 2026
CVE-2025-26278

dref is vulnerable to prototype pollution

Published Sep 25, 2025
CVE-2026-25152

@backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator

Published Feb 2, 2026
GHSA-x3ff-w252-2g7j

StableLib Ed25519 Signature Malleability via Missing S < L Check

Published Apr 1, 2026
CVE-2021-32822MEDIUM

Insertion of Sensitive Information into Externally-Accessible File or Directory and Exposure of Sensitive Information to an Unauthorized Actor in hbs

Published Sep 2, 2021
CVE-2025-29775

xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment

Published Mar 14, 2025
CVE-2026-33129

h3 has an observable timing discrepancy in basic auth utils

Published Mar 18, 2026
CVE-2021-3666CRITICAL

body-parser-xml vulnerable to Prototype Pollution

Published Sep 14, 2021
MAL-2025-1165

Malicious code in paytm-blink-checkout-vue2-example (npm)

Published Feb 3, 2025
MAL-2025-2649

Malicious code in blockzie-l10n (npm)

Published Mar 25, 2025
CVE-2026-23835

LobeHub Vulnerable to Improper Authorization in Presigned Upload

Published Feb 1, 2026
CVE-2026-32040

OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation

Published Mar 3, 2026
CVE-2025-64764

Astro vulnerable to reflected XSS via the server islands feature

Published Nov 19, 2025
CVE-2023-26116MEDIUM

angular vulnerable to regular expression denial of service via the angular.copy() utility

Published Mar 30, 2023
GHSA-wwrj-437c-ppq4

Duplicate Advisory: OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 31, 2026
CVE-2026-25639

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

Published Feb 9, 2026
CVE-2026-5327MEDIUM
Risk: 31.78/100

fast-filesystem-mcp is vulnerable to command injection through handleGetDiskUsage function

Published Apr 2, 2026
CVE-2022-31142HIGH

fastify-bearer-auth vulnerable to Timing Attack Vector

Published Jul 15, 2022
CVE-2022-37259HIGH

steal Inefficient Regular Expression Complexity vulnerability via string variable

Published Sep 21, 2022
CVE-2022-0086CRITICAL

uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)

Published Jan 6, 2022
CVE-2026-1774

CASL Ability is Vulnerable to Prototype Pollution

Published Feb 10, 2026
GHSA-38cw-85xc-xr9x

Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM

Published Jan 16, 2026
MAL-2025-2342

Malicious code in foundry-js-react-blueprint (npm)

Published Mar 13, 2025
MAL-2022-1631

Malicious code in blz-internal-pkg (npm)

Published Jun 20, 2022
MAL-2022-3108

Malicious code in formidblue (npm)

Published Aug 19, 2022
CVE-2026-24767

NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality

Published Jan 28, 2026
CVE-2025-63700

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

Published Nov 20, 2025
CVE-2025-57326

sassdoc-extras vulnerable to prototype pollution

Published Sep 24, 2025
MAL-2022-3186

Malicious code in free-roblox-robux-codes-app (npm)

Published Jun 20, 2022
CVE-2026-34451
Risk: 0.02/100

Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories

Published Apr 1, 2026
CVE-2026-3520

Multer Vulnerable to Denial of Service via Uncontrolled Recursion

Published Mar 5, 2026
GHSA-3xp3-pr8x-f755

Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts

Published Apr 9, 2026
MAL-2025-5212

Malicious code in audible-react-assets (npm)

Published Jun 21, 2025
CVE-2026-28358

NocoDB Vulnerable to User Enumeration via Password Reset Endpoint

Published Mar 2, 2026
CVE-2017-1000452HIGH

Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames

Published Jan 4, 2018
CVE-2024-23339MEDIUM

Prototype pollution not blocked by object-path related utilities in hoolock

Published Jan 23, 2024
CVE-2024-32869MEDIUM

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

Published Apr 23, 2024
CVE-2023-34234MEDIUM

OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning

Published Jun 8, 2023
CVE-2023-29003HIGH

SvelteKit vulnerable to Cross-Site Request Forgery

Published Apr 4, 2023
CVE-2023-26113HIGH

Collection.js vulnerable to Prototype Pollution

Published Mar 18, 2023
CVE-2021-29445MEDIUM

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtime

Published Apr 19, 2021
CVE-2021-4278MEDIUM

tree-kit vulnerable to Prototype Pollution

Published Dec 25, 2022
MAL-2022-1444

Malicious code in bablpluginsyntaxdynamicimport (npm)

Published Aug 19, 2022
MAL-2022-1445

Malicious code in bablpresetpev (npm)

Published Aug 19, 2022
MAL-2026-1104

Malicious code in bubble-core (npm)

Published Mar 2, 2026
MAL-2022-5447

Malicious code in preloadsmartablejs (npm)

Published Jun 20, 2022
CVE-2021-23353MEDIUM

jspdf vulnerable to Regular Expression Denial of Service (ReDoS)

Published Mar 12, 2021
CVE-2025-66035

Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client

Published Nov 26, 2025
MAL-2022-6565

Malicious code in thumb-assembler (npm)

Published Jun 20, 2022
CVE-2025-61914

n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox

Published Dec 26, 2025
MAL-2022-6986

Malicious code in vt-blockchain-bootcamp-starter-frontend (npm)

Published Jun 8, 2022
GHSA-67mh-4wv8-2f99

esbuild enables any website to send any requests to the development server and read the response

Published Feb 10, 2025
CVE-2026-32009

OpenClaw: safeBins static default trusted dirs allow writable-dir binary hijack (`jq`)

Published Mar 3, 2026
CVE-2022-3978MEDIUM

NodeBB vulnerable to Cross-Site Request Forgery

Published Nov 13, 2022
CVE-2026-25050

Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy

Published Jan 30, 2026
CVE-2019-10794MEDIUM

component-flatten vulnerable to Prototype Pollution

Published May 24, 2022
MAL-2022-1613

Malicious code in blockchain-explorer-sdk (npm)

Published Jun 8, 2022
MAL-2022-1614

Malicious code in blockchain-wallet-ios (npm)

Published Jun 20, 2022
CVE-2017-16897HIGH

passport-wsfed-saml2 vulnerable to Signature Bypass in SAML2 token

Published Jun 21, 2023
MAL-2023-1250

Malicious code in noblox.js-ssh (npm)

Published Aug 9, 2023
CVE-2023-38687MEDIUM

Svelecte item names vulnerable to execution of arbitrary JavaScript

Published Aug 14, 2023
CVE-2021-32853MEDIUM

Erxes vulnerable to Cross-site Scripting

Published Feb 21, 2023
MAL-2022-2916

Malicious code in executables.handler (npm)

Published Jun 20, 2022
MAL-2022-4349

Malicious code in loblaws-mkt (npm)

Published Jun 20, 2022
CVE-2026-32621

Apollo Federation vulnerable to prototype pollution via incomplete key sanitization

Published Mar 13, 2026
MAL-2023-8688

Malicious code in blockchain-contracts (npm)

Published Dec 11, 2023
CVE-2022-37258CRITICAL

steal vulnerable to Prototype Pollution

Published Sep 17, 2022
CVE-2025-53092

Strapi core vulnerable to sensitive data exposure via CORS misconfiguration

Published Oct 16, 2025
CVE-2019-11003MEDIUM

Materialize-css vulnerable to Cross-site Scripting in autocomplete component

Published Apr 9, 2019
MAL-2022-2162

Malicious code in console-less-variables (npm)

Published Jun 20, 2022
MAL-2026-2058

Malicious code in @emilgroup/public-api-sdk (npm)

Published Mar 22, 2026
CVE-2023-37259MEDIUM

matrix-react-sdk vulnerable to XSS in Export Chat feature

Published Jul 18, 2023
GHSA-chm2-m3w2-wcxm

OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch

Published Feb 17, 2026
CVE-2018-25083CRITICAL

pullit vulnerable to command injection

Published Sep 3, 2020
CVE-2026-23745

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

Published Jan 16, 2026
CVE-2025-27793

Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]

Published Mar 27, 2025
CVE-2016-1000223

Forgeable Public/Private Tokens in jws

Published Sep 1, 2020
CVE-2026-28466

OpenClaw Vulnerable to Remote Code Execution via Node Invoke Approval Bypass in Gateway

Published Mar 2, 2026
CVE-2022-40440MEDIUM

mxGraph vulnerable to cross-site scripting in setTooltips function

Published Oct 12, 2022
CVE-2022-3423HIGH

NocoDB vulnerable to Denial of Service

Published Oct 7, 2022
GHSA-h8r8-wccr-v5f2

DOMPurify is vulnerable to mutation-XSS via Re-Contextualization

Published Mar 27, 2026
MAL-2025-191184

Malicious code in @alexadark/reusable-functions (npm)

Published Nov 25, 2025
CVE-2026-26185

Directus Vulnerable to User Enumeration via Password Reset Timing Attack

Published Feb 12, 2026
CVE-2025-61913

Flowise is vulnerable to arbitrary file write through its WriteFileTool

Published Oct 9, 2025
GHSA-fr4j-65pv-gjjj

Renovate vulnerable to arbitrary command injection via npm manager and malicious Renovate configuration

Published Jan 13, 2026
CVE-2022-25885HIGH

muhammara and hummus vulnerable to null pointer dereference on bad response object

Published Nov 1, 2022
CVE-2025-70949

@perfood/couch-auth has an Observable Timing Discrepancy

Published Mar 5, 2026
CVE-2022-41714MEDIUM

fastest-json-copy vulnerable to Prototype Pollution

Published Nov 4, 2022
MAL-2025-359

Malicious code in collapsible-group (npm)

Published Jan 23, 2025
MAL-2022-124

Malicious code in @blackice12/tiny (npm)

Published Jun 8, 2022
CVE-2026-33142

OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy parameters

Published Mar 18, 2026
MAL-2025-191213

Malicious code in @dev-blinq/cucumber_client (npm)

Published Nov 24, 2025
MAL-2025-191214

Malicious code in @dev-blinq/ui-systems (npm)

Published Nov 25, 2025
CVE-2025-69287

BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability

Published Feb 17, 2026
MAL-2022-554

Malicious code in @ramp106/timetable (npm)

Published Jun 20, 2022
CVE-2026-31975

@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection

Published Mar 11, 2026
CVE-2026-34405MEDIUM
Risk: 30.51/100

Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes

Published Mar 31, 2026
MAL-2025-3815

Malicious code in airtable-blocks-internal (npm)

Published May 15, 2025
CVE-2024-34075MEDIUM

kurwov vulnerable to Denial of Service due to improper data sanitization

Published May 3, 2024
GHSA-hh43-q692-2xmq

Duplicate Advisory: `OpenClaw: session_status` let sandboxed subagents access parent or sibling session state

Published Mar 29, 2026
MAL-2025-2585

Malicious code in vulnerable-dependency (npm)

Published Mar 21, 2025
MAL-2022-5981

Malicious code in sdm.vendor.zen-observable (npm)

Published Jun 20, 2022
CVE-2023-0410MEDIUM

@builder.io/qwik vulnerable to Cross-site Scripting

Published Jan 20, 2023
CVE-2022-25852HIGH

pg-native and libpq vulnerable to uncontrolled resource consumption

Published Jun 18, 2022
MAL-2025-191488

Malicious code in eslint-plugin-react-hooks-published (npm)

Published Nov 29, 2025
MAL-2025-191489

Malicious code in liblynxtextra.so (npm)

Published Nov 29, 2025
MAL-2022-6431

Malicious code in tds-publish (npm)

Published Oct 4, 2022
CVE-2026-26861

CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function

Published Feb 27, 2026
CVE-2025-67647

SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

Published Jan 15, 2026
MAL-2022-7006

Malicious code in vulnerablbsusuendency (npm)

Published Nov 7, 2022
CVE-2019-15598CRITICAL

Treekill Enables OS Command Injection

Published May 24, 2022
GHSA-j7p2-qcwm-94v4

OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides

Published Mar 31, 2026
CVE-2022-31179HIGH

Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD

Published Jul 15, 2022
MAL-2022-6666

Malicious code in tslint-blueprint-palantir (npm)

Published Jun 20, 2022
MAL-2022-7222

Malicious code in workers-airtable-form (npm)

Published Jun 20, 2022
CVE-2026-32980

OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion

Published Mar 16, 2026
CVE-2022-25895HIGH

lite-dev-server vulnerable to Directory Traversal

Published Dec 21, 2022
CVE-2022-35513HIGH

Blink1Control2 uses weak password encryption

Published Sep 8, 2022
CVE-2020-28278CRITICAL

shvl vulnerable to prototype pollution

Published May 24, 2022
CVE-2026-31997

OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind

Published Mar 2, 2026
CVE-2026-22170

OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty

Published Mar 4, 2026
MAL-2025-4400

Malicious code in seatable (npm)

Published May 23, 2025
CVE-2026-29066

TinaCMS CLI has Arbitrary File Read via Disabled Vite Filesystem Restriction

Published Mar 12, 2026
GHSA-q86m-697p-h7fh

Duplicate Advisory: OpenClaw: system.run approvals did not bind PATH-token executable identity, enabling post-approval executable rebind

Published Mar 19, 2026
MAL-2022-802

Malicious code in ab-smartable (npm)

Published Jun 20, 2022
CVE-2026-27971

Qwik vulnerable to Unauthenticated RCE via server$ Deserialization

Published Mar 2, 2026
MAL-2022-76

Malicious code in @amplify-components/amplify-table (npm)

Published Jun 22, 2022
CVE-2022-36313MEDIUM

file-type vulnerable to Infinite Loop via malformed MKV file

Published Jul 22, 2022
MAL-2022-6575

Malicious code in timhutable (npm)

Published Aug 19, 2022
CVE-2022-46164CRITICAL

NodeBB vulnerable to account takeover via prototype vulnerability

Published Dec 5, 2022
CVE-2025-57352

min-document vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2017-16006MEDIUM

XSS in Data URI in remarkable

Published Nov 9, 2018
CVE-2026-22171

OpenClaw vulnerable to path traversal in Feishu media temp-file naming allows writes outside os.tmpdir()

Published Mar 3, 2026
MAL-2023-125

Malicious code in beginners-luck-chance-of-a-lifetime-1-by-kate-clayborn-on-audible-full-chapters- (npm)

Published May 10, 2023
CVE-2020-28451CRITICAL

image-tiler susceptible to command injection

Published Aug 3, 2022
CVE-2026-22785

orval MCP client is vulnerable to a code injection attack.

Published Jan 13, 2026
CVE-2026-32006

OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback

Published Mar 3, 2026
CVE-2016-4567MEDIUM

MediaElement Vulnerable to Reflected XSS

Published May 17, 2022
MAL-2025-48459

Malicious code in iwf-ant-design-draggable-modal (npm)

Published Oct 18, 2025
CVE-2026-32242

Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance

Published Mar 12, 2026
MAL-2025-4673

Malicious code in @sasmeee/gamble (npm)

Published Jun 4, 2025
CVE-2021-4245MEDIUM

npm package rfc6902 vulnerable to Prototype Pollution

Published Dec 15, 2022
CVE-2023-26491MEDIUM

rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters

Published Mar 1, 2023
CVE-2025-69202

axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

Published Dec 30, 2025
MAL-2022-7033

Malicious code in wagtail-supertable (npm)

Published May 31, 2022
CVE-2026-33938

Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

Published Mar 27, 2026
MAL-2022-111

Malicious code in @azure-tests/perf-storage-blob (npm)

Published Jun 20, 2022
CVE-2025-47944

Multer vulnerable to Denial of Service from maliciously crafted requests

Published May 19, 2025
MAL-2025-48174

Malicious code in redirect-j5blfb (npm)

Published Oct 9, 2025
CVE-2021-43788MEDIUM

NodeBB vulnerable to path traversal in translator module

Published Nov 30, 2021
CVE-2026-31873

Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity

Published Mar 12, 2026
MAL-2022-4870

Malicious code in noblox.js-beta (npm)

Published Jun 20, 2022
CVE-2021-33829MEDIUM

ckeditor4 vulnerable to cross-site scripting

Published Jun 21, 2021
MAL-2025-6000

Malicious code in public-tools-and-demos (npm)

Published Jul 15, 2025
Check your entire dependency tree at onceRun dependency scan →