OsVault/npm/bun
npm2 critical

bun

75 known vulnerabilities · 2 critical · 3 high

CVE-2025-8022

bun vulnerable to OS Command Injection

Published Jul 23, 2025
CVE-2024-21548HIGH

Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo

Published Dec 18, 2024
CVE-2022-29257MEDIUM

AutoUpdater module fails to validate certain nested components of the bundle

Published Jun 16, 2022
CVE-2018-14731HIGH

Missing Origin Validation in parcel-bundler

Published Oct 30, 2018
GHSA-qcj9-wwgw-6gm8

OpenClaw: Workspace `.env` can override the bundled plugin trust root

Published Apr 3, 2026
CVE-2020-7794CRITICAL

Command injection in buns

Published Jan 13, 2021
GHSA-96qw-h329-v5rg

Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles

Published Jan 8, 2026
MAL-2025-167

Malicious code in bc-bundle (npm)

Published Jan 20, 2025
MAL-2022-1730

Malicious code in bunny-v3 (npm)

Published Jun 20, 2022
CVE-2021-32770HIGH

Basic-auth app bundle credential exposure in gatsby-source-wordpress

Published Jul 19, 2021
MAL-2022-2089

Malicious code in com.unity.modules.unitywebrequestassetbundle (npm)

Published Jun 20, 2022
MAL-2022-4350

Malicious code in loblaws-mkt-bundle (npm)

Published Jun 20, 2022
MAL-2022-6728

Malicious code in ubuntu-drivers-common (npm)

Published Jun 20, 2022
MAL-2024-11025

Malicious code in aa-bundler (npm)

Published Nov 27, 2024
MAL-2022-810

Malicious code in abunews-components (npm)

Published Jun 20, 2022
MAL-2025-191079

Malicious code in bun-plugin-httpfile (npm)

Published Nov 24, 2025
MAL-2025-1563

Malicious code in webbundle-plugins (npm)

Published Feb 28, 2025
MAL-2025-173

Malicious code in com.unity.assetbundlebrowser (npm)

Published Jan 20, 2025
MAL-2025-3885

Malicious code in etherbundle (npm)

Published May 16, 2025
CVE-2024-47068

DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS

Published Sep 23, 2024
MAL-2025-5222

Malicious code in bundle-text (npm)

Published Jun 23, 2025
MAL-2025-4489

Malicious code in microbundle-starter (npm)

Published May 27, 2025
MAL-2025-4805

Malicious code in @loybung/textfont (npm)

Published Jun 10, 2025
MAL-2022-4459

Malicious code in mailru-toolkit-lego-bundle (npm)

Published Jun 20, 2022
MAL-2025-4807

Malicious code in @loybung/unicode-fonts (npm)

Published Jun 10, 2025
MAL-2025-4810

Malicious code in @loybung/weatherapi (npm)

Published Jun 10, 2025
MAL-2026-356

Malicious code in react-server-dom-unbundled (npm)

Published Jan 20, 2026
MAL-2025-4799

Malicious code in @loybung/hyper-client (npm)

Published Jun 10, 2025
MAL-2022-2070

Malicious code in com.unity.modules.assetbundle (npm)

Published Jun 20, 2022
GHSA-3qpv-xf3v-mm45

OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code

Published Apr 2, 2026
CVE-2024-45812MEDIUM

Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS

Published Sep 17, 2024
CVE-2024-38989CRITICAL

Prototype pollution in izatop bunt

Published Aug 12, 2024
MAL-2022-688

Malicious code in @ucs-private/rollup-plugin-dts-bundle (npm)

Published Jul 22, 2022
MAL-2024-10621

Malicious code in pumpfun-bundle-helpers.js (npm)

Published Nov 12, 2024
MAL-2022-2561

Malicious code in domestic-market-bundle (npm)

Published Jun 20, 2022
MAL-2025-2129

Malicious code in sol-web3-bundler (npm)

Published Mar 4, 2025
MAL-2023-895

Malicious code in toolbox-bem-bundle (npm)

Published Jan 30, 2023
CVE-2025-68429

Storybook manager bundle may expose environment variables during build

Published Dec 18, 2025
MAL-2026-1208

Malicious code in tailwindcss-fonts-bundler (npm)

Published Mar 3, 2026
MAL-2026-1209

Malicious code in tailwindcss-form-bundler (npm)

Published Mar 3, 2026
MAL-2026-1977

Malicious code in json-bundling (npm)

Published Mar 20, 2026
MAL-2025-1168

Malicious code in pkl.tmbundle (npm)

Published Feb 3, 2025
MAL-2025-6178

Malicious code in monosize-bundler-rsbuild (npm)

Published Jul 22, 2025
MAL-2025-7068

Malicious code in @amber-team/report-bundle-diff (npm)

Published Aug 14, 2025
MAL-2025-192312

Malicious code in react-svg-bundler (npm)

Published Dec 5, 2025
MAL-2022-1729

Malicious code in bunny-v2 (npm)

Published Jun 20, 2022
MAL-2025-4795

Malicious code in @loybung/discohook (npm)

Published Jun 10, 2025
MAL-2025-4796

Malicious code in @loybung/dous (npm)

Published Jun 10, 2025
MAL-2025-4806

Malicious code in @loybung/textreplace (npm)

Published Jun 10, 2025
MAL-2025-2186

Malicious code in paymaster-bundler-examples (npm)

Published Mar 5, 2025
MAL-2022-5022

Malicious code in odesk.bpa-tsf-calc-bundle (npm)

Published Jun 20, 2022
MAL-2024-9174

Malicious code in openai-bun-test (npm)

Published Oct 9, 2024
MAL-2025-4804

Malicious code in @loybung/systeminfo (npm)

Published Jun 10, 2025
MAL-2025-170

Malicious code in bundle-cryp (npm)

Published Jan 20, 2025
MAL-2023-477

Malicious code in globalize-bundle (npm)

Published Mar 16, 2023
MAL-2023-516

Malicious code in ifabric-styling-bundle (npm)

Published Mar 16, 2023
MAL-2024-10625

Malicious code in web3-bundle-helper.js (npm)

Published Nov 12, 2024
MAL-2024-10626

Malicious code in web3-bundle-helpers.js (npm)

Published Nov 12, 2024
MAL-2025-2098

Malicious code in bsc-web3-bundler (npm)

Published Mar 4, 2025
MAL-2025-2736

Malicious code in test-utils-bundle (npm)

Published Mar 27, 2025
MAL-2022-7054

Malicious code in wcebpack-bunde-analyzer (npm)

Published Aug 19, 2022
MAL-2026-1336

Malicious code in tailwindcss-forms-bundler (npm)

Published Mar 11, 2026
MAL-2025-190652

Malicious code in @asyncapi/bundler (npm)

Published Nov 24, 2025
MAL-2024-1312

Malicious code in actions-next-bundle-analyzer (npm)

Published May 1, 2024
MAL-2025-47053

Malicious code in bundleliep (npm)

Published Sep 11, 2025
MAL-2025-4797

Malicious code in @loybung/emoji (npm)

Published Jun 10, 2025
MAL-2025-4798

Malicious code in @loybung/encode (npm)

Published Jun 10, 2025
MAL-2025-4800

Malicious code in @loybung/inject (npm)

Published Jun 10, 2025
MAL-2025-4801

Malicious code in @loybung/launcher (npm)

Published Jun 10, 2025
MAL-2025-5954

Malicious code in sentry-bundler-plugin-dev (npm)

Published Jul 15, 2025
MAL-2025-4803

Malicious code in @loybung/rdcw-slipverify (npm)

Published Jun 10, 2025
MAL-2025-4809

Malicious code in @loybung/weather-api (npm)

Published Jun 10, 2025
MAL-2025-4808

Malicious code in @loybung/utils (npm)

Published Jun 10, 2025
MAL-2025-4802

Malicious code in @loybung/provider-loader (npm)

Published Jun 10, 2025
MAL-2026-1935

Malicious code in jsonify-bundler (npm)

Published Mar 20, 2026
Check your entire dependency tree at onceRun dependency scan →