OsVault/npm/i
npm46 critical

i

1001 known vulnerabilities · 46 critical · 112 high

CVE-2021-3820HIGH

inflect vulnerable to Inefficient Regular Expression Complexity

Published Sep 29, 2021
CVE-2015-8851HIGH

Insecure Entropy Source - Math.random() in node-uuid

Published Apr 16, 2020
GHSA-22qr-rp27-j9wm

PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE

Published May 19, 2026
GHSA-2767-2q9v-9326

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

Published Apr 17, 2026
MAL-2024-931

Malicious code in iifl_api (npm)

Published Jan 29, 2024
MAL-2024-949

Malicious code in diil-front (npm)

Published Jan 31, 2024
MAL-2024-9495

Malicious code in agora-rtc-web (npm)

Published Oct 16, 2024
CVE-2024-9506

ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

Published Oct 15, 2024
GHSA-935g-9rq5-q95c

short-video-maker has a path traversal vulnerability

Published May 8, 2026
CVE-2020-27224CRITICAL

Cross-site Scripting (XSS) in Eclipse Theia

Published Apr 13, 2021
GHSA-4xw9-cx39-r355

json-web-token library is vulnerable to a JWT algorithm confusion attack

Published Nov 17, 2023
GHSA-49rj-9fvp-4h2h

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

Published Jun 3, 2026
MAL-2025-1628

Malicious code in sui-cctp (npm)

Published Feb 28, 2025
MAL-2025-7

Malicious code in treedome (npm)

Published Jan 2, 2025
MAL-2025-129

Malicious code in jssdk-infrastructure (npm)

Published Jan 16, 2025
CVE-2022-25906HIGH

is-http2 vulnerable to Improper Input Validation

Published Feb 1, 2023
CVE-2024-8182

Flowise Unauthenticated Denial of Service (DoS) vulnerability

Published Aug 27, 2024
MAL-2025-1290

Malicious code in kraken-dev (npm)

Published Feb 12, 2025
GHSA-5624-2pmv-jx46

Summarize contains a missing authorization vulnerability

Published May 18, 2026
MAL-2022-1842

Malicious code in caspets (npm)

Published Jun 20, 2022
MAL-2024-7927

Malicious code in ampersend-mymove (npm)

Published Aug 7, 2024
MAL-2022-1843

Malicious code in cat-weather-widget (npm)

Published Jun 20, 2022
MAL-2022-3021

Malicious code in ffwebsite (npm)

Published Jun 20, 2022
MAL-2022-7443

Malicious code in @getstep/sdk (npm)

Published Jun 20, 2022
MAL-2025-191057

Malicious code in @tiaanduplessis/react-progressbar (npm)

Published Nov 24, 2025
MAL-2025-191091

Malicious code in feature-flip (npm)

Published Nov 24, 2025
GHSA-2vx9-7wpg-88jq

n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

Published May 19, 2026
CVE-2025-27098

Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler

Published Feb 16, 2023
GHSA-654m-c8p4-x5fp

Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

Published May 29, 2026
MAL-2025-1454

Malicious code in yizhifabao60 (npm)

Published Feb 17, 2025
GHSA-32mq-hpph-xfvr

@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes

Published May 19, 2026
GHSA-3875-8gcx-7v46

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

Published May 19, 2026
MAL-2024-7940

Malicious code in bs58lite (npm)

Published Aug 7, 2024
GHSA-67gq-6q8c-qqh6

Summarize contains a missing authorization vulnerability

Published May 18, 2026
GHSA-6j2x-vhqr-qr7q

vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass

Published May 29, 2026
CVE-2023-26135HIGH

flatnest Prototype Pollution vulnerability

Published Jun 30, 2023
CVE-2025-13204

expr-eval vulnerable to Prototype Pollution

Published Nov 14, 2025
GHSA-3qcw-2rhx-2726

Turbo: Unexpected local code execution during Yarn Berry detection

Published May 19, 2026
CVE-2020-28438CRITICAL

deferred-exec Command Injection vulnerability

Published Jul 26, 2022
MAL-2025-1532

Malicious code in int_pinterest_sfra (npm)

Published Feb 23, 2025
MAL-2024-7960

Malicious code in gutenberg-ui (npm)

Published Aug 7, 2024
GHSA-75hx-xj24-mqrw

n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport

Published Apr 10, 2026
GHSA-76w7-j9cq-rx2j

vm2 is Vulnerable to Sandbox Breakout Through Promise Species

Published May 29, 2026
GHSA-866g-f22w-33x8

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

Published May 18, 2026
MAL-2025-1547

Malicious code in zzmaliciouspackage (npm)

Published Feb 23, 2025
GHSA-2qrv-rc5x-2g2h

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

Published Apr 7, 2026
GHSA-898c-q2cr-xwhg

axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

Published May 29, 2026
MAL-2025-1625

Malicious code in sddst-ui (npm)

Published Feb 28, 2025
MAL-2024-7978

Malicious code in onboarding-components (npm)

Published Aug 7, 2024
GHSA-6vr3-7wcx-v5g5

browserstack-runner vulnerable to Remote Code Execution via vm sandbox escape in _log HTTP handler

Published Jun 3, 2026
CVE-2017-16175HIGH

Directory Traversal in ewgaddis.lab6

Published Jul 23, 2018
MAL-2026-3987

Malicious code in @antv/g6-element (npm)

Published May 19, 2026
MAL-2025-1655

Malicious code in secureshield4 (npm)

Published Mar 1, 2025
CVE-2025-57354

counterpart vulnerable to prototype pollution

Published Sep 24, 2025
GHSA-c4cf-2hgv-2qv6

vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain

Published May 29, 2026
CVE-2022-28397CRITICAL

Arbitrary file upload in Ghost

Published Apr 13, 2022
MAL-2025-1689

Malicious code in @f2p-mml-frontends/mml-styles (npm)

Published Mar 3, 2025
MAL-2026-4263

Malicious code in secdriven (npm)

Published May 23, 2026
GHSA-4c35-wcg5-mm9h

next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys

Published May 6, 2026
CVE-2021-23440HIGH

Prototype Pollution in set-value

Published Sep 13, 2021
CVE-2017-16057HIGH

nodemssql is malware

Published Nov 9, 2018
GHSA-4fg7-f244-3j49

HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

Published May 19, 2026
MAL-2026-4264

Malicious code in dds-js-idl (npm)

Published May 23, 2026
MAL-2026-4256

Malicious code in @citi-icg-171632/citicms-repo-component (npm)

Published May 22, 2026
MAL-2026-4257

Malicious code in @cloudways-lab/unified-design-system (npm)

Published May 22, 2026
GHSA-9g8x-92q2-p28f

NodeVM observability builtins leak host process and HTTP request data

Published May 29, 2026
CVE-2013-7379MEDIUM

API Admin Auth Weakness in tomato

Published Aug 31, 2020
GHSA-g6ww-w5j2-r7x3

BoxLite: Permission Bypass Allows Modification of Read-Only Files

Published May 21, 2026
MAL-2026-4258

Malicious code in @engagehub/core (npm)

Published May 22, 2026
MAL-2025-190761

Malicious code in @zapier/babel-preset-zapier (npm)

Published Nov 24, 2025
CVE-2026-29053

Ghost Vulnerable to Remote Code Execution via Malicious Themes

Published Mar 3, 2026
CVE-2024-53384

tsup DOM Clobbering vulnerability

Published Mar 3, 2025
CVE-2020-24855MEDIUM

easywebpack-cli Path Traversal vulnerability

Published Dec 15, 2022
CVE-2022-39203HIGH

Parsing issue in matrix-org/node-irc leading to room takeovers

Published Sep 15, 2022
GHSA-5cvp-p7p4-mcx9

Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass

Published May 18, 2026
CVE-2023-5573MEDIUM

Allocation of Resources Without Limits or Throttling in vriteio/vrite

Published Oct 13, 2023
CVE-2024-23725MEDIUM

Cross-site Scripting in Ghost

Published Jan 21, 2024
GHSA-h64w-w9pr-82m4

ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag

Published May 29, 2026
CVE-2022-39287HIGH

tiny-csrf has openly visible CSRF tokens

Published Oct 7, 2022
CVE-2026-23957

Seroval affected by Denial of Service via Array serialization

Published Jan 21, 2026
CVE-2026-25722

Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection

Published Feb 6, 2026
MAL-2024-801

Malicious code in wlwz-2312-7001 (npm)

Published Jan 24, 2024
CVE-2026-32064

OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 3, 2026
CVE-2026-28452

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

Published Feb 18, 2026
MAL-2025-190950

Malicious code in compare-obj (npm)

Published Nov 24, 2025
MAL-2025-190958

Malicious code in email-deliverability-tester (npm)

Published Nov 24, 2025
GHSA-8cph-rgr4-g5vj

Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers

Published May 29, 2026
CVE-2025-12758

Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements

Published Nov 27, 2025
GHSA-3xx2-mqjm-hg9x

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

Published Apr 16, 2026
GHSA-25wv-8phj-8p7r

OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths

Published Apr 9, 2026
GHSA-8ghr-w65f-j3qr

FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions

Published Jun 8, 2026
CVE-2022-43441HIGH

sqlite vulnerable to code execution due to Object coercion

Published Mar 13, 2023
CVE-2022-41777HIGH

nadesiko3 allows remote attacker to inject invalid value to decodeURIComponent of nako3edit

Published Dec 5, 2022
MAL-2024-8020

Malicious code in benasin_logger (npm)

Published Aug 9, 2024
MAL-2025-190995

Malicious code in react-native-datepicker-modal (npm)

Published Nov 24, 2025
MAL-2025-191004

Malicious code in react-native-retriable-fetch (npm)

Published Nov 24, 2025
MAL-2025-191053

Malicious code in @seezo/sdr-mcp-server (npm)

Published Nov 24, 2025
GHSA-m4wx-m65x-ghrr

vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE

Published May 29, 2026
CVE-2022-39225MEDIUM

parse-server's session object properties can be updated by foreign user if object ID is known

Published Sep 21, 2022
CVE-2025-4644

Payload's SQLite adapter Session Fixation vulnerability

Published Aug 29, 2025
CVE-2026-26830

pdf-image has an OS Command Injection Vulnerability through its pdfFilePath parameter

Published Mar 25, 2026
CVE-2013-4660MEDIUM

Deserialization Code Execution in js-yaml

Published Oct 24, 2017
MAL-2024-8040

Malicious code in system-library-gameanalytics-common (npm)

Published Aug 26, 2024
GHSA-8646-j5j9-6r62

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

Published Jun 3, 2026
GHSA-m5q2-4fm3-vfqp

vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks

Published May 29, 2026
MAL-2022-1247

Malicious code in azure-arm-iothub-samples-ts (npm)

Published Jun 20, 2022
MAL-2022-3989

Malicious code in iv-build-utils (npm)

Published Jun 20, 2022
MAL-2025-191066

Malicious code in automation_model (npm)

Published Nov 24, 2025
MAL-2025-191069

Malicious code in babel-preset-kinvey-flex-service (npm)

Published Nov 24, 2025
MAL-2025-191073

Malicious code in better-auth-nuxt (npm)

Published Nov 24, 2025
GHSA-4948-f92q-f432

@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading

Published Apr 22, 2026
CVE-2015-1369HIGH

SQL Injection in sequelize

Published Oct 24, 2017
CVE-2023-37299MEDIUM

Joplin Cross-site Scripting vulnerability

Published Jun 30, 2023
MAL-2022-3756

Malicious code in icons-mail (npm)

Published Jun 20, 2022
MAL-2022-517

Malicious code in @portswigger/fetlife-assets (npm)

Published Jun 20, 2022
MAL-2022-5170

Malicious code in ozone-material (npm)

Published Jun 20, 2022
CVE-2022-39396CRITICAL

Remote code execution via MongoDB BSON parser through prototype pollution

Published Nov 8, 2022
CVE-2015-8856MEDIUM

Cross-Site Scripting in serve-index

Published Oct 24, 2017
MAL-2022-1027

Malicious code in anypoint-component-site (npm)

Published Aug 19, 2022
MAL-2024-8065

Malicious code in who_mobile (npm)

Published Aug 28, 2024
CVE-2023-29019HIGH

Session fixation in fastify-passport

Published Apr 21, 2023
GHSA-8rpw-6cqh-2v9h

browserstack-runner has an unauthenticated arbitrary file read via path traversal in HTTP server

Published Jun 3, 2026
MAL-2022-5171

Malicious code in p224 (npm)

Published Jun 20, 2022
MAL-2025-191138

Malicious code in pergel (npm)

Published Nov 24, 2025
MAL-2025-191151

Malicious code in wallet-evm (npm)

Published Nov 24, 2025
CVE-2019-10061CRITICAL

OS Command Injection in node-opencv

Published Oct 12, 2021
MAL-2022-6498

Malicious code in test494 (npm)

Published Jun 20, 2022
CVE-2016-10550CRITICAL

SQL Injection in sequelize

Published Feb 18, 2019
CVE-2022-41878HIGH

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

Published Nov 9, 2022
MAL-2025-191172

Malicious code in @accordproject/concerto-linter (npm)

Published Nov 25, 2025
GHSA-4rc3-7j7w-m548

liquidjs has a Denial of Service via circular block reference in layout

Published Apr 24, 2026
MAL-2025-191173

Malicious code in @accordproject/concerto-linter-default-ruleset (npm)

Published Nov 25, 2025
GHSA-8x6r-g9mw-2r78

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

Published Jun 3, 2026
MAL-2022-1028

Malicious code in anyswap-rewards (npm)

Published Jul 18, 2022
MAL-2024-8090

Malicious code in sweet-ruin-immortals-after-dark-16-by-kresley-cole-on-audiobook-full-volumes- (npm)

Published Aug 29, 2024
GHSA-4x48-cgf9-q33f

Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection

Published Apr 14, 2026
CVE-2016-10531MEDIUM

Sanitization bypass using HTML Entities in marked

Published Feb 18, 2019
GHSA-q3fm-4wcw-g57x

vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter

Published May 29, 2026
MAL-2022-5341

Malicious code in pipedrive-embeddable-ringcentral-phone-spa (npm)

Published Jun 20, 2022
CVE-2021-46704CRITICAL

OS Command Injection in GenieACS

Published Mar 7, 2022
CVE-2019-10802CRITICAL

OS Command Injection in giting

Published Apr 13, 2021
CVE-2016-10661HIGH

Downloads Resources over HTTP in phantomjs-cheniu

Published Feb 18, 2019
MAL-2024-8099

Malicious code in @diotoborg/a-quas (npm)

Published Sep 2, 2024
MAL-2024-81

Malicious code in schibsted-style (npm)

Published Jan 11, 2024
GHSA-qr28-p3wr-mxq3

ngrok is Vulnerable to Command Injection

Published May 18, 2026
MAL-2022-5471

Malicious code in prod_assets_web_modules (npm)

Published Jun 20, 2022
CVE-2025-45143

string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)

Published Jun 30, 2025
CVE-2022-37262HIGH

steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments

Published Sep 16, 2022
MAL-2024-8108

Malicious code in @diotoborg/ad-non (npm)

Published Sep 2, 2024
CVE-2026-32061

OpenClaw vulnerable to arbitrary file read via $include directive

Published Mar 3, 2026
MAL-2025-191248

Malicious code in @oku-ui/alert-dialog (npm)

Published Nov 25, 2025
MAL-2025-191265

Malicious code in @oku-ui/presence (npm)

Published Nov 25, 2025
CVE-2023-26118MEDIUM

angular vulnerable to regular expression denial of service via the <input type="url"> element

Published Mar 30, 2023
MAL-2023-152

Malicious code in caas-canvas (npm)

Published Mar 31, 2023
MAL-2024-10263

Malicious code in kbc-ui.templates (npm)

Published Oct 29, 2024
MAL-2024-12119

Malicious code in stablecoin-aptos (npm)

Published Dec 24, 2024
CVE-2016-5682MEDIUM

Cross-Site Scripting in swagger-ui

Published Sep 1, 2020
GHSA-47wq-cj9q-wpmp

Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys

Published Apr 16, 2026
MAL-2024-8122

Malicious code in @diotoborg/aliquam-fugit-culpa (npm)

Published Sep 2, 2024
MAL-2025-191294

Malicious code in @posthog/laudspeaker-plugin (npm)

Published Nov 25, 2025
CVE-2022-24278HIGH

Directory traversal in convert-svg-core

Published Jun 11, 2022
MAL-2024-382

Malicious code in wlwz-2312-2305 (npm)

Published Jan 24, 2024
CVE-2021-29059HIGH

ReDOS in IS-SVG

Published Dec 10, 2021
GHSA-r9pm-gxmw-wv6p

NodeVM network builtin exclusions bypass via internal _http_client and _http_server

Published May 29, 2026
MAL-2025-191410

Malicious code in quickswap-smart-order-router (npm)

Published Nov 24, 2025
CVE-2021-23495MEDIUM

Open redirect in karma

Published Feb 26, 2022
GHSA-rp36-8xq3-r6c4

NodeVM builtin denylist bypass via process and inspector/promises allows host code execution

Published May 29, 2026
MAL-2025-191171

Malicious code in @accordproject/concerto-analysis (npm)

Published Nov 25, 2025
CVE-2024-27088

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
MAL-2024-8041

Malicious code in system-library-gameanalytics-slotanalytics (npm)

Published Aug 26, 2024
GHSA-f22v-gfqf-p8f3

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

Published Jun 3, 2026
GHSA-6c8g-9hfh-pq5h

HAXcms: Private Key Disclosure via Broken HMAC Implementation

Published May 19, 2026
MAL-2025-191433

Malicious code in tcsp (npm)

Published Nov 25, 2025
MAL-2024-8145

Malicious code in @diotoborg/aspernatur-id (npm)

Published Sep 2, 2024
CVE-2025-5891

pm2 Regular Expression Denial of Service vulnerability

Published Jun 9, 2025
CVE-2017-16007MEDIUM

Invalid Curve Attack in node-jose

Published Jul 20, 2018
MAL-2025-191435

Malicious code in tiptap-shadcn-vue (npm)

Published Nov 24, 2025
GHSA-4jpm-cgx2-8h37

Flowise: Sensitive Data Leak in public-chatbotConfig

Published Apr 16, 2026
CVE-2022-27263CRITICAL

Unrestricted Upload of File with Dangerous Type in Strapi

Published Apr 13, 2022
MAL-2024-8151

Malicious code in @diotoborg/assumenda-saepe-mollitia (npm)

Published Sep 2, 2024
CVE-2017-16095HIGH

Directory Traversal in serverliujiayi1

Published Sep 1, 2020
CVE-2017-16201HIGH

Directory Traversal in zjjserver

Published Sep 1, 2020
MAL-2025-190584

Malicious code in @kiwiiw/ez-lib (npm)

Published Nov 20, 2025
GHSA-h9fj-c2qr-76g2

FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString

Published Jun 8, 2026
GHSA-6vp2-6r7m-2jvx

Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour

Published May 19, 2026
MAL-2022-1086

Malicious code in argocd-diff-action (npm)

Published Jun 20, 2022
GHSA-rr89-w3h9-m66j

ExifReader is vulnerable to denial of service via unbounded decompression of image metadata

Published May 29, 2026
MAL-2024-8163

Malicious code in @diotoborg/autem-dolor (npm)

Published Sep 2, 2024
MAL-2024-8164

Malicious code in @diotoborg/autem-id (npm)

Published Sep 2, 2024
GHSA-j42q-r6qx-xrfp

Duplicate Advisory: OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName

Published Apr 10, 2026
MAL-2025-191480

Malicious code in accounts-base (npm)

Published Nov 27, 2025
MAL-2025-191482

Malicious code in wartsila-application-json (npm)

Published Nov 27, 2025
MAL-2025-191174

Malicious code in @accordproject/concerto-metamodel (npm)

Published Nov 25, 2025
CVE-2023-23630HIGH

XSS Attack with Express API

Published Jan 31, 2023
MAL-2024-8167

Malicious code in @diotoborg/autem-vero (npm)

Published Sep 2, 2024
GHSA-jhm7-29pj-4xvf

@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codes

Published Apr 16, 2026
GHSA-c73c-x77g-854r

OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS

Published May 12, 2026
CVE-2021-43307MEDIUM

Regular expression denial of service in semver-regex

Published Jun 3, 2022
GHSA-v6mx-mf47-r5wg

vm2 has a Sandbox Escape issue

Published May 29, 2026
GHSA-6xwp-cp5h-q856

Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm

Published May 19, 2026
MAL-2025-191199

Malicious code in @browserbasehq/stagehand-docs (npm)

Published Nov 25, 2025
MAL-2025-191276

Malicious code in @oku-ui/tabs (npm)

Published Nov 25, 2025
CVE-2023-7078HIGH

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 29, 2023
CVE-2023-46998MEDIUM

Bootbox.js Cross Site Scripting vulnerability

Published Nov 14, 2023
MAL-2022-1030

Malicious code in aocrn (npm)

Published Aug 19, 2022
MAL-2024-818

Malicious code in wlwz-2312-7200 (npm)

Published Jan 24, 2024
CVE-2011-4969MEDIUM

jQuery vulnerable to Cross-Site Scripting (XSS)

Published May 14, 2022
MAL-2025-191359

Malicious code in @voiceflow/nestjs-rate-limit (npm)

Published Nov 25, 2025
GHSA-7hgr-7h44-33w2

CamoFox MCP: Unauthenticated HTTP MCP browser-control surface

Published May 19, 2026
CVE-2023-27563HIGH

n8n Privilege Escalation vulnerability

Published May 10, 2023
GHSA-7mqx-wwh4-f9fw

Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying

Published May 13, 2026
CVE-2017-16079HIGH

smb is malware

Published Aug 29, 2018
CVE-2021-33040MEDIUM

Cross-site Scripting in epubjs

Published Jan 21, 2022
CVE-2020-8137CRITICAL

Code injection in blamer

Published May 6, 2021
CVE-2019-10769CRITICAL

Sandbox Breakout / Arbitrary Code Execution in safer-eval

Published Dec 11, 2019
CVE-2019-15658HIGH

SQL Injection in connect-pg-simple

Published Aug 26, 2019
CVE-2019-25225MEDIUM

sanitize-html is vulnerable to XSS through incomprehensive sanitization

Published Sep 8, 2025
CVE-2026-25641

@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses

Published Feb 5, 2026
GHSA-wjjv-3mj2-39hf

AgenticMail API/storage and outbound relay hardening fixes

Published May 29, 2026
GHSA-ccfq-2454-f5xw

SillyTavern has a SSRF vulnerability in the CORS proxy middleware

Published May 12, 2026
MAL-2022-1458

Malicious code in bankin_thechnical (npm)

Published Jun 20, 2022
MAL-2025-191424

Malicious code in shell-exec (npm)

Published Nov 24, 2025
CVE-2022-3145MEDIUM

@okta/oidc-middlewareOpen Redirect vulnerability

Published Jan 9, 2023
CVE-2024-21505HIGH

web3-utils Prototype Pollution vulnerability

Published Mar 27, 2024
CVE-2024-21536HIGH

Denial of service in http-proxy-middleware

Published Oct 19, 2024
CVE-2020-12648MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Aug 11, 2020
MAL-2025-191538

Malicious code in hl-naduccio (npm)

Published Dec 1, 2025
MAL-2022-1486

Malicious code in bdesse (npm)

Published Aug 19, 2022
MAL-2024-8191

Malicious code in @diotoborg/corporis-quia (npm)

Published Sep 2, 2024
GHSA-g3xq-3gmv-qq8g

claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh

Published May 13, 2026
MAL-2022-5379

Malicious code in pm-manager (npm)

Published Aug 2, 2022
CVE-2018-3722HIGH

Prototype Pollution in merge-deep

Published Jul 26, 2018
MAL-2022-5472

Malicious code in product-tools (npm)

Published Jun 20, 2022
MAL-2025-191491

Malicious code in babel-plugin-standalone (npm)

Published Nov 30, 2025
GHSA-hvp3-26wx-g2w4

Strapi: Password Reset Does Not Revoke Existing Refresh Sessions

Published May 13, 2026
GHSA-9r33-xhw8-4qqp

HAX CMS: Denial of Service using Malicious Import Request

Published May 19, 2026
CVE-2024-43795MEDIUM

OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)

Published Oct 2, 2024
MAL-2022-6278

Malicious code in srve-favico (npm)

Published Aug 19, 2022
MAL-2023-1274

Malicious code in proton-pack (npm)

Published May 2, 2023
MAL-2024-519

Malicious code in wlwz-2312-3807 (npm)

Published Jan 24, 2024
MAL-2024-529

Malicious code in wlwz-2312-3908 (npm)

Published Jan 24, 2024
MAL-2024-7283

Malicious code in @zitterorg/natus-eos-vel (npm)

Published Jul 4, 2024
CVE-2023-45884MEDIUM

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Published Nov 9, 2023
CVE-2023-37466CRITICAL

vm2 Sandbox Escape vulnerability

Published Jul 13, 2023
MAL-2025-191576

Malicious code in jqxcore (npm)

Published Dec 1, 2025
MAL-2025-191583

Malicious code in redirect-5k9q5v (npm)

Published Dec 1, 2025
CVE-2023-27490HIGH

Missing proper state, nonce and PKCE checks for OAuth authentication

Published Mar 13, 2023
GHSA-5fw2-mwhh-9947

Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials

Published Apr 17, 2026
MAL-2025-191584

Malicious code in redirect-clrm2u (npm)

Published Dec 1, 2025
GHSA-fhh6-4qxv-rpqj

9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

Published May 19, 2026
MAL-2024-8192

Malicious code in @diotoborg/corporis-repellat-dicta (npm)

Published Sep 2, 2024
CVE-2025-68457

Orejime has executable code in HTML attributes

Published Dec 19, 2025
MAL-2025-2658

Malicious code in cln-logger (npm)

Published Mar 25, 2025
MAL-2025-6190

Malicious code in obvbd (npm)

Published Jul 22, 2025
MAL-2025-7074

Malicious code in @amber-team/storybook-utils (npm)

Published Aug 14, 2025
CVE-2026-2265MEDIUM
Risk: 32.52/100

Replicator deserializes untrusted user input

Published Apr 1, 2026
CVE-2022-1650HIGH

Exposure of Sensitive Information in eventsource

Published May 13, 2022
GHSA-ccx3-fw7q-rr2r

OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks

Published Apr 9, 2026
CVE-2021-31597CRITICAL

Improper Certificate Validation in xmlhttprequest-ssl

Published May 24, 2021
CVE-2022-37623CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 31, 2022
MAL-2022-1031

Malicious code in aoe_playstyle (npm)

Published Jun 20, 2022
MAL-2024-8206

Malicious code in @diotoborg/cum-saepe-minima (npm)

Published Sep 2, 2024
MAL-2024-8207

Malicious code in @diotoborg/cum-ut-iure (npm)

Published Sep 2, 2024
MAL-2025-1206

Malicious code in appqos-client (npm)

Published Feb 3, 2025
CVE-2021-3223HIGH

Path traversal in Node-RED-Dashboard

Published Jan 29, 2021
CVE-2020-7755HIGH

Regular Expression Denial of Service in dat.gui

Published May 10, 2021
MAL-2025-191993

Malicious code in elf-stats-bright-cushion-246 (npm)

Published Dec 3, 2025
MAL-2022-1033

Malicious code in ap-election-adapter (npm)

Published Jun 20, 2022
CVE-2019-15600HIGH

Cross-Site Scripting in http_server

Published Mar 31, 2020
MAL-2024-8215

Malicious code in @diotoborg/delectus-recusandae-aut (npm)

Published Sep 2, 2024
GHSA-fx6j-w5w5-h468

Nuxt: Reflected XSS in `navigateTo()` external redirect

Published May 19, 2026
MAL-2025-1455

Malicious code in yizhifabao61 (npm)

Published Feb 17, 2025
MAL-2025-182

Malicious code in dotgov-list (npm)

Published Jan 20, 2025
MAL-2025-7964

Malicious code in @frozen-team-qa/types (npm)

Published Aug 14, 2025
CVE-2023-32235HIGH

Path Traversal in Ghost

Published May 5, 2023
CVE-2020-24660CRITICAL

Lack of URL normalization may lead to authorization bypass when URL access rules are used

Published Sep 9, 2020
CVE-2021-26073HIGH

Broken Authentication in Atlassian Connect Express

Published May 24, 2022
CVE-2020-7632CRITICAL

OS Command Injection in node-mpv

Published Jan 7, 2022
MAL-2024-8224

Malicious code in @diotoborg/dicta-recusandae-veniam (npm)

Published Sep 2, 2024
MAL-2024-8225

Malicious code in @diotoborg/dignissimos-aliquam (npm)

Published Sep 2, 2024
CVE-2024-21539HIGH

Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit

Published Nov 15, 2024
GHSA-7q9x-8g6p-3x75

@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template

Published Mar 25, 2026
GHSA-cr3w-cw5w-h3fj

Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE

Published Jan 26, 2026
CVE-2026-27122

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

Published Feb 19, 2026
MAL-2026-1062

Malicious code in express-core-validator (npm)

Published Feb 27, 2026
CVE-2021-23335HIGH

LDAP Injection in is-user-valid

Published Apr 13, 2021
MAL-2026-3257

Malicious code in @omni-corp-infra/sso-bridge-core (npm)

Published Apr 29, 2026
CVE-2020-7681HIGH

Path Traversal in marscode

Published May 7, 2021
MAL-2026-3258

Malicious code in @tech-global/internal-gateway-core (npm)

Published Apr 29, 2026
GHSA-5w25-hxp5-h8c9

Duplicate Advisory: Improper Verification of Cryptographic Signature

Published Jun 21, 2021
MAL-2024-8235

Malicious code in @diotoborg/dolor-earum-quia (npm)

Published Sep 2, 2024
GHSA-95h2-gj7x-gx9w

Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

Published Apr 9, 2026
MAL-2024-8236

Malicious code in @diotoborg/dolor-iure (npm)

Published Sep 2, 2024
MAL-2025-190642

Malicious code in @asyncapi/react-component (npm)

Published Nov 24, 2025
MAL-2022-1042

Malicious code in api-routes-rest (npm)

Published Jul 21, 2022
MAL-2024-8249

Malicious code in @diotoborg/dolores-fugiat-autem (npm)

Published Sep 2, 2024
CVE-2026-30920

OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding

Published Mar 9, 2026
CVE-2020-7763HIGH

Arbitrary File Read in phantom-html-to-pdf

Published Nov 6, 2020
MAL-2025-190961

Malicious code in expressos (npm)

Published Nov 24, 2025
MAL-2025-191441

Malicious code in uniswap-router-sdk (npm)

Published Nov 24, 2025
MAL-2025-191517

Malicious code in mongodb-atlas-cli-toc-generator (npm)

Published Dec 1, 2025
MAL-2026-3263

Malicious code in @bcs-adapters/core-adapter (npm)

Published May 4, 2026
MAL-2025-192085

Malicious code in elf-stats-merry-chimney-765 (npm)

Published Dec 3, 2025
MAL-2024-8260

Malicious code in @diotoborg/dolorum-dolorum (npm)

Published Sep 2, 2024
CVE-2021-43812MEDIUM

Open redirect in @auth0/nextjs-auth0

Published Dec 16, 2021
CVE-2016-10559HIGH

Downloads Resources over HTTP in selenium-download

Published Feb 18, 2019
MAL-2024-8261

Malicious code in @diotoborg/dolorum-ipsam (npm)

Published Sep 2, 2024
CVE-2024-29027CRITICAL

Server crashes on invalid Cloud Function or Cloud Job name

Published Mar 19, 2024
CVE-2020-7629CRITICAL

OS Command Injection in install-package

Published Feb 10, 2022
MAL-2024-8262

Malicious code in @diotoborg/dolorum-iste-excepturi (npm)

Published Sep 2, 2024
MAL-2026-2135

Malicious code in yelp-react-component-photo-upload (npm)

Published Mar 24, 2026
MAL-2026-3280

Malicious code in pi-exa-mcp (npm)

Published May 4, 2026
MAL-2026-3281

Malicious code in pos-next-react-native (npm)

Published May 4, 2026
MAL-2026-3282

Malicious code in shopify-draggable (npm)

Published May 4, 2026
MAL-2024-8271

Malicious code in @diotoborg/eaque-illum-qui (npm)

Published Sep 2, 2024
MAL-2024-8272

Malicious code in @diotoborg/eaque-iste (npm)

Published Sep 2, 2024
MAL-2025-192140

Malicious code in elf-stats-snowdusted-fireplace-396 (npm)

Published Dec 3, 2025
CVE-2025-8101

Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)

Published Jul 26, 2025
CVE-2025-24012

XSS/HTML Injection Vulnerability in Umbraco Backoffice Components

Published Jan 21, 2025
MAL-2025-192141

Malicious code in elf-stats-snowdusted-saddlebag-790 (npm)

Published Dec 3, 2025
GHSA-6pfc-6m7w-m8fx

OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper

Published Mar 31, 2026
CVE-2020-9038MEDIUM

Cross-site Scripting in Joplin

Published Oct 13, 2020
MAL-2025-48539

Malicious code in zdachboostv3 (npm)

Published Oct 21, 2025
MAL-2026-3283

Malicious code in temhe-dev (npm)

Published May 4, 2026
MAL-2026-3284

Malicious code in tinfoil-shops (npm)

Published May 4, 2026
CVE-2026-27001

OpenClaw: Unsanitized CWD path injection into LLM prompts

Published Feb 18, 2026
GHSA-534w-2vm4-89xr

OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch

Published Mar 3, 2026
CVE-2020-7617MEDIUM

Prototype Pollution in ini-parser

Published Jun 10, 2020
MAL-2025-192154

Malicious code in elf-stats-sparkly-cocoa-863 (npm)

Published Dec 3, 2025
MAL-2025-192159

Malicious code in elf-stats-sprucey-snowman-250 (npm)

Published Dec 3, 2025
CVE-2025-29927

Authorization Bypass in Next.js Middleware

Published Mar 21, 2025
CVE-2021-25913CRITICAL

Prototype Pollution in set-or-get

Published Apr 12, 2021
CVE-2026-23889

pnpm has Windows-specific tarball Path Traversal

Published Jan 26, 2026
CVE-2023-46308CRITICAL

plotly.js prototype pollution vulnerability

Published Jan 3, 2024
MAL-2024-828

Malicious code in wlwz-2312-7301 (npm)

Published Jan 24, 2024
MAL-2025-9264

Malicious code in @protos-team/frontend-server (npm)

Published Aug 14, 2025
MAL-2026-3285

Malicious code in vpi-guides (npm)

Published May 4, 2026
MAL-2024-8280

Malicious code in @diotoborg/eius-animi-ullam (npm)

Published Sep 2, 2024
MAL-2026-3286

Malicious code in wagner-horizon (npm)

Published May 4, 2026
CVE-2021-39171MEDIUM

Unlimited transforms allowed for signed nodes

Published Aug 30, 2021
CVE-2017-20160MEDIUM

express-param vulnerable to Improper Handling of Extra Parameters

Published Dec 31, 2022
CVE-2016-10598HIGH

arrayfire-js downloads Resources over HTTP

Published Feb 18, 2019
MAL-2025-192181

Malicious code in elf-stats-twinkling-marshmallow-913 (npm)

Published Dec 3, 2025
CVE-2025-5276

Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Published May 29, 2025
MAL-2025-192197

Malicious code in elf-stats-wintry-icicle-283 (npm)

Published Dec 3, 2025
MAL-2022-109

Malicious code in @azure-tests/perf-service-bus (npm)

Published Jun 20, 2022
CVE-2016-10519HIGH

Remote Memory Disclosure in bittorrent-dht

Published Sep 1, 2020
CVE-2024-22891CRITICAL

Nteract Remote Code Execution vulnerability

Published Mar 1, 2024
MAL-2022-1090

Malicious code in arkane-network (npm)

Published Jun 20, 2022
MAL-2026-3903

Malicious code in @antv/f6-element (npm)

Published May 19, 2026
MAL-2026-1361

Malicious code in pcl-build-docroot (npm)

Published Mar 12, 2026
MAL-2026-2415

Malicious code in oc-aa-module-client (npm)

Published Mar 24, 2026
MAL-2026-3287

Malicious code in ams-ssk (npm)

Published May 2, 2026
CVE-2019-5485CRITICAL

Command Injection in gitlabhook

Published Sep 16, 2019
CVE-2022-39384MEDIUM

OpenZeppelin Contracts initializer reentrancy may lead to double initialization

Published Dec 14, 2021
CVE-2025-57752

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

Published Aug 29, 2025
CVE-2020-36650MEDIUM

gry vulnerable to Command Injection

Published Jan 11, 2023
MAL-2024-8290

Malicious code in @diotoborg/esse-accusantium-ratione (npm)

Published Sep 2, 2024
CVE-2024-51434

Froala WYSIWYG editor allows cross-site scripting (XSS)

Published Nov 8, 2024
MAL-2024-8291

Malicious code in @diotoborg/esse-distinctio-repellat (npm)

Published Sep 2, 2024
MAL-2025-192210

Malicious code in elf-stats-frostbitten-reindeer-875 (npm)

Published Dec 3, 2025
MAL-2026-4265

Malicious code in @asavie/i18n (npm)

Published May 23, 2026
MAL-2026-4461

Malicious code in @venturo/playwright (npm)

Published May 20, 2026
MAL-2025-192212

Malicious code in elf-stats-ginger-reindeer-411 (npm)

Published Dec 3, 2025
MAL-2026-3288

Malicious code in common-tg-service (npm)

Published May 2, 2026
MAL-2026-3322

Malicious code in microsoft-agents-auth-service (npm)

Published May 4, 2026
GHSA-2rqg-gjgv-84jm

OpenClaw: Gateway `agent` calls could override the workspace boundary

Published Mar 13, 2026
MAL-2025-192213

Malicious code in elf-stats-gingersnap-ornament-469 (npm)

Published Dec 3, 2025
MAL-2025-192214

Malicious code in elf-stats-glittering-fir-252 (npm)

Published Dec 3, 2025
CVE-2020-7639MEDIUM

eivindfjeldstad-dot contains prototype pollution vulnerability

Published May 25, 2021
MAL-2024-8303

Malicious code in @diotoborg/et-voluptatum-mollitia (npm)

Published Sep 2, 2024
GHSA-5g3j-89fr-r2vp

skilleton has improper input handling in repository/path processing

Published Apr 8, 2026
CVE-2020-7682HIGH

Path Traversal in marked-tree

Published May 7, 2021
CVE-2022-29257MEDIUM

AutoUpdater module fails to validate certain nested components of the bundle

Published Jun 16, 2022
GHSA-3298-56p6-rpw2

OpenClaw has incomplete Fix for CVE-2026-27486: Unvalidated SIGKILL in `!stop` Chat Command via `shell-utils.ts`

Published Mar 30, 2026
GHSA-g87j-gm7p-6vw2

Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 19, 2026
CVE-2021-23354MEDIUM

printf vulnerable to Regular Expression Denial of Service (ReDoS)

Published Mar 19, 2021
MAL-2024-8316

Malicious code in @diotoborg/eveniet-officia (npm)

Published Sep 2, 2024
CVE-2021-34080CRITICAL

OS Command injection in ssl-utils

Published Jun 3, 2022
CVE-2025-66031

node-forge has ASN.1 Unbounded Recursion

Published Nov 26, 2025
CVE-2023-31999HIGH

@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state

Published Jul 5, 2023
CVE-2021-23348MEDIUM

Arbitrary Command Injection in portprocesses

Published Apr 6, 2021
MAL-2024-8317

Malicious code in @diotoborg/eveniet-pariatur-esse (npm)

Published Sep 2, 2024
MAL-2024-8318

Malicious code in @diotoborg/ex-quo-odio (npm)

Published Sep 2, 2024
MAL-2026-3323

Malicious code in paypal-payouts-bridge (npm)

Published May 4, 2026
GHSA-7853-gqqm-vcwx

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools

Published Apr 8, 2026
MAL-2026-4734

Malicious code in xorma-js (npm)

Published May 19, 2026
MAL-2025-192218

Malicious code in elf-stats-merry-cookiejar-442 (npm)

Published Dec 3, 2025
MAL-2026-3326

Malicious code in paychex-common-vendor-lib (npm)

Published May 4, 2026
CVE-2019-14772MEDIUM

Cross-Site Scripting (XSS) in Verdaccio

Published May 29, 2019
MAL-2025-192229

Malicious code in elf-stats-sleighing-nutcracker-806 (npm)

Published Dec 3, 2025
CVE-2025-53889

Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows

Published Jul 15, 2025
MAL-2025-192266

Malicious code in elf-stats-silvered-star-676 (npm)

Published Dec 3, 2025
MAL-2025-192267

Malicious code in elf-stats-snowdusted-lantern-234 (npm)

Published Dec 3, 2025
GHSA-7fqq-q52p-2jjg

OpenCC has an Out-of-bounds read when processing truncated UTF-8 input

Published Mar 29, 2026
MAL-2026-3329

Malicious code in api-typings (npm)

Published May 4, 2026
MAL-2026-3330

Malicious code in seek-pass (npm)

Published May 4, 2026
MAL-2026-4834

Malicious code in @polka-ui/config (npm)

Published May 27, 2026
GHSA-7jp6-r74r-995q

OpenClaw: Matrix profile config persistence was reachable from operator.write message tools

Published Apr 17, 2026
MAL-2026-3331

Malicious code in lazyhtml-scripts (npm)

Published May 4, 2026
MAL-2026-3337

Malicious code in @t-in-one/save_application_hid_to_storage (npm)

Published May 4, 2026
MAL-2026-3338

Malicious code in ms.analytics-web (npm)

Published May 4, 2026
MAL-2022-4540

Malicious code in mefthos (npm)

Published Aug 19, 2022
MAL-2025-192368

Malicious code in paysera-checkout-modal (npm)

Published Dec 7, 2025
MAL-2025-192370

Malicious code in elf-stats-snowdusted-cookiejar-250 (npm)

Published Dec 4, 2025
CVE-2025-4643

Payload does not invalidate JWTs after log out

Published Aug 29, 2025
CVE-2026-33468

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

Published Mar 20, 2026
CVE-2021-21423MEDIUM

Rebuild-bot workflow may allow unauthorised repository modifications

Published Apr 6, 2021
CVE-2021-25916CRITICAL

Prototype pollution vulnerability in 'patchmerge'

Published Oct 13, 2021
MAL-2025-192473

Malicious code in elf-stats-candlelit-train-228 (npm)

Published Dec 11, 2025
MAL-2026-4866

Malicious code in @car-loans/deal (npm)

Published May 28, 2026
GHSA-g839-vp47-wgh8

Duplicate Advisory: OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingress

Published Mar 21, 2026
CVE-2025-48054

radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published May 27, 2025
CVE-2023-6460MEDIUM

Logging of the firestore key within nodejs-firestore

Published Dec 4, 2023
CVE-2026-26832

node-tesseract-ocr is vulnerable to OS Command Injection through unsanitized recognize() function parameter

Published Mar 25, 2026
MAL-2024-8370

Malicious code in @diotoborg/inventore-quasi (npm)

Published Sep 2, 2024
CVE-2026-1615

jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions

Published Feb 9, 2026
CVE-2016-10540HIGH

Regular Expression Denial of Service in minimatch

Published Oct 9, 2018
CVE-2022-2064HIGH

Insufficient Session Expiration in NocoDB

Published Jun 14, 2022
CVE-2016-10662HIGH

Downloads Resources over HTTP in tomita

Published Feb 18, 2019
MAL-2025-192539

Malicious code in elf-stats-twinkling-bell-867 (npm)

Published Dec 11, 2025
MAL-2025-192541

Malicious code in mui-wrapper-icons (npm)

Published Dec 11, 2025
CVE-2018-3732HIGH

Path Traversal in resolve-path

Published Jul 18, 2018
CVE-2025-62595

Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic

Published Oct 21, 2025
CVE-2016-4055MEDIUM

Regular Expression Denial of Service in moment

Published Oct 24, 2017
MAL-2025-192545

Malicious code in bfruitmaliciousxmlparser (npm)

Published Dec 12, 2025
MAL-2024-8380

Malicious code in @diotoborg/iste-laborum (npm)

Published Sep 2, 2024
MAL-2025-192567

Malicious code in uba-plugins (npm)

Published Dec 12, 2025
MAL-2026-4884

Malicious code in @cloudplatform-single-spa/agreements (npm)

Published May 28, 2026
MAL-2026-4885

Malicious code in @cloudplatform-single-spa/aifactory-notebooks (npm)

Published May 28, 2026
CVE-2020-28433HIGH

node-latex-pdf is susceptible to command injection

Published Aug 3, 2022
MAL-2024-8392

Malicious code in @diotoborg/labore-atque (npm)

Published Sep 2, 2024
MAL-2025-192620

Malicious code in android_teminator_x (npm)

Published Dec 19, 2025
CVE-2019-15479MEDIUM

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Published Sep 23, 2019
MAL-2026-4886

Malicious code in @cloudplatform-single-spa/airflow (npm)

Published May 28, 2026
GHSA-gcmm-c94j-j47x

@puchunjie/doc-tools-mcp has a Path Traversal Issue

Published May 4, 2026
MAL-2022-1098

Malicious code in arm-attestation (npm)

Published Jun 20, 2022
MAL-2022-1099

Malicious code in arm-azurestack (npm)

Published Jun 20, 2022
MAL-2025-192674

Malicious code in xnetgpt (npm)

Published Dec 19, 2025
CVE-2016-10520HIGH

Regular Expression Denial of Service in jadedown

Published Feb 18, 2019
MAL-2025-192682

Malicious code in @nosinovacao/nosid-mfe-common (npm)

Published Dec 20, 2025
CVE-2026-25752

FUXA Unauthenticated Remote Arbitrary Device Tag Write

Published Feb 5, 2026
MAL-2026-4898

Malicious code in @cloudplatform-single-spa/cnapp-ui (npm)

Published May 28, 2026
GHSA-89r3-6x4j-v7wf

OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection

Published Apr 2, 2026
GHSA-63f5-hhc7-cx6p

OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval

Published Mar 16, 2026
CVE-2022-21164LOW

Unhandled case in node-lmdb

Published Mar 17, 2022
GHSA-h97f-6pqj-q452

OpenClaw has a IPv6 multicast SSRF classifier bypass

Published Mar 3, 2026
MAL-2024-8406

Malicious code in @diotoborg/libero-ratione-delectus (npm)

Published Sep 2, 2024
MAL-2022-1850

Malicious code in cd-system (npm)

Published Jul 5, 2022
MAL-2026-4900

Malicious code in @cloudplatform-single-spa/corax (npm)

Published May 28, 2026
CVE-2026-22177

OpenClaw's config env vars allowed startup env injection into service runtime

Published Mar 3, 2026
MAL-2025-192709

Malicious code in amazon-testpackage (npm)

Published Dec 23, 2025
MAL-2025-192710

Malicious code in amournapraia (npm)

Published Dec 23, 2025
MAL-2026-4901

Malicious code in @cloudplatform-single-spa/cp-api-gw (npm)

Published May 28, 2026
MAL-2026-4902

Malicious code in @cloudplatform-single-spa/datagrid (npm)

Published May 28, 2026
CVE-2019-10795MEDIUM

Prototype Pollution in undefsafe

Published Feb 9, 2022
MAL-2022-1488

Malicious code in bdwngkairzovfpje (npm)

Published Jul 11, 2022
CVE-2015-5688MEDIUM

Directory Traversal in geddy

Published Oct 24, 2017
MAL-2024-8428

Malicious code in @diotoborg/molestiae-doloribus (npm)

Published Sep 2, 2024
MAL-2025-192740

Malicious code in elf-stats-caroling-wreath-635 (npm)

Published Dec 23, 2025
MAL-2024-8429

Malicious code in @diotoborg/molestiae-maxime (npm)

Published Sep 2, 2024
MAL-2025-192754

Malicious code in chai-max (npm)

Published Dec 23, 2025
MAL-2025-192771

Malicious code in elf-stats-glittering-cookie-844 (npm)

Published Dec 23, 2025
MAL-2026-4903

Malicious code in @cloudplatform-single-spa/dataplatform (npm)

Published May 28, 2026
MAL-2022-4158

Malicious code in kg_portal (npm)

Published Jun 20, 2022
MAL-2022-5248

Malicious code in paypay-ecommerce-miniapp (npm)

Published Jun 20, 2022
CVE-2025-31128

gifplayer XSS vulnerability

Published Mar 31, 2025
MAL-2025-192951

Malicious code in ugc-kit (npm)

Published Dec 27, 2025
GHSA-939r-rj45-g2rj

OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins

Published Apr 17, 2026
MAL-2026-4954

Malicious code in @cloudplatform-single-spa/observability (npm)

Published May 28, 2026
CVE-2015-8857CRITICAL

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

Published Oct 24, 2017
MAL-2025-192965

Malicious code in awsmcc (npm)

Published Dec 30, 2025
CVE-2026-29185

Backstage vulnerable to potential reading of SCM URLs using built in token

Published Mar 5, 2026
MAL-2022-4558

Malicious code in mepjow (npm)

Published Aug 19, 2022
CVE-2017-16072HIGH

nodemailer.js is malware

Published Aug 29, 2018
CVE-2017-16153HIGH

Directory Traversal in gaoxuyan

Published Sep 1, 2020
MAL-2024-8471

Malicious code in @diotoborg/nobis-facilis (npm)

Published Sep 2, 2024
CVE-2026-25047

deepHas vulnerable to Prototype Pollution via constructor.prototype

Published Jan 29, 2026
MAL-2025-2014

Malicious code in configs-web-react (npm)

Published Mar 3, 2025
CVE-2026-27609

Parse Dashboard is Missing CSRF Protection for its Agent Endpoint

Published Feb 25, 2026
CVE-2020-7725CRITICAL

Prototype Pollution in worksmith

Published May 6, 2021
CVE-2025-56200

validator.js has a URL validation bypass vulnerability in its isURL function

Published Sep 30, 2025
MAL-2025-2017

Malicious code in aws-features-signin-proxy-client (npm)

Published Mar 3, 2025
MAL-2024-8472

Malicious code in @diotoborg/nobis-mollitia (npm)

Published Sep 2, 2024
MAL-2026-4958

Malicious code in @cloudplatform-single-spa/paas-redis (npm)

Published May 28, 2026
MAL-2025-2035

Malicious code in console-node-ts (npm)

Published Mar 3, 2025
CVE-2021-25946CRITICAL

Prototype pollution in nconf-toml

Published Jun 7, 2021
MAL-2026-4967

Malicious code in @cloudplatform-single-spa/security-groups (npm)

Published May 28, 2026
MAL-2022-4562

Malicious code in merlin-products-fetch (npm)

Published Jun 20, 2022
MAL-2022-4563

Malicious code in merlin-ui (npm)

Published Jun 20, 2022
MAL-2022-4570

Malicious code in metalsapi-adapter (npm)

Published Jun 20, 2022
CVE-2023-30843HIGH

Hidden fields can be leaked on readable collections in Payload

Published Apr 26, 2023
MAL-2024-849

Malicious code in wlwz-2312-7504 (npm)

Published Jan 24, 2024
MAL-2025-2092

Malicious code in aws-ui-component-select (npm)

Published Mar 4, 2025
MAL-2026-4973

Malicious code in @cloudplatform-single-spa/static-page (npm)

Published May 28, 2026
MAL-2025-2230

Malicious code in pixelary (npm)

Published Mar 11, 2025
CVE-2017-16126MEDIUM

Tracking Module in botbait

Published Sep 1, 2020
MAL-2025-2264

Malicious code in linear-open-issue (npm)

Published Mar 11, 2025
CVE-2021-21306MEDIUM

Regular Expression Denial of Service (REDoS) in Marked

Published Feb 8, 2021
CVE-2021-39157HIGH

Improper Handling of Exceptional Conditions in detect-character-encoding

Published Aug 25, 2021
MAL-2026-4983

Malicious code in @cloudplatform-single-spa/svp-images (npm)

Published May 28, 2026
MAL-2024-85

Malicious code in tsb-authorization (npm)

Published Jan 12, 2024
CVE-2020-7683HIGH

Directory traversal in rollup-plugin-server

Published Jul 29, 2020
CVE-2024-21511CRITICAL

MySQL2 for Node Arbitrary Code Injection

Published Apr 23, 2024
MAL-2022-4817

Malicious code in newclick-components (npm)

Published Jun 20, 2022
MAL-2022-482

Malicious code in @openmage/fetlife-assets (npm)

Published Jun 20, 2022
MAL-2025-2696

Malicious code in ofjaaah-dependency-confusion (npm)

Published Mar 25, 2025
MAL-2026-4984

Malicious code in @cloudplatform-single-spa/svp-interfaces (npm)

Published May 28, 2026
CVE-2017-16065HIGH

openssl.js is malware

Published Aug 29, 2018
CVE-2021-46871MEDIUM

phoenix_html allows Cross-site Scripting in HEEx class attributes

Published Jan 10, 2023
MAL-2024-8503

Malicious code in @diotoborg/officiis-nam-dignissimos (npm)

Published Sep 2, 2024
MAL-2026-4985

Malicious code in @cloudplatform-single-spa/svp-lbaas (npm)

Published May 28, 2026
MAL-2025-3246

Malicious code in fatfingers-hello (npm)

Published Apr 17, 2025
MAL-2025-3247

Malicious code in fatfingers-helloo (npm)

Published Apr 17, 2025
MAL-2022-4828

Malicious code in nextcloud-js-tests (npm)

Published Jun 20, 2022
CVE-2018-14731HIGH

Missing Origin Validation in parcel-bundler

Published Oct 30, 2018
MAL-2024-8512

Malicious code in @diotoborg/optio-voluptatum (npm)

Published Sep 2, 2024
MAL-2025-3532

Malicious code in nsemea-core-poc (npm)

Published Apr 29, 2025
MAL-2026-4986

Malicious code in @cloudplatform-single-spa/svp-managed-kubernetes (npm)

Published May 28, 2026
CVE-2026-32033

OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths

Published Mar 3, 2026
MAL-2024-8515

Malicious code in @diotoborg/perferendis-odit (npm)

Published Sep 2, 2024
CVE-2025-30359

webpack-dev-server users' source code may be stolen when they access a malicious web site

Published Jun 4, 2025
MAL-2024-8523

Malicious code in @diotoborg/placeat-placeat (npm)

Published Sep 2, 2024
CVE-2024-29194HIGH

OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

Published Mar 25, 2024
MAL-2025-3618

Malicious code in cordova-plugin-permissions (npm)

Published May 6, 2025
MAL-2022-4969

Malicious code in nucleus-integration-banana (npm)

Published Jun 20, 2022
MAL-2026-5009

Malicious code in @fb-deposit/form-savings-account (npm)

Published May 28, 2026
CVE-2022-23080MEDIUM

Server-Side Request Forgery in Directus

Published Jun 23, 2022
MAL-2024-8541

Malicious code in @diotoborg/quaerat-dicta (npm)

Published Sep 2, 2024
MAL-2025-3974

Malicious code in wegenenverkeer (npm)

Published May 5, 2025
MAL-2025-4134

Malicious code in string-multiutils (npm)

Published May 21, 2025
CVE-2024-21908MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Oct 22, 2021
MAL-2022-5427

Malicious code in postcssmipot (npm)

Published Aug 19, 2022
MAL-2025-4464

Malicious code in airdrop-interface-markets (npm)

Published May 27, 2025
MAL-2022-544

Malicious code in @qw-app/images (npm)

Published Jun 20, 2022
CVE-2021-23341HIGH

Denial of service in prismjs

Published Mar 1, 2021
MAL-2026-5038

Malicious code in @t-in-one/form_product_token (npm)

Published May 29, 2026
MAL-2022-5453

Malicious code in preset-modules (npm)

Published Jun 20, 2022
MAL-2025-4493

Malicious code in nayan-videos-downloaders (npm)

Published May 27, 2025
CVE-2020-5251HIGH

Information disclosure in parse-server

Published Mar 4, 2020
MAL-2024-8576

Malicious code in @diotoborg/quo-dolorem-ducimus (npm)

Published Sep 2, 2024
MAL-2025-47866

Malicious code in zenith.svg-loader (npm)

Published Sep 26, 2025
CVE-2018-16487MEDIUM

Prototype Pollution in lodash

Published Feb 7, 2019
GHSA-hf68-49fm-59cq

OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

Published Mar 26, 2026
MAL-2026-5043

Malicious code in @t-in-one/prefill_transformers_data_token (npm)

Published May 29, 2026
MAL-2022-5460

Malicious code in prism-reactjs (npm)

Published Jun 20, 2022
MAL-2024-8583

Malicious code in @diotoborg/quos-accusantium (npm)

Published Sep 2, 2024
CVE-2019-5483MEDIUM

Sensitive Data Exposure in seneca

Published Sep 11, 2019
CVE-2022-29244HIGH

Packing does not respect root-level ignore files in workspaces

Published Jun 2, 2022
GHSA-52vj-fvrv-7q82

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

Published Apr 10, 2026
MAL-2024-8584

Malicious code in @diotoborg/quos-eos (npm)

Published Sep 2, 2024
CVE-2023-30541MEDIUM

OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated

Published Apr 17, 2023
MAL-2026-5044

Malicious code in @t-in-one/restore_application_hid_from_storage (npm)

Published May 29, 2026
MAL-2026-5045

Malicious code in @t-in-one/safe_local_storage_token (npm)

Published May 29, 2026
MAL-2025-47892

Malicious code in pycodestyle (npm)

Published Oct 2, 2025
MAL-2025-49356

Malicious code in aes-valid-ipherv (npm)

Published Nov 5, 2025
MAL-2025-5451

Malicious code in plonkscript-docs (npm)

Published Jun 18, 2025
MAL-2026-1515

Malicious code in developit (npm)

Published Mar 16, 2026
CVE-2016-10695HIGH

Downloads Resources over HTTP in npm-test-sqlite3-trunk

Published Sep 1, 2020
CVE-2016-10623HIGH

Downloads Resources over HTTP in macaca-chromedriver-zxa

Published Feb 18, 2019
MAL-2025-5973

Malicious code in web3js-wallet (npm)

Published Jul 15, 2025
MAL-2025-6186

Malicious code in nf-cons-log (npm)

Published Jul 22, 2025
MAL-2025-626

Malicious code in hardhat-configs (npm)

Published Jan 30, 2025
MAL-2025-6334

Malicious code in style-postprocessor (npm)

Published Jul 28, 2025
MAL-2025-6335

Malicious code in uidraftism (npm)

Published Jul 28, 2025
CVE-2024-29271MEDIUM

VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability

Published Mar 22, 2024
GHSA-6f7g-v4pp-r667

Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise

Published Apr 16, 2026
MAL-2026-1581

Malicious code in whatnot-events (npm)

Published Mar 19, 2026
MAL-2026-1679

Malicious code in chai-promised-async (npm)

Published Mar 18, 2026
MAL-2026-1690

Malicious code in chain-promised-cli (npm)

Published Mar 18, 2026
MAL-2026-2419

Malicious code in express-session-js (npm)

Published Apr 2, 2026
MAL-2026-2420

Malicious code in @_wnpm/wnpm-cli (npm)

Published Apr 2, 2026
MAL-2022-5461

Malicious code in privacy-test-pages (npm)

Published Jun 20, 2022
MAL-2026-5046

Malicious code in @t-in-one/send_add_application (npm)

Published May 29, 2026
CVE-2020-28280CRITICAL

Prototype pollution vulnerability in 'predefine'

Published Oct 12, 2021
MAL-2026-5047

Malicious code in @cplace-paw-fe/cf-training-extended (npm)

Published May 29, 2026
MAL-2022-5464

Malicious code in privateinternal-a (npm)

Published Jun 20, 2022
CVE-2026-26316

OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust

Published Feb 17, 2026
MAL-2026-2709

Malicious code in @appleseed-apple/ac-sass-kit (npm)

Published Apr 16, 2026
MAL-2026-2905

Malicious code in simple-auth-basic (npm)

Published Apr 15, 2026
CVE-2021-37916MEDIUM

Joplin vulnerable to Cross-site Scripting in notes

Published May 24, 2022
MAL-2026-2914

Malicious code in modern-events (npm)

Published Apr 16, 2026
MAL-2026-2915

Malicious code in bitu-staking (npm)

Published Apr 12, 2026
MAL-2022-5476

Malicious code in progressbrwepbackplugin (npm)

Published Aug 19, 2022
MAL-2026-5050

Malicious code in @rsi-community/hub-client-app (npm)

Published May 29, 2026
CVE-2022-0087MEDIUM

Reflected cross-site scripting (XSS) vulnerability

Published Jan 12, 2022
GHSA-hv93-r4j3-q65f

OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing

Published Feb 17, 2026
MAL-2022-5532

Malicious code in purview-scanning (npm)

Published Jun 20, 2022
MAL-2026-5051

Malicious code in @tc-core/provider-service (npm)

Published May 29, 2026
MAL-2026-5052

Malicious code in @timelycare/api (npm)

Published May 29, 2026
MAL-2022-5538

Malicious code in qdjoxcrmsvaynikk (npm)

Published Jul 11, 2022
GHSA-8783-3wgf-jggf

Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints

Published Apr 16, 2026
MAL-2026-2987

Malicious code in @bmg-web/bmg-external-link (npm)

Published Apr 22, 2026
MAL-2026-2988

Malicious code in @bmg-web/bmg-grid (npm)

Published Apr 22, 2026
CVE-2026-28792

TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

Published Mar 12, 2026
MAL-2026-2989

Malicious code in @bmg-web-features/bmg-user-interaction-tracker (npm)

Published Apr 22, 2026
MAL-2026-2990

Malicious code in etsyapp (npm)

Published Apr 22, 2026
MAL-2026-5058

Malicious code in argpras (npm)

Published May 29, 2026
MAL-2022-5622

Malicious code in rdocumentation-workers (npm)

Published Oct 31, 2022
CVE-2017-16203HIGH

coffe-script is malware

Published Aug 6, 2018
MAL-2026-5059

Malicious code in chai-bundle (npm)

Published May 29, 2026
CVE-2025-12735

expr-eval does not restrict functions passed to the evaluate function

Published Nov 5, 2025
CVE-2023-26159HIGH

Follow Redirects improperly handles URLs in the url.parse() function

Published Jan 2, 2024
MAL-2026-5060

Malicious code in chai-extensions-extras (npm)

Published May 29, 2026
CVE-2025-53364

Parse Server exposes the data schema via GraphQL API

Published Jul 10, 2025
CVE-2025-61917

n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

Published Feb 4, 2026
MAL-2026-3004

Malicious code in @nklkas/hyperliquid (npm)

Published Apr 23, 2026
MAL-2026-3005

Malicious code in changelog-cli-logger (npm)

Published Apr 23, 2026
MAL-2026-3006

Malicious code in changelog-utils-structured-logger (npm)

Published Apr 23, 2026
CVE-2023-28443MEDIUM

directus vulnerable to Insertion of Sensitive Information into Log File

Published Mar 23, 2023
CVE-2022-0639MEDIUM

url-parse Incorrectly parses URLs that include an '@'

Published Feb 18, 2022
CVE-2017-16190HIGH

Directory Traversal in dcdcdcdcdc

Published Sep 1, 2020
MAL-2026-5061

Malicious code in chai-use-test (npm)

Published May 29, 2026
MAL-2026-5062

Malicious code in codex-devcontainer-install (npm)

Published May 29, 2026
MAL-2026-3010

Malicious code in separadordeinfocc (npm)

Published Apr 23, 2026
MAL-2026-888

Malicious code in pyright-root (npm)

Published Feb 13, 2026
MAL-2026-5063

Malicious code in customerdigital-service-lib (npm)

Published May 29, 2026
MAL-2022-5623

Malicious code in rdtkfuhjacoezmwn (npm)

Published Jul 11, 2022
MAL-2022-5631

Malicious code in react-address-entry-field (npm)

Published Jun 20, 2022
MAL-2026-5064

Malicious code in ethers-contract (npm)

Published May 29, 2026
MAL-2026-5065

Malicious code in ethers-errors (npm)

Published May 29, 2026
MAL-2022-5632

Malicious code in react-bank-api (npm)

Published Jul 5, 2022
CVE-2026-22176

OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 3, 2026
CVE-2016-10576HIGH

fuseki downloads Resources over HTTP

Published Feb 18, 2019
MAL-2026-5066

Malicious code in ethers-hash (npm)

Published May 29, 2026
CVE-2018-16486CRITICAL

Prototype Pollution in defaults-deep

Published Feb 7, 2019
CVE-2016-10703HIGH

Denial of Service in ecstatic

Published Dec 28, 2017
MAL-2022-1499

Malicious code in ben1 (npm)

Published Jul 8, 2022
CVE-2020-7684HIGH

Path traversal in rollup-plugin-serve

Published May 18, 2021
GHSA-4jpw-hj22-2xmc

OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE

Published Mar 13, 2026
MAL-2024-8542

Malicious code in @diotoborg/quaerat-eius (npm)

Published Sep 2, 2024
MAL-2026-5067

Malicious code in ethers-hdnode (npm)

Published May 29, 2026
MAL-2025-192249

Malicious code in elf-stats-shimmering-muffin-598 (npm)

Published Dec 3, 2025
MAL-2026-5068

Malicious code in evmchain-cli (npm)

Published May 29, 2026
GHSA-jh3h-rpxg-fr36

Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover

Published May 19, 2026
GHSA-c276-fj82-f2pq

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Published Apr 16, 2026
CVE-2026-33671

Picomatch has a ReDoS vulnerability via extglob quantifiers

Published Mar 25, 2026
MAL-2026-5070

Malicious code in foundry-config (npm)

Published May 29, 2026
MAL-2022-5634

Malicious code in react-cionx (npm)

Published Aug 19, 2022
MAL-2022-5640

Malicious code in react-dnd-examples-hooks (npm)

Published Jun 20, 2022
MAL-2022-5641

Malicious code in react-dom-is (npm)

Published Jun 20, 2022
CVE-2026-27970

Angular i18n vulnerable to Cross-Site Scripting

Published Feb 27, 2026
MAL-2026-5074

Malicious code in one-view-chat-ui-module (npm)

Published May 29, 2026
CVE-2016-10536MEDIUM

Insecure Defaults Allow MITM Over TLS in engine.io-client

Published Feb 18, 2019
MAL-2022-5642

Malicious code in react-dom-router-compatibility (npm)

Published May 31, 2022
GHSA-vp62-r36r-9xqp

Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace

Published Apr 21, 2026
MAL-2022-6621

Malicious code in tracker-radar (npm)

Published Jun 20, 2022
CVE-2025-22150

Use of Insufficiently Random Values in undici

Published Jan 21, 2025
CVE-2015-9235CRITICAL

Verification Bypass in jsonwebtoken

Published Oct 9, 2018
MAL-2022-663

Malicious code in @tinyspeck/calls-desktop-interop (npm)

Published Jun 20, 2022
MAL-2022-6633

Malicious code in training-kit (npm)

Published Jun 20, 2022
MAL-2022-6634

Malicious code in training-platform-web (npm)

Published Jun 20, 2022
MAL-2022-6635

Malicious code in tranchess-core (npm)

Published Jul 18, 2022
CVE-2026-24125

@tinacms/graphql has a Path Traversal issue

Published Mar 12, 2026
CVE-2026-33896CRITICAL
Risk: 88/100

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Published Mar 26, 2026
CVE-2021-40823MEDIUM

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

Published Sep 14, 2021
CVE-2026-31862

@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters

Published Mar 11, 2026
CVE-2021-23369MEDIUM

Remote code execution in handlebars when compiling templates

Published May 6, 2021
CVE-2022-25645MEDIUM

Prototype Pollution in dset

Published May 3, 2022
MAL-2022-5697

Malicious code in reactrdeux (npm)

Published Aug 19, 2022
CVE-2024-56159

Astro's server source code is exposed to the public if sourcemaps are enabled

Published Dec 19, 2024
MAL-2022-5699

Malicious code in reacttapefentplugin (npm)

Published Aug 19, 2022
MAL-2026-5080

Malicious code in tailwind-clamps-line (npm)

Published May 29, 2026
MAL-2026-5081

Malicious code in tailwind-effect (npm)

Published May 29, 2026
MAL-2026-5082

Malicious code in tailwind-smooth-slider (npm)

Published May 29, 2026
MAL-2022-5701

Malicious code in read.node (npm)

Published Dec 7, 2022
MAL-2022-5707

Malicious code in realtime-react (npm)

Published Jun 20, 2022
MAL-2022-5708

Malicious code in realtime-react-ui (npm)

Published Jun 20, 2022
CVE-2023-38507HIGH

Strapi Improper Rate Limiting vulnerability

Published Sep 13, 2023
CVE-2021-27524MEDIUM

Margox Braft-Editor Cross-site Scripting Vulnerability

Published Aug 11, 2023
MAL-2026-5085

Malicious code in web3-config-loader (npm)

Published May 29, 2026
CVE-2021-23359HIGH

Code injection in port-killer

Published Apr 13, 2021
CVE-2021-23398MEDIUM

Cross-site scripting in react-bootstrap-table

Published Dec 10, 2021
CVE-2019-10749CRITICAL

SQL Injection in sequelize

Published Nov 8, 2019
MAL-2022-5709

Malicious code in reamd (npm)

Published Aug 19, 2022
MAL-2022-5720

Malicious code in reddit-client-lib (npm)

Published Jun 20, 2022
MAL-2022-5721

Malicious code in redirect-safe (npm)

Published Oct 20, 2022
MAL-2022-5730

Malicious code in reflect_decorators (npm)

Published Jun 20, 2022
MAL-2022-578

Malicious code in @seller-center/grace (npm)

Published Jun 20, 2022
MAL-2022-5786

Malicious code in richdocuments (npm)

Published Jun 20, 2022
MAL-2022-5787

Malicious code in richmediacore (npm)

Published Jun 20, 2022
CVE-2026-4923

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Published Mar 27, 2026
GHSA-gwhp-pf74-vj37

Fastify's connection header abuse enables stripping of proxy-added headers

Published Apr 16, 2026
CVE-2024-43796MEDIUM

express vulnerable to XSS via response.redirect()

Published Sep 10, 2024
CVE-2025-70948

@perfood/couch-auth has a host header injection vulnerability

Published Mar 5, 2026
CVE-2016-10680HIGH

Downloads Resources over HTTP in adamvr-geoip-lite

Published Sep 1, 2020
GHSA-pcw7-5633-82vv

Strapi Upload Plugin MIME Validation Bypass via Content API

Published May 14, 2026
CVE-2026-3089

Actual Sync Server has an Authenticated Path Traversal

Published Mar 10, 2026
GHSA-28g4-38q8-3cwc

Flowise: Cypher Injection in GraphCypherQAChain

Published Apr 16, 2026
MAL-2026-955

Malicious code in crypto-locale (npm)

Published Feb 20, 2026
CVE-2024-57189

Erxes Path Traversal vulnerability

Published Jun 10, 2025
MAL-2022-5824

Malicious code in rn-amazon-payment-service (npm)

Published Sep 26, 2022
MAL-2022-5833

Malicious code in roblox-es6-migration-helper (npm)

Published Jun 20, 2022
CVE-2019-9154HIGH

Improper Key Verification in openpgp

Published Aug 23, 2019
CVE-2026-28395

OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback

Published Feb 17, 2026
CVE-2020-28500MEDIUM

Regular Expression Denial of Service (ReDoS) in lodash

Published Jan 6, 2022
CVE-2020-7677HIGH

thenify before 3.3.1 made use of unsafe calls to `eval`.

Published Jul 18, 2022
CVE-2023-25653HIGH

Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)

Published Feb 16, 2023
CVE-2017-16034

Command Injection in pidusage

Published Sep 1, 2020
MAL-2022-5835

Malicious code in rocket-league-credits-hakc-2022 (npm)

Published Jun 20, 2022
MAL-2022-5856

Malicious code in rsk-devportal (npm)

Published Jul 21, 2022
MAL-2022-5882

Malicious code in rxp-js (npm)

Published Jun 20, 2022
MAL-2022-5886

Malicious code in ryjqvlxozpdcubta (npm)

Published Jul 11, 2022
MAL-2022-5887

Malicious code in rysewnplkutazmfc (npm)

Published Jul 11, 2022
MAL-2022-5965

Malicious code in scilla (npm)

Published Jun 8, 2022
GHSA-2858-xg23-26fp

OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots

Published Mar 3, 2026
CVE-2020-28426HIGH

Command injection in kill-process-on-port

Published Mar 19, 2021
MAL-2025-192725

Malicious code in chai-pack (npm)

Published Dec 23, 2025
CVE-2017-16163HIGH

Directory Traversal in dylmomo

Published Sep 1, 2020
CVE-2021-23384MEDIUM

Open Redirect in koa-remove-trailing-slashes

Published Feb 10, 2022
MAL-2026-1027

Malicious code in rtxbbtyols (npm)

Published Feb 24, 2026
MAL-2024-8626

Malicious code in @diotoborg/sed-tempora-natus (npm)

Published Sep 2, 2024
MAL-2024-8627

Malicious code in @diotoborg/sed-veniam-cupiditate (npm)

Published Sep 2, 2024
CVE-2023-23936MEDIUM

CRLF Injection in Nodejs ‘undici’ via host

Published Feb 16, 2023
CVE-2026-30962

Parse Server has a protected fields bypass via logical query operators

Published Mar 11, 2026
CVE-2020-28450HIGH

Prototype Pollution in decal

Published Apr 13, 2021
CVE-2026-28793

TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete

Published Mar 12, 2026
MAL-2022-5966

Malicious code in scilla-server (npm)

Published Jun 8, 2022
MAL-2022-5967

Malicious code in scopely-mopub-aacebookaudiencenetwork-adapters (npm)

Published Jun 20, 2022
CVE-2022-31069MEDIUM

Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
CVE-2024-27296MEDIUM

Directus version number disclosure

Published Mar 1, 2024
MAL-2022-1059

Malicious code in apollocli8ent (npm)

Published Aug 19, 2022
CVE-2026-1664

Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing

Published Feb 3, 2026
GHSA-m866-6qv5-p2fg

OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Published Mar 31, 2026
GHSA-rf75-g96h-j3rm

Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 2, 2026
MAL-2022-106

Malicious code in @azure-tests/perf-keyvault-secrets (npm)

Published Jun 20, 2022
MAL-2024-8646

Malicious code in @diotoborg/suscipit-officia (npm)

Published Sep 2, 2024
MAL-2022-5970

Malicious code in script-package (npm)

Published Jul 6, 2022
MAL-2022-6103

Malicious code in shopify-marketplaces-buyer-app (npm)

Published Jun 20, 2022
GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

Published Apr 6, 2026
MAL-2024-8647

Malicious code in @diotoborg/suscipit-vitae (npm)

Published Sep 2, 2024
MAL-2022-7077

Malicious code in web-stories-renderer (npm)

Published Jul 21, 2022
MAL-2022-7078

Malicious code in web-stories-wp (npm)

Published Jun 20, 2022
MAL-2022-1060

Malicious code in apollolinhttp (npm)

Published Aug 19, 2022
MAL-2024-8658

Malicious code in @diotoborg/temporibus-quasi-quasi (npm)

Published Sep 2, 2024
CVE-2025-69873

ajv has ReDoS when using `$data` option

Published Feb 11, 2026
CVE-2016-10626HIGH

Downloads Resources over HTTP in mystem3

Published Feb 18, 2019
GHSA-r849-826x-wgqm

Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 19, 2026
CVE-2025-54798

tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

Published Aug 6, 2025
MAL-2022-6130

Malicious code in singhaditi2707 (npm)

Published Jun 20, 2022
CVE-2026-32055

OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 12, 2026
MAL-2022-6132

Malicious code in sint-plugin-prkomise (npm)

Published Aug 19, 2022
CVE-2026-21852

Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

Published Jan 21, 2026
CVE-2021-26700HIGH

Remote code execution in vscode-npm-script

Published May 24, 2022
MAL-2024-8674

Malicious code in @diotoborg/velit-placeat (npm)

Published Sep 2, 2024
CVE-2022-21670MEDIUM

Uncontrolled Resource Consumption in markdown-it

Published Jan 12, 2022
GHSA-mhr7-2xmv-4c4q

OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode

Published Apr 3, 2026
GHSA-2h6j-mhcp-9j9h

GenieACS has an unauthenticated access vulnerability via the NBI API endpoint

Published Apr 7, 2026
MAL-2022-6163

Malicious code in slg-shared-utils (npm)

Published Jun 22, 2022
CVE-2025-57329

web3-core-method is vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2026-28482

OpenClaw's unsanitized session ID enables path traversal in transcript file operations

Published Feb 18, 2026
MAL-2022-6164

Malicious code in slg-vue-components (npm)

Published Jun 22, 2022
MAL-2022-617

Malicious code in @sugoma/amogus (npm)

Published Jun 20, 2022
CVE-2017-16039HIGH

Directory Traversal in hftp

Published Jul 24, 2018
CVE-2023-27564HIGH

n8n Information Disclosure vulnerability

Published May 10, 2023
MAL-2022-1065

Malicious code in app.1inch.io (npm)

Published Jul 25, 2022
MAL-2024-870

Malicious code in wlwz-2312-7707 (npm)

Published Jan 24, 2024
MAL-2022-6170

Malicious code in small-ms (npm)

Published Jul 8, 2022
CVE-2021-21413HIGH

Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate

Published Apr 6, 2021
CVE-2017-16118HIGH

Regular Expression Denial of Service in forwarded

Published Jul 24, 2018
MAL-2022-6175

Malicious code in smartsuite-ui (npm)

Published Jun 20, 2022
CVE-2015-9545HIGH

Improper Input Validation in xdLocalStorage

Published Dec 9, 2021
CVE-2022-21144HIGH

Denial of service vulnerability exists in libxmljs

Published May 3, 2022
CVE-2020-28470HIGH

Cross-site Scripting (XSS) in @scullyio/scully

Published Apr 13, 2021
CVE-2023-31133HIGH

Ghost vulnerable to information disclosure of private API fields

Published May 3, 2023
MAL-2022-6178

Malicious code in smfjcvkwqbigrpkt (npm)

Published Jul 11, 2022
MAL-2022-6179

Malicious code in smithy-client (npm)

Published Jun 20, 2022
MAL-2022-6180

Malicious code in smithy-typescript (npm)

Published Jun 20, 2022
CVE-2017-16222MEDIUM

Directory Traversal in elding

Published Aug 6, 2018
MAL-2024-8719

Malicious code in muthu (npm)

Published Sep 3, 2024
CVE-2022-35143CRITICAL

Raneto v0.17.0 employs weak password complexity requirements

Published Aug 5, 2022
CVE-2022-41957HIGH

muhammara and hummus vulnerable to Unchecked Return Value to NULL Pointer Dereference

Published Dec 5, 2022
CVE-2025-56572

Finance.js vulnerable to DoS via the seekZero() parameter

Published Sep 30, 2025
CVE-2023-42282CRITICAL

NPM IP package incorrectly identifies some private IP addresses as public

Published Feb 8, 2024
CVE-2021-23562MEDIUM

Code injection in plupload

Published Dec 16, 2021
MAL-2022-6183

Malicious code in sn-par-select (npm)

Published Sep 26, 2022
CVE-2024-41818HIGH

fast-xml-parser vulnerable to ReDOS at currency parsing

Published Jul 29, 2024
CVE-2020-4045HIGH

Information disclosure in SSB-DB

Published Jun 11, 2020
MAL-2022-6184

Malicious code in sn-seismic-addons (npm)

Published Jun 20, 2022
MAL-2022-6217

Malicious code in sorareshshsjs (npm)

Published Jun 8, 2022
MAL-2022-622

Malicious code in @tampmd/bth-react-components (npm)

Published Jun 20, 2022
CVE-2019-18608HIGH

Cezerin Unauthorized Acces

Published May 24, 2022
CVE-2018-7651MEDIUM

Regular Expression Denial of Service in ssri

Published Mar 7, 2018
GHSA-mqpr-49jj-32rc

n8n: Webhook Forgery on Github Webhook Trigger

Published Feb 26, 2026
CVE-2026-33768

Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

Published Mar 26, 2026
CVE-2020-1914CRITICAL

Always-Incorrect Control Flow Implementation in Facebook Hermes

Published May 24, 2022
CVE-2018-1000620CRITICAL

Insufficient Entropy in cryptiles

Published Sep 11, 2018
MAL-2022-1492

Malicious code in bebekair (npm)

Published Jun 9, 2022
CVE-2026-22028

Preact has JSON VNode Injection issue

Published Jan 7, 2026
MAL-2024-8819

Malicious code in 0g-storage-contracts (npm)

Published Sep 5, 2024
CVE-2021-29491

Use of Potentially Dangerous Function in mixme

Published May 6, 2021
CVE-2021-34078HIGH

OS Command Injection in lifion-verify-deps

Published Jun 3, 2022
MAL-2022-6220

Malicious code in sourcekit-lsp (npm)

Published Jun 20, 2022
CVE-2017-16078HIGH

Shadowsock is malware

Published Aug 27, 2018
MAL-2022-6221

Malicious code in sovryn-node-integration-tests (npm)

Published Jun 20, 2022
MAL-2022-6222

Malicious code in soydata (npm)

Published Jun 20, 2022
MAL-2022-6223

Malicious code in sp-bootstrap (npm)

Published Jun 13, 2022
GHSA-mvv8-v4jj-g47j

Directus: Sensitive fields exposed in revision history

Published Apr 4, 2026
CVE-2026-25128

fast-xml-parser has RangeError DoS Numeric Entities Bug

Published Jan 30, 2026
CVE-2017-16061HIGH

tkinter is malware

Published Nov 1, 2018
MAL-2024-8822

Malicious code in tappp-tv-ui-lib (npm)

Published Sep 5, 2024
CVE-2026-33979

Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk)

Published Mar 27, 2026
MAL-2022-6228

Malicious code in sparhandy-speedtest (npm)

Published Jul 21, 2022
MAL-2022-6244

Malicious code in sportsdataio-adapter (npm)

Published Jun 20, 2022
CVE-2026-30947

Parse Server has a bypass of class-level permissions in LiveQuery

Published Mar 11, 2026
CVE-2017-16024MEDIUM

Tmp files readable by other users in sync-exec

Published Nov 9, 2018
CVE-2018-3731HIGH

Path Traversal in public

Published Jul 18, 2018
GHSA-pjwm-pj3p-43mv

axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

Published May 29, 2026
MAL-2022-3324

Malicious code in gemini-adapter (npm)

Published Jun 20, 2022
MAL-2022-6006

Malicious code in seller-listing-service (npm)

Published Nov 9, 2022
CVE-2023-2850MEDIUM

Unintentional leakage of private information via cross-origin websocket session hijacking

Published Jul 25, 2023
GHSA-r7p2-r9g4-4xph

Duplicate Advisory: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients

Published Apr 24, 2026
MAL-2022-756

Malicious code in @xvideos/client-api (npm)

Published Jun 20, 2022
MAL-2024-12173

Malicious code in solaraexecutor (npm)

Published Dec 31, 2024
MAL-2024-8867

Malicious code in node-integration-test (npm)

Published Sep 11, 2024
MAL-2022-6250

Malicious code in spotify-debouncer (npm)

Published Jun 20, 2022
MAL-2022-6253

Malicious code in spotify-event-definitions (npm)

Published Jun 20, 2022
CVE-2016-1000238

Spoofing attack due to unvalidated KDC in node-krb5

Published Sep 1, 2020
CVE-2025-68157

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

Published Feb 5, 2026
CVE-2024-36361MEDIUM

Pug allows JavaScript code execution if an application accepts untrusted input

Published May 24, 2024
MAL-2025-1120

Malicious code in facebook-pixel-for-wordpress (npm)

Published Feb 3, 2025
CVE-2022-23623HIGH

Validation bypass in frourio

Published Feb 7, 2022
MAL-2024-3800

Malicious code in usaa-a11y-test (npm)

Published Jun 25, 2024
MAL-2024-882

Malicious code in wlwz-2312-7901 (npm)

Published Jan 24, 2024
GHSA-72c6-fx6q-fr5w

@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

Published Apr 16, 2026
CVE-2017-16224MEDIUM

Open Redirect in st

Published Aug 6, 2018
MAL-2022-626

Malicious code in @tekion/alpha (npm)

Published Jun 20, 2022
MAL-2022-6260

Malicious code in spotify-playback (npm)

Published Jun 20, 2022
MAL-2025-1677

Malicious code in pages14.0.0_i18n (npm)

Published Mar 3, 2025
MAL-2022-628

Malicious code in @tekion/fxt (npm)

Published Jun 20, 2022
MAL-2022-1068

Malicious code in app_intelligence (npm)

Published Jun 20, 2022
MAL-2022-6283

Malicious code in ssnap-web (npm)

Published Jun 20, 2022
MAL-2026-1135

Malicious code in yuji-baileys (npm)

Published Mar 2, 2026
CVE-2025-57320

json-schema-editor-visual vulnerable to prototype pollution

Published Sep 24, 2025
MAL-2026-4415

Malicious code in @onerjs/smart-filters-blocks (npm)

Published May 23, 2026
MAL-2026-4843

Malicious code in @polka-ui/loads (npm)

Published May 28, 2026
MAL-2026-4875

Malicious code in @car-loans/online-sign-aff (npm)

Published May 28, 2026
CVE-2022-24717MEDIUM

Cross Site Scripting (XSS) in @finastra/ssr-pages

Published Mar 1, 2022
CVE-2022-37257CRITICAL

steal vulnerable to Prototype Pollution via requestedVersion variable

Published Sep 16, 2022
CVE-2025-25977

canvg Prototype Pollution vulnerability

Published Mar 10, 2025
MAL-2026-5164

Malicious code in @emcd-vue/b2b-pay-form (npm)

Published Jun 1, 2026
MAL-2024-8943

Malicious code in ml-translate-vis (npm)

Published Sep 22, 2024
MAL-2022-6284

Malicious code in sso-ebay (npm)

Published Sep 14, 2022
MAL-2022-6285

Malicious code in ssomicroservicefrontend (npm)

Published Sep 13, 2022
CVE-2026-0540

DOMPurify contains a Cross-site Scripting vulnerability

Published Mar 3, 2026
CVE-2019-10804CRITICAL

OS Command Injection in serial-number

Published Apr 13, 2021
MAL-2022-6299

Malicious code in state.aggregator (npm)

Published Jun 20, 2022
CVE-2025-27109

Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)

Published Feb 25, 2025
MAL-2026-5166

Malicious code in sourceflow-tracker (npm)

Published Jun 2, 2026
MAL-2026-5168

Malicious code in vg-interaction-model (npm)

Published Jun 2, 2026
CVE-2020-8215HIGH

Buffer overflow in canvas

Published May 7, 2021
MAL-2022-63

Malicious code in @aia-digital/request-module (npm)

Published Jun 20, 2022
MAL-2022-6301

Malicious code in statusim-mobile (npm)

Published Jun 20, 2022
MAL-2022-6303

Malicious code in steamdb-browser-extension (npm)

Published Jun 20, 2022
CVE-2025-61686

React Router has Path Traversal in File Session Storage

Published Jan 8, 2026
CVE-2020-15156MEDIUM

XSS due to lack of CSRF validation for replying/publishing

Published Aug 26, 2020
CVE-2014-8883

Directory Traversal in nhouston

Published Aug 31, 2020
CVE-2021-23434MEDIUM

Prototype Pollution in object-path

Published Sep 1, 2021
MAL-2024-9006

Malicious code in inclusive-ai-dao-website (npm)

Published Sep 27, 2024
CVE-2025-57164

FlowiseAI Pre-Auth Arbitrary Code Execution

Published Sep 15, 2025
CVE-2024-57066

@ndhoule/defaults prototype pollution

Published Feb 6, 2025
MAL-2026-5179

Malicious code in chai-midpatch (npm)

Published Jun 3, 2026
MAL-2022-6308

Malicious code in stnylelint-config-tandrad (npm)

Published Aug 19, 2022
MAL-2022-6309

Malicious code in storage-blob-changefeed (npm)

Published Jun 20, 2022
MAL-2022-6316

Malicious code in storageblob (npm)

Published Jun 20, 2022
CVE-2026-27203

eBay API MCP Server Affected by Environment Variable Injection

Published Feb 19, 2026
CVE-2022-36077HIGH

Exfiltration of hashed SMB credentials on Windows via file:// redirect

Published Nov 10, 2022
CVE-2025-59057

React Router has XSS Vulnerability

Published Jan 8, 2026
MAL-2024-9050

Malicious code in hedgedoc-api (npm)

Published Sep 30, 2024
MAL-2022-6318

Malicious code in stories-carousel (npm)

Published Jun 20, 2022
CVE-2023-34245HIGH

@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme

Published Jun 9, 2023
MAL-2022-6323

Malicious code in streamer-market-dashboard (npm)

Published Jun 20, 2022
CVE-2022-31150MEDIUM

undici before v5.8.0 vulnerable to CRLF injection in request headers

Published Jul 21, 2022
GHSA-4c3q-x735-j3r5

Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

Published Apr 17, 2026
CVE-2022-29823CRITICAL

Feather-Sequelize cleanQuery method vulnerable to Prototype Pollution

Published Oct 26, 2022
CVE-2024-34708MEDIUM

Directus allows redacted data extraction on the API through "alias"

Published May 13, 2024
CVE-2020-7626CRITICAL

karma-mojo enables OS Command Injection

Published Feb 10, 2022
CVE-2020-7779MEDIUM

Regular Expression Denial of Service in djvalidator

Published Feb 9, 2022
CVE-2017-16053HIGH

fabric-js is malware

Published Jul 23, 2018
MAL-2024-9090

Malicious code in hilla-components-dependencies (npm)

Published Oct 4, 2024
CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
MAL-2022-6324

Malicious code in stressfault (npm)

Published Jun 20, 2022
MAL-2022-6331

Malicious code in stripe-demo-connect-standard-saas-platform (npm)

Published Jul 25, 2022
CVE-2025-69264

pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

Published Jan 7, 2026
CVE-2022-24433HIGH

Command injection in simple-git

Published Mar 12, 2022
MAL-2022-107

Malicious code in @azure-tests/perf-monitor-query (npm)

Published Jun 20, 2022
MAL-2024-9118

Malicious code in 29ge1l (npm)

Published Oct 9, 2024
CVE-2025-59536

Claude Code can execute commands prior to the startup trust dialog

Published Oct 3, 2025
CVE-2026-28486

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

Published Mar 2, 2026
CVE-2022-2216CRITICAL

Server-Side Request Forgery in parse-url

Published Jun 28, 2022
CVE-2016-1000226

Cross-Site Scripting in swagger-ui

Published Sep 1, 2020
MAL-2022-6340

Malicious code in stylelint-config-monorepo-palantir (npm)

Published Jun 20, 2022
MAL-2022-6342

Malicious code in stylis-ifl4 (npm)

Published Jun 2, 2022
MAL-2022-4659

Malicious code in mock-solc-0.6 (npm)

Published Jun 8, 2022
MAL-2024-11088

Malicious code in seller-webchat-service (npm)

Published Nov 27, 2024
CVE-2022-31367HIGH

Strapi mishandles hidden attributes within admin API responses

Published Sep 28, 2022
GHSA-p77w-8qqv-26rm

Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage

Published May 9, 2026
MAL-2022-6343

Malicious code in stylleint (npm)

Published Aug 19, 2022
MAL-2022-6344

Malicious code in subek (npm)

Published Jun 13, 2022
MAL-2022-6345

Malicious code in subscriptionid-apiversion (npm)

Published Jun 20, 2022
CVE-2025-54073

mcp-package-docs vulnerable to command injection in several tools

Published Aug 5, 2025
GHSA-3fv3-6p2v-gxwj

OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths

Published Apr 9, 2026
CVE-2026-28446

OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)

Published Feb 17, 2026
CVE-2024-47529

OpenC3 stores passwords in clear text (`GHSL-2024-129`)

Published Oct 2, 2024
CVE-2024-53983

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

Published Dec 2, 2024
MAL-2022-3611

Malicious code in here_base (npm)

Published Jun 20, 2022
MAL-2022-6346

Malicious code in suer (npm)

Published Aug 19, 2022
MAL-2025-4337

Malicious code in e-learning-garena (npm)

Published May 23, 2025
MAL-2022-6347

Malicious code in suggests (npm)

Published Jun 20, 2022
MAL-2022-6348

Malicious code in suhallowexqual (npm)

Published Aug 19, 2022
CVE-2025-56515

Fiora chat group avatar is vulnerable to XSS via SVG files

Published Oct 1, 2025
CVE-2023-35931LOW

Shescape potential environment variable exposure on Windows with CMD

Published Jun 22, 2023
CVE-2026-25547

@isaacs/brace-expansion has Uncontrolled Resource Consumption

Published Feb 3, 2026
CVE-2025-69211

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

Published Dec 30, 2025
CVE-2024-38987MEDIUM

@aofl/cli-lib Prototype Pollution vulnerability

Published Jul 1, 2024
MAL-2024-9169

Malicious code in new-code-script-gt-a-samp-h-a-c-k-down-lo-ad-lkk02y (npm)

Published Oct 9, 2024
CVE-2026-26319

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Published Feb 17, 2026
CVE-2026-30921

OneUptime: Synthetic Monitor RCE via exposed Playwright browser object

Published Mar 7, 2026
GHSA-p7mm-r948-4q3q

Paperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server

Published Apr 16, 2026
CVE-2024-31217MEDIUM

@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling

Published Jun 12, 2024
CVE-2020-24939HIGH

Prototype pollution in supermixer

Published Dec 10, 2021
MAL-2022-6349

Malicious code in suorce-map (npm)

Published Aug 19, 2022
MAL-2025-3140

Malicious code in ac-async-helpers (npm)

Published Apr 7, 2025
MAL-2025-47058

Malicious code in epxressoo (npm)

Published Sep 11, 2025
MAL-2022-635

Malicious code in @texashealth/fetlife-assets (npm)

Published Jun 20, 2022
CVE-2020-19850MEDIUM

Directus API vulnerable to denial of service

Published Apr 4, 2023
CVE-2026-33713

n8n has SQL Injection in Data Table Node via orderByColumn Expression

Published Mar 26, 2026
CVE-2025-62410

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

Published Oct 15, 2025
MAL-2022-11

Malicious code in 01template1 (npm)

Published Jun 20, 2022
MAL-2025-3864

Malicious code in yamoney-guidelines (npm)

Published May 16, 2025
MAL-2026-3158

Malicious code in apple-internal-pki-trust (npm)

Published Apr 29, 2026
CVE-2020-28278CRITICAL

shvl vulnerable to prototype pollution

Published May 24, 2022
GHSA-5jg4-p4qw-cgfr

@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags

Published Apr 4, 2026
MAL-2022-1379

Malicious code in azure-storage-common-cpp (npm)

Published Jun 20, 2022
MAL-2022-6350

Malicious code in supcom-web (npm)

Published Jun 20, 2022
MAL-2022-6352

Malicious code in super-streams (npm)

Published Jun 20, 2022
CVE-2024-37890HIGH

ws affected by a DoS when handling a request with many HTTP headers

Published Jun 17, 2024
CVE-2017-16063HIGH

node-opensl is malware

Published Oct 3, 2018
CVE-2016-10649HIGH

frames-compiler downloads Resources over HTTP

Published Sep 1, 2020
CVE-2026-3449

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

Published Mar 3, 2026
CVE-2026-32053

OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse

Published Mar 3, 2026
GHSA-5jpx-9hw9-2fx4

NextAuthjs Email misdelivery Vulnerability

Published Oct 29, 2025
CVE-2022-25907HIGH

ts-deepmerge before 2.0.2 vulnerable to Prototype Pollution

Published Aug 10, 2022
MAL-2025-4355

Malicious code in gop_status_frontend (npm)

Published May 23, 2025
CVE-2021-40663CRITICAL

Prototype Pollution in deep.assign

Published Jul 1, 2022
CVE-2026-32019

OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard

Published Mar 4, 2026
CVE-2026-33287

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

Published Mar 25, 2026
CVE-2017-16155HIGH

Directory Traversal in fast-http-cli

Published Jul 23, 2018
CVE-2024-43035MEDIUM

Fonoster is vulnerable to directory traversal

Published Mar 5, 2026
MAL-2022-1511

Malicious code in bfs-hello-world (npm)

Published Jun 20, 2022
GHSA-vr6p-vq2p-6j74

Withdrawn Advisory: LikeC4 has RCE through vulnerable React and Next.js versions

Published Dec 15, 2025
CVE-2026-25533

Sandbox escape via infinite recursion and error objects

Published Feb 5, 2026
MAL-2022-1512

Malicious code in bfvcjmwgayetoizd (npm)

Published Jul 11, 2022
MAL-2024-9276

Malicious code in o-typography (npm)

Published Oct 11, 2024
MAL-2025-4357

Malicious code in gunbazaar (npm)

Published May 23, 2025
MAL-2025-4567

Malicious code in log5j-v2 (npm)

Published May 26, 2025
MAL-2025-48924

Malicious code in energy-portal (npm)

Published Oct 28, 2025
MAL-2022-6353

Malicious code in superapp-sdk (npm)

Published Jun 20, 2022
CVE-2021-4326LOW

Imperative CLI vulnerable to Command Injection

Published Mar 1, 2023
CVE-2021-41182MEDIUM

XSS in the `altField` option of the Datepicker widget in jquery-ui

Published Oct 26, 2021
MAL-2022-1070

Malicious code in appboy (npm)

Published Jun 20, 2022
CVE-2020-7686HIGH

Directory traversal in rollup-plugin-server

Published Jul 29, 2020
GHSA-9gp8-hjxr-6f34

OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls

Published Apr 3, 2026
CVE-2024-46488

Heap-based Buffer Overflow in sqlite-vec

Published Sep 25, 2024
MAL-2024-9277

Malicious code in opti-distube (npm)

Published Oct 11, 2024
MAL-2022-6354

Malicious code in superset-websocket (npm)

Published Jun 20, 2022
MAL-2022-6358

Malicious code in supplysec-alert (npm)

Published Jun 20, 2022
MAL-2022-637

Malicious code in @thecheesecakefactory/fetlife-assets (npm)

Published Jun 20, 2022
MAL-2025-47063

Malicious code in hrpdesign (npm)

Published Sep 9, 2025
MAL-2025-47347

Malicious code in rxnt-kue (npm)

Published Sep 16, 2025
GHSA-vrhm-gvg7-fpcf

Memory exhaustion in SvelteKit remote form deserialization (experimental only)

Published Feb 19, 2026
MAL-2022-1107

Malicious code in arm-storsimple8000series (npm)

Published Jun 20, 2022
CVE-2021-24044CRITICAL

Access of Resource Using Incompatible Type in Hermes

Published Jan 16, 2022
CVE-2025-66479

Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing

Published Dec 4, 2025
MAL-2024-9310

Malicious code in 4tj82n (npm)

Published Oct 16, 2024
MAL-2025-47888

Malicious code in lovable-react (npm)

Published Oct 2, 2025
MAL-2025-6098

Malicious code in indexer-worker-service (npm)

Published Jul 21, 2025
MAL-2022-6370

Malicious code in svgjquyfeinbxrpl (npm)

Published Jul 11, 2022
MAL-2022-6380

Malicious code in swlenium-wkebdriver (npm)

Published Aug 19, 2022
MAL-2022-6384

Malicious code in synapse-artifacts (npm)

Published Jun 20, 2022
GHSA-5rp4-cwgh-gvwq

Duplicate Advisory: OpenClaw: WebSocket shared-auth connections could self-declare elevated scopes

Published Mar 19, 2026
MAL-2024-9320

Malicious code in a-lbum-do-wnload-avai-lable-file-261573-generations-do7io-mdogom (npm)

Published Oct 16, 2024
CVE-2026-24006

Seroval affected by Denial of Service via Deeply Nested Objects

Published Jan 22, 2026
CVE-2020-7787HIGH

Improper Authentication in react-adal

Published Apr 13, 2021
GHSA-9h9m-rr67-9jpg

coursevault-preview has a path traversal due to improper base-directory boundary validation

Published Apr 8, 2026
CVE-2026-1526

Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

Published Mar 13, 2026
GHSA-9hjh-fr4f-gxc4

OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin

Published Mar 27, 2026
MAL-2025-4905

Malicious code in vite-plugin-svgn (npm)

Published Jun 10, 2025
CVE-2026-23733

Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)

Published Jan 20, 2026
MAL-2025-49077

Malicious code in zeus-me-ops-tool (npm)

Published Oct 29, 2025
MAL-2022-6387

Malicious code in synapse-spark (npm)

Published Jun 20, 2022
CVE-2026-32094

Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash

Published Mar 11, 2026
CVE-2016-1000237MEDIUM

Cross-Site Scripting in sanitize-html

Published Apr 16, 2020
MAL-2025-49078

Malicious code in zeus-mex-user-profile (npm)

Published Oct 29, 2025
CVE-2015-6584MEDIUM

DataTable Vulnerable to Cross-Site Scripting

Published Aug 31, 2020
CVE-2021-25979CRITICAL

Apostrophe CMS Insufficient Session Expiration vulnerability

Published Nov 10, 2021
MAL-2024-9334

Malicious code in ava-ilable-down-load-mp3-today-2013-10071-pure-heroine-vldvc-oyqobe (npm)

Published Oct 16, 2024
CVE-2016-10633HIGH

dwebp-bin downloads Resources over HTTP

Published Feb 18, 2019
MAL-2026-476

Malicious code in @transaction-list/transaction-list-xs (npm)

Published Jan 23, 2026
MAL-2022-6402

Malicious code in szgkwdcqehtuiyjk (npm)

Published Jul 11, 2022
CVE-2026-27699

Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

Published Feb 25, 2026
Check your entire dependency tree at onceRun dependency scan →