OsVault/npm/glob
npm

glob

66 known vulnerabilities · 0 critical · 1 high

CVE-2025-64756

glob CLI: Command injection via -c/--cmd executes matches with shell:true

Published Nov 17, 2025
MAL-2026-3258

Malicious code in @tech-global/internal-gateway-core (npm)

Published Apr 29, 2026
CVE-2026-33671

Picomatch has a ReDoS vulnerability via extglob quantifiers

Published Mar 25, 2026
CVE-2026-32094

Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash

Published Mar 11, 2026
MAL-2024-987

Malicious code in @globalsearch/productstub (npm)

Published Feb 10, 2024
CVE-2026-33672

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Published Mar 25, 2026
CVE-2019-16777HIGH

npm Vulnerable to Global node_modules Binary Overwrite

Published Dec 13, 2019
MAL-2025-192335

Malicious code in elf-stats-mulled-snowglobe-636 (npm)

Published Dec 5, 2025
CVE-2026-27903

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Published Feb 26, 2026
CVE-2025-65110

Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gadgets in the global scope

Published Jan 5, 2026
MAL-2023-984

Malicious code in yandex-global-state-controller (npm)

Published Jan 30, 2023
CVE-2020-28469MEDIUM

glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex

Published Jun 7, 2021
MAL-2025-1776

Malicious code in consumer-platform-global-package (npm)

Published Mar 3, 2025
MAL-2026-1165

Malicious code in @global-dax-ad-platform/dax-components (npm)

Published Mar 3, 2026
MAL-2026-1167

Malicious code in @global-dax-ad-platform/dax-modules (npm)

Published Mar 3, 2026
MAL-2026-1168

Malicious code in @global-dax-ad-platform/dax-styles (npm)

Published Mar 3, 2026
MAL-2026-2649

Malicious code in okxglobal (npm)

Published Apr 14, 2026
MAL-2026-363

Malicious code in pl-global-ec-uikit (npm)

Published Jan 20, 2026
MAL-2026-2410

Malicious code in @the-coca-cola-company/ngps-global-common-utils (npm)

Published Mar 24, 2026
MAL-2022-5388

Malicious code in poc-globalleakage (npm)

Published Jul 21, 2022
MAL-2022-6419

Malicious code in target-global-mbox (npm)

Published Jun 20, 2022
MAL-2026-367

Malicious code in uq-global-ec-uikit (npm)

Published Jan 20, 2026
MAL-2025-192448

Malicious code in elf-stats-sparkly-snowglobe-243 (npm)

Published Dec 11, 2025
MAL-2022-2613

Malicious code in dup-glob (npm)

Published Sep 29, 2022
MAL-2022-290

Malicious code in @globes/fetlife-assets (npm)

Published Jun 20, 2022
MAL-2022-1706

Malicious code in bsd-global-nav-design-ui (npm)

Published Jun 20, 2022
MAL-2022-496

Malicious code in @partner-global-ui/components (npm)

Published Jun 20, 2022
MAL-2024-986

Malicious code in @globalsearch/abstraction (npm)

Published Feb 10, 2024
MAL-2022-587

Malicious code in @shared-ui/global-navigation-header (npm)

Published Jun 20, 2022
CVE-2026-27904

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Published Feb 26, 2026
MAL-2025-4638

Malicious code in atlas-global-npm (npm)

Published Jun 3, 2025
MAL-2026-1166

Malicious code in @global-dax-ad-platform/dax-hooks (npm)

Published Mar 3, 2026
MAL-2026-1148

Malicious code in ethglobal-finale (npm)

Published Mar 3, 2026
CVE-2024-53866

pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion

Published Dec 10, 2024
MAL-2026-1513

Malicious code in vitest-globals (npm)

Published Mar 16, 2026
MAL-2022-6652

Malicious code in trin-glob (npm)

Published Sep 14, 2022
MAL-2025-192773

Malicious code in elf-stats-jolly-snowglobe-266 (npm)

Published Dec 23, 2025
MAL-2025-9303

Malicious code in @sellerly-kit/global-error (npm)

Published Aug 14, 2025
MAL-2026-3163

Malicious code in npm-global-util (npm)

Published Apr 29, 2026
MAL-2023-548

Malicious code in karma-jasmine-i-global (npm)

Published Jan 30, 2023
MAL-2022-878

Malicious code in ae-global (npm)

Published Jun 20, 2022
MAL-2026-1169

Malicious code in @global-dax-ad-platform/dax-types (npm)

Published Mar 3, 2026
MAL-2023-8099

Malicious code in brum-global-variable (npm)

Published Sep 13, 2023
MAL-2026-364

Malicious code in shared-global-ec-uikit (npm)

Published Jan 20, 2026
MAL-2022-6922

Malicious code in videoplayershakaglobalconfig (npm)

Published Jun 20, 2022
MAL-2023-477

Malicious code in globalize-bundle (npm)

Published Mar 16, 2023
MAL-2023-62

Malicious code in @superbet-group/web.lib.global-styles (npm)

Published Feb 9, 2023
MAL-2022-5719

Malicious code in red-bull-global-onboarding (npm)

Published Jun 20, 2022
MAL-2025-192026

Malicious code in elf-stats-evergreen-snowglobe-961 (npm)

Published Dec 3, 2025
MAL-2025-192440

Malicious code in elf-stats-candystriped-snowglobe-426 (npm)

Published Dec 11, 2025
MAL-2024-8825

Malicious code in hyperion-global (npm)

Published Sep 5, 2024
MAL-2022-3390

Malicious code in global-order-tracker (npm)

Published Jun 20, 2022
MAL-2022-3391

Malicious code in globo-ab-client (npm)

Published Jun 20, 2022
MAL-2025-3933

Malicious code in novacredit-global2 (npm)

Published May 17, 2025
MAL-2025-48581

Malicious code in node-global-win (npm)

Published Oct 24, 2025
MAL-2026-1170

Malicious code in @global-dax-ad-platform/dax-utils (npm)

Published Mar 3, 2026
MAL-2025-192030

Malicious code in elf-stats-festive-snowglobe-440 (npm)

Published Dec 3, 2025
MAL-2025-3931

Malicious code in novacredit-global (npm)

Published May 17, 2025
CVE-2025-59052

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

Published Sep 10, 2025
MAL-2025-4421

Malicious code in ghpglobaldata (npm)

Published May 25, 2025
MAL-2025-4422

Malicious code in hpglobaldata (npm)

Published May 25, 2025
MAL-2022-643

Malicious code in @tide-web-apps/global-environments (npm)

Published Jun 14, 2022
MAL-2025-192237

Malicious code in elf-stats-storybook-snowglobe-157 (npm)

Published Dec 3, 2025
MAL-2025-48350

Malicious code in @global-engineering-shared/gweb-material-global (npm)

Published Oct 7, 2025
MAL-2026-139

Malicious code in rt-global-nav (npm)

Published Jan 7, 2026
MAL-2026-361

Malicious code in gu-global-ec-uikit (npm)

Published Jan 20, 2026
Check your entire dependency tree at onceRun dependency scan →