OsVault/npm/connect
npm5 critical

connect

108 known vulnerabilities · 5 critical · 6 high

CVE-2013-7370MEDIUM

methodOverride Middleware Reflected Cross-Site Scripting in connect

Published Aug 31, 2020
CVE-2018-3717MEDIUM

Cross-Site Scripting in connect

Published Jul 26, 2018
CVE-2013-7371MEDIUM

Node Connect Reflected Cross-Site Scripting in Sencha Labs Connect middleware

Published May 5, 2022
CVE-2026-3635

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

Published Mar 25, 2026
CVE-2022-2237MEDIUM

keycloak-connect contains Open redirect vulnerability in the Node.js adapter

Published Mar 2, 2023
CVE-2019-15658HIGH

SQL Injection in connect-pg-simple

Published Aug 26, 2019
CVE-2021-26073HIGH

Broken Authentication in Atlassian Connect Express

Published May 24, 2022
MAL-2025-3926

Malicious code in wagmi-ethers-connectors (npm)

Published May 16, 2025
GHSA-gwhp-pf74-vj37

Fastify's connection header abuse enables stripping of proxy-added headers

Published Apr 16, 2026
GHSA-9hjh-fr4f-gxc4

OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin

Published Mar 27, 2026
GHSA-fqw4-mph7-2vr8

OpenClaw: Silent privilege escalation via gateway shared-auth reconnect

Published Mar 27, 2026
CVE-2026-32014

OpenClaw: Node reconnect metadata spoofing could bypass platform-based node command policy

Published Mar 3, 2026
GHSA-5wj5-87vq-39xm

OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement

Published Apr 9, 2026
CVE-2026-28472

OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validated

Published Feb 17, 2026
CVE-2025-6514

mcp-remote exposed to OS command injection via untrusted MCP server connections

Published Jul 9, 2025
CVE-2022-24794HIGH

URL Redirection to Untrusted Site ('Open Redirect') in express-openid-connect

Published Mar 31, 2022
MAL-2022-5433

Malicious code in pp-mp-connected-path (npm)

Published May 18, 2022
MAL-2022-4565

Malicious code in meshblu-connector-arc-thermometer (npm)

Published Jun 20, 2022
MAL-2022-2260

Malicious code in cs-connection-hub (npm)

Published Jun 13, 2022
CVE-2026-24766

NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS

Published Jan 28, 2026
CVE-2021-41246MEDIUM

Session fixation in express-openid-connect

Published Dec 9, 2021
GHSA-gqqj-85qm-8qhf

Paperclip: codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email

Published Apr 16, 2026
MAL-2024-8865

Malicious code in fma-connect-javascript (npm)

Published Sep 11, 2024
CVE-2025-52882

Claude Code Improper Authorization via websocket connections from arbitrary origins

Published Jun 23, 2025
CVE-2016-10599HIGH

sauce-connect downloads Resources over HTTP

Published Feb 18, 2019
CVE-2020-7633CRITICAL

apiconnect-cli-plugins vulnerable to OS Command Injection

Published May 24, 2021
MAL-2024-9330

Malicious code in alb-um-availa-ble-zip-mp3-file-46046-radical-connector-m2ydd-nirtvy (npm)

Published Oct 16, 2024
MAL-2024-18

Malicious code in matomo-looker-studio-connector (npm)

Published Jan 2, 2024
CVE-2025-64496

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Published Nov 7, 2025
MAL-2025-107

Malicious code in uber-connect (npm)

Published Jan 14, 2025
MAL-2024-11172

Malicious code in spinal-core-connectorjs (npm)

Published Dec 1, 2024
MAL-2025-4713

Malicious code in fin-connector (npm)

Published Jun 7, 2025
MAL-2025-48422

Malicious code in deficonnect-private-sdk (npm)

Published Oct 15, 2025
CVE-2022-35942CRITICAL

loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter

Published Aug 11, 2022
MAL-2024-9353

Malicious code in down-lo-ad-now-zip-mp3-18275-skelliconnection-taeie-mgpquk (npm)

Published Oct 16, 2024
MAL-2025-2036

Malicious code in ct-connect-stripe (npm)

Published Mar 3, 2025
MAL-2025-48573

Malicious code in mender-connect (npm)

Published Oct 24, 2025
MAL-2022-3057

Malicious code in fitbit-connect (npm)

Published Jul 21, 2022
MAL-2022-3058

Malicious code in fitbit-connect-client-api (npm)

Published Jun 20, 2022
GHSA-wvr4-3wq4-gpc5

MCP Connect has unauthenticated remote OS command execution via /bridge endpoint

Published Mar 19, 2026
MAL-2025-3728

Malicious code in com.unity.furioos-connection-kit (npm)

Published May 10, 2025
MAL-2025-48421

Malicious code in deficonnect-internal-utils (npm)

Published Oct 15, 2025
CVE-2025-11287

MCPHub has an Improper Authorization vulnerability via its handleSseConnection function

Published Oct 5, 2025
MAL-2025-2071

Malicious code in connector123 (npm)

Published Mar 4, 2025
MAL-2024-9434

Malicious code in wagmi-connectors (npm)

Published Oct 18, 2024
CVE-2022-29623HIGH

Connect-Multiparty allows arbitrary file upload

Published May 17, 2022
MAL-2023-8119

Malicious code in walletconnect-website (npm)

Published Sep 17, 2023
MAL-2024-1134

Malicious code in raydium-connect (npm)

Published Mar 19, 2024
MAL-2025-191479

Malicious code in chia-gaming-lobby-connection (npm)

Published Nov 27, 2025
MAL-2022-2156

Malicious code in connect_softbank_interface (npm)

Published Jul 21, 2022
MAL-2022-2157

Malicious code in connectflasjh (npm)

Published Aug 19, 2022
GHSA-5rp4-cwgh-gvwq

Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes

Published Mar 19, 2026
MAL-2025-2496

Malicious code in com.unity.connect.share (npm)

Published Mar 18, 2025
MAL-2025-2498

Malicious code in connectrix (npm)

Published Mar 18, 2025
CVE-2023-30543MEDIUM

`chainId` may be outdated if user changes chains as part of connection in @web3-react

Published Apr 18, 2023
MAL-2022-5107

Malicious code in opsgenie-connectwise-integration (npm)

Published Sep 7, 2022
MAL-2022-2171

Malicious code in contentsource-connector (npm)

Published Jun 20, 2022
MAL-2022-5255

Malicious code in pc-nrfconnect-shared (npm)

Published Jun 20, 2022
MAL-2025-3824

Malicious code in custom-social-connections (npm)

Published May 15, 2025
MAL-2023-438

Malicious code in fi-connect (npm)

Published Jan 10, 2023
MAL-2025-192660

Malicious code in @sodexo-connect/sap-cdc-client (npm)

Published Dec 19, 2025
MAL-2022-2155

Malicious code in connect-rtc-js (npm)

Published Jun 20, 2022
MAL-2024-10256

Malicious code in visma-connect-bv (npm)

Published Oct 28, 2024
CVE-2017-16125HIGH

Directory Traversal in rtcmulticonnection-client

Published Jul 23, 2018
CVE-2024-53843

@dapperduckling/keycloak-connector-server has Reflected XSS Vulnerability in Authentication Flow URL Handling

Published Nov 26, 2024
CVE-2026-31818CRITICAL
Risk: 48/100

Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist

Published Apr 3, 2026
MAL-2024-11867

Malicious code in 32red-connect (npm)

Published Dec 15, 2024
MAL-2022-3591

Malicious code in helix-contentsource-connector (npm)

Published Jun 20, 2022
MAL-2024-11856

Malicious code in 000webhost-connect (npm)

Published Dec 14, 2024
CVE-2017-7474CRITICAL

keycloak-connect and keycloak-js improperly handle invalid tokens

Published Nov 15, 2017
MAL-2022-1089

Malicious code in arkane-connect (npm)

Published Jun 20, 2022
MAL-2024-11983

Malicious code in gft-sam-connector (npm)

Published Dec 19, 2024
MAL-2022-6330

Malicious code in stripe-connect-rocketrides (npm)

Published May 31, 2022
MAL-2025-1027

Malicious code in bookingcom-connect (npm)

Published Feb 3, 2025
MAL-2025-4535

Malicious code in wallet-connector-rce (npm)

Published May 28, 2025
CVE-2020-7781CRITICAL

Command injection in connection-tester

Published Dec 17, 2020
GHSA-x49q-fhhm-r9jf

Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes

Published Mar 20, 2026
MAL-2025-6279

Malicious code in db-connections-templates (npm)

Published Jul 23, 2025
MAL-2025-1575

Malicious code in binance-connector-ruby (npm)

Published Feb 28, 2025
MAL-2026-1698

Malicious code in connect-me-icon (npm)

Published Mar 18, 2026
MAL-2022-1577

Malicious code in binance-connector-node (npm)

Published May 16, 2022
MAL-2025-9293

Malicious code in @sellerly-kit/amazon-token-connect (npm)

Published Aug 14, 2025
MAL-2022-6331

Malicious code in stripe-demo-connect-standard-saas-platform (npm)

Published Jul 25, 2022
MAL-2025-4055

Malicious code in web3connectjs (npm)

Published May 20, 2025
MAL-2024-11173

Malicious code in spinal-core-connectorjs_type (npm)

Published Dec 1, 2024
MAL-2022-2158

Malicious code in connecthistoryapifallbacc (npm)

Published Aug 19, 2022
MAL-2024-59

Malicious code in webrtc-studio-connection (npm)

Published Jan 10, 2024
MAL-2025-48615

Malicious code in binance-connector-js (npm)

Published Oct 26, 2025
MAL-2023-1341

Malicious code in wcc-connector (npm)

Published May 23, 2023
MAL-2026-3273

Malicious code in @w3m-app/is_connected (npm)

Published May 4, 2026
MAL-2026-2507

Malicious code in @fairwords/loopback-connector-es (npm)

Published Apr 8, 2026
MAL-2026-412

Malicious code in connect-web (npm)

Published Jan 21, 2026
MAL-2025-191578

Malicious code in lbank-connector (npm)

Published Dec 1, 2025
MAL-2025-191579

Malicious code in lbank-connector-nodejs (npm)

Published Dec 1, 2025
MAL-2022-4025

Malicious code in jetpack-connection (npm)

Published Jun 20, 2022
MAL-2022-3331

Malicious code in generator-connection (npm)

Published Jun 20, 2022
MAL-2025-2734

Malicious code in dmpconnectjsapp-base (npm)

Published Mar 27, 2025
MAL-2025-3848

Malicious code in openidconnect.net (npm)

Published May 15, 2025
MAL-2024-10686

Malicious code in waletconnect (npm)

Published Nov 13, 2024
MAL-2022-4512

Malicious code in mbed-connector (npm)

Published Jun 20, 2022
MAL-2024-9001

Malicious code in worldpay-raft-connect (npm)

Published Sep 27, 2024
CVE-2019-10157MEDIUM

Forced Logout in keycloak-connect

Published Jun 13, 2019
MAL-2025-4142

Malicious code in web3walletconnect (npm)

Published May 21, 2025
MAL-2025-322

Malicious code in canva-connect-api-starter-kit (npm)

Published Jan 22, 2025
MAL-2025-190870

Malicious code in @mparpaillon/connector-parse (npm)

Published Nov 24, 2025
MAL-2025-4726

Malicious code in connectnodewebclient (npm)

Published Jun 9, 2025
MAL-2025-48564

Malicious code in deviceconnect (npm)

Published Oct 24, 2025
MAL-2025-83

Malicious code in ebay-connect (npm)

Published Jan 14, 2025
Check your entire dependency tree at onceRun dependency scan →