OsVault/npm/i
npm55 critical

i

1001 known vulnerabilities · 55 critical · 144 high

CVE-2021-3820HIGH

inflect vulnerable to Inefficient Regular Expression Complexity

Published Sep 29, 2021
CVE-2026-24125

@tinacms/graphql has a Path Traversal issue

Published Mar 12, 2026
MAL-2024-8639

Malicious code in @diotoborg/soluta-numquam-ipsam (npm)

Published Sep 2, 2024
MAL-2024-8643

Malicious code in @diotoborg/suscipit-amet (npm)

Published Sep 2, 2024
CVE-2021-23359HIGH

Code injection in port-killer

Published Apr 13, 2021
CVE-2021-23398MEDIUM

Cross-site scripting in react-bootstrap-table

Published Dec 10, 2021
CVE-2026-25581

SCEditor has DOM XSS via emoticon URL/HTML injection

Published Feb 6, 2026
CVE-2021-43803HIGH

Unexpected server crash in Next.js.

Published Dec 7, 2021
MAL-2024-931

Malicious code in iifl_api (npm)

Published Jan 29, 2024
MAL-2024-949

Malicious code in diil-front (npm)

Published Jan 31, 2024
MAL-2024-9495

Malicious code in agora-rtc-web (npm)

Published Oct 16, 2024
CVE-2024-36361MEDIUM

Pug allows JavaScript code execution if an application accepts untrusted input

Published May 24, 2024
MAL-2025-129

Malicious code in jssdk-infrastructure (npm)

Published Jan 16, 2025
CVE-2022-25906HIGH

is-http2 vulnerable to Improper Input Validation

Published Feb 1, 2023
GHSA-5j59-xgg2-r9c4

Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up

Published Dec 12, 2025
MAL-2025-1290

Malicious code in kraken-dev (npm)

Published Feb 12, 2025
GHSA-5vjq-5jmg-39xq

Renovate affected by remote code execution was possible using the bazel-module or bazelisk managers, when using lockFileMaintenance

Published Apr 16, 2026
MAL-2022-1842

Malicious code in caspets (npm)

Published Jun 20, 2022
MAL-2024-7927

Malicious code in ampersend-mymove (npm)

Published Aug 7, 2024
MAL-2022-1843

Malicious code in cat-weather-widget (npm)

Published Jun 20, 2022
CVE-2019-18841HIGH

Prototype Pollution in chartkick

Published Dec 2, 2019
MAL-2022-1850

Malicious code in cd-system (npm)

Published Jul 5, 2022
MAL-2022-3021

Malicious code in ffwebsite (npm)

Published Jun 20, 2022
MAL-2022-7443

Malicious code in @getstep/sdk (npm)

Published Jun 20, 2022
MAL-2025-191057

Malicious code in @tiaanduplessis/react-progressbar (npm)

Published Nov 24, 2025
MAL-2025-191091

Malicious code in feature-flip (npm)

Published Nov 24, 2025
MAL-2025-1454

Malicious code in yizhifabao60 (npm)

Published Feb 17, 2025
MAL-2025-1455

Malicious code in yizhifabao61 (npm)

Published Feb 17, 2025
CVE-2026-33896CRITICAL
Risk: 88/100

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Published Mar 26, 2026
MAL-2024-7940

Malicious code in bs58lite (npm)

Published Aug 7, 2024
CVE-2017-16067HIGH

node-opencv is malware

Published Aug 29, 2018
CVE-2024-57189

Erxes Path Traversal vulnerability

Published Jun 10, 2025
GHSA-29qv-4j9f-fjw5

Unsafe object property setter in mathjs

Published Apr 16, 2026
CVE-2020-7704CRITICAL

linux-cmdline is vulnerable to Prototype Pollution via the constructor

Published May 24, 2022
CVE-2020-28438CRITICAL

deferred-exec Command Injection vulnerability

Published Jul 26, 2022
CVE-2023-26135HIGH

flatnest Prototype Pollution vulnerability

Published Jun 30, 2023
CVE-2025-13204

expr-eval vulnerable to Prototype Pollution

Published Nov 14, 2025
CVE-2022-25645MEDIUM

Prototype Pollution in dset

Published May 3, 2022
MAL-2025-1532

Malicious code in int_pinterest_sfra (npm)

Published Feb 23, 2025
MAL-2024-7960

Malicious code in gutenberg-ui (npm)

Published Aug 7, 2024
GHSA-2crg-3p73-43xp

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

Published Apr 10, 2026
CVE-2019-10749CRITICAL

SQL Injection in sequelize

Published Nov 8, 2019
MAL-2025-1547

Malicious code in zzmaliciouspackage (npm)

Published Feb 23, 2025
GHSA-2qrv-rc5x-2g2h

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

Published Apr 7, 2026
MAL-2025-1565

Malicious code in tablegen (npm)

Published Feb 28, 2025
MAL-2025-1574

Malicious code in behat (npm)

Published Feb 28, 2025
MAL-2025-1576

Malicious code in cis-photoshop-api-docs (npm)

Published Feb 28, 2025
MAL-2025-1625

Malicious code in sddst-ui (npm)

Published Feb 28, 2025
MAL-2025-1628

Malicious code in sui-cctp (npm)

Published Feb 28, 2025
CVE-2017-16101HIGH

Directory Traversal in serverwg

Published Sep 1, 2020
CVE-2021-23328MEDIUM

Prototype Pollution in iniparserjs

Published Apr 13, 2021
GHSA-8h25-q488-4hxw

OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment

Published Apr 23, 2026
MAL-2024-7978

Malicious code in onboarding-components (npm)

Published Aug 7, 2024
CVE-2018-16473MEDIUM

Path Traversal in takeapeek

Published Nov 6, 2018
CVE-2025-24360

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

Published Jan 27, 2025
MAL-2024-7979

Malicious code in ooflienro (npm)

Published Aug 7, 2024
CVE-2020-15215MEDIUM

Context isolation bypass in Electron

Published Oct 6, 2020
CVE-2021-23426MEDIUM

Prototype Pollution in Proto

Published Sep 2, 2021
MAL-2025-1655

Malicious code in secureshield4 (npm)

Published Mar 1, 2025
MAL-2025-1677

Malicious code in pages14.0.0_i18n (npm)

Published Mar 3, 2025
MAL-2025-168

Malicious code in borsh-js (npm)

Published Jan 20, 2025
CVE-2025-57354

counterpart vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2023-38507HIGH

Strapi Improper Rate Limiting vulnerability

Published Sep 13, 2023
MAL-2025-1689

Malicious code in @f2p-mml-frontends/mml-styles (npm)

Published Mar 3, 2025
MAL-2025-182

Malicious code in dotgov-list (npm)

Published Jan 20, 2025
MAL-2025-1906

Malicious code in npm-manifest (npm)

Published Mar 3, 2025
MAL-2025-190642

Malicious code in @asyncapi/react-component (npm)

Published Nov 24, 2025
CVE-2022-41957HIGH

muhammara and hummus vulnerable to Unchecked Return Value to NULL Pointer Dereference

Published Dec 5, 2022
MAL-2025-190674

Malicious code in @posthog/rrweb-snapshot (npm)

Published Nov 24, 2025
MAL-2025-190687

Malicious code in @trigo/keycloak-api (npm)

Published Nov 24, 2025
MAL-2025-190700

Malicious code in react-library-setup (npm)

Published Nov 24, 2025
CVE-2021-23440HIGH

Prototype Pollution in set-value

Published Sep 13, 2021
CVE-2021-23558HIGH

Prototype Pollution in bmoor

Published Feb 1, 2022
MAL-2025-190761

Malicious code in @zapier/babel-preset-zapier (npm)

Published Nov 24, 2025
CVE-2019-10804CRITICAL

OS Command Injection in serial-number

Published Apr 13, 2021
CVE-2024-53384

tsup DOM Clobbering vulnerability

Published Mar 3, 2025
CVE-2018-3730HIGH

Path Traversal in mcstatic

Published Jul 27, 2018
CVE-2020-24855MEDIUM

easywebpack-cli Path Traversal vulnerability

Published Dec 15, 2022
CVE-2022-36083MEDIUM

JOSE vulnerable to resource exhaustion via specifically crafted JWE

Published Sep 16, 2022
CVE-2022-39203HIGH

Parsing issue in matrix-org/node-irc leading to room takeovers

Published Sep 15, 2022
CVE-2022-39287HIGH

tiny-csrf has openly visible CSRF tokens

Published Oct 7, 2022
CVE-2026-23957

Seroval affected by Denial of Service via Array serialization

Published Jan 21, 2026
CVE-2026-25722

Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection

Published Feb 6, 2026
MAL-2024-801

Malicious code in wlwz-2312-7001 (npm)

Published Jan 24, 2024
CVE-2026-32064

OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 3, 2026
CVE-2022-39382CRITICAL

@keystone-6/core's NODE_ENV defaults to development with esbuild

Published Nov 3, 2022
CVE-2022-39236MEDIUM

Improper beacon events in matrix-js-sdk can result in availability issues

Published Sep 29, 2022
CVE-2026-28452

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

Published Feb 18, 2026
MAL-2025-190950

Malicious code in compare-obj (npm)

Published Nov 24, 2025
MAL-2025-190958

Malicious code in email-deliverability-tester (npm)

Published Nov 24, 2025
MAL-2025-190961

Malicious code in expressos (npm)

Published Nov 24, 2025
CVE-2025-12758

Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements

Published Nov 27, 2025
GHSA-3xx2-mqjm-hg9x

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

Published Apr 16, 2026
GHSA-25wv-8phj-8p7r

OpenClaw: Concurrent async auth attempts can bypass the intended shared-secret rate-limit budget on Tailscale-capable paths

Published Apr 9, 2026
GHSA-442j-39wm-28r2

Handlebars.js has a Property Access Validation Bypass in container.lookup

Published Mar 29, 2026
CVE-2026-3635

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

Published Mar 25, 2026
CVE-2022-43441HIGH

sqlite vulnerable to code execution due to Object coercion

Published Mar 13, 2023
CVE-2026-5323MEDIUM
Risk: 26.5/100

a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function

Published Apr 2, 2026
CVE-2022-41777HIGH

nadesiko3 allows remote attacker to inject invalid value to decodeURIComponent of nako3edit

Published Dec 5, 2022
MAL-2024-8020

Malicious code in benasin_logger (npm)

Published Aug 9, 2024
MAL-2025-190995

Malicious code in react-native-datepicker-modal (npm)

Published Nov 24, 2025
MAL-2025-191004

Malicious code in react-native-retriable-fetch (npm)

Published Nov 24, 2025
MAL-2025-191053

Malicious code in @seezo/sdr-mcp-server (npm)

Published Nov 24, 2025
GHSA-26wg-9xf2-q495

Novu has a XSS sanitization bypass

Published Apr 14, 2026
CVE-2022-39225MEDIUM

parse-server's session object properties can be updated by foreign user if object ID is known

Published Sep 21, 2022
CVE-2022-41654MEDIUM

ghost vulnerable to unauthorized newsletter modification via improper access controls

Published Nov 28, 2022
CVE-2025-4644

Payload's SQLite adapter Session Fixation vulnerability

Published Aug 29, 2025
CVE-2026-26830

pdf-image has an OS Command Injection Vulnerability through its pdfFilePath parameter

Published Mar 25, 2026
CVE-2013-4660MEDIUM

Deserialization Code Execution in js-yaml

Published Oct 24, 2017
MAL-2024-8040

Malicious code in system-library-gameanalytics-common (npm)

Published Aug 26, 2024
CVE-2023-26118MEDIUM

angular vulnerable to regular expression denial of service via the <input type="url"> element

Published Mar 30, 2023
MAL-2022-1247

Malicious code in azure-arm-iothub-samples-ts (npm)

Published Jun 20, 2022
MAL-2022-3989

Malicious code in iv-build-utils (npm)

Published Jun 20, 2022
MAL-2025-191066

Malicious code in automation_model (npm)

Published Nov 24, 2025
MAL-2025-191069

Malicious code in babel-preset-kinvey-flex-service (npm)

Published Nov 24, 2025
GHSA-2767-2q9v-9326

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

Published Apr 17, 2026
CVE-2014-8883

Directory Traversal in nhouston

Published Aug 31, 2020
MAL-2025-191073

Malicious code in better-auth-nuxt (npm)

Published Nov 24, 2025
GHSA-4948-f92q-f432

@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading

Published Apr 22, 2026
CVE-2015-1369HIGH

SQL Injection in sequelize

Published Oct 24, 2017
CVE-2023-37299MEDIUM

Joplin Cross-site Scripting vulnerability

Published Jun 30, 2023
MAL-2022-3756

Malicious code in icons-mail (npm)

Published Jun 20, 2022
MAL-2022-517

Malicious code in @portswigger/fetlife-assets (npm)

Published Jun 20, 2022
MAL-2022-5170

Malicious code in ozone-material (npm)

Published Jun 20, 2022
CVE-2021-30246CRITICAL

RSA signature validation vulnerability on maleable encoded message in jsrsasign

Published Apr 16, 2021
CVE-2022-39396CRITICAL

Remote code execution via MongoDB BSON parser through prototype pollution

Published Nov 8, 2022
CVE-2015-8856MEDIUM

Cross-Site Scripting in serve-index

Published Oct 24, 2017
CVE-2015-8851HIGH

Insecure Entropy Source - Math.random() in node-uuid

Published Apr 16, 2020
MAL-2022-1027

Malicious code in anypoint-component-site (npm)

Published Aug 19, 2022
MAL-2024-8065

Malicious code in who_mobile (npm)

Published Aug 28, 2024
CVE-2023-29019HIGH

Session fixation in fastify-passport

Published Apr 21, 2023
CVE-2023-6293HIGH

sequelize-typescript Prototype Pollution vulnerability

Published Nov 24, 2023
MAL-2022-5171

Malicious code in p224 (npm)

Published Jun 20, 2022
GHSA-7qf6-h84j-8fq4

OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model

Published Mar 3, 2026
MAL-2025-191138

Malicious code in pergel (npm)

Published Nov 24, 2025
MAL-2025-191151

Malicious code in wallet-evm (npm)

Published Nov 24, 2025
MAL-2022-6498

Malicious code in test494 (npm)

Published Jun 20, 2022
MAL-2022-650

Malicious code in @tinkoff-react-bui/checkbox-boxed (npm)

Published Jun 20, 2022
CVE-2026-4923

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Published Mar 27, 2026
CVE-2026-3089

Actual Sync Server has an Authenticated Path Traversal

Published Mar 10, 2026
CVE-2016-10550CRITICAL

SQL Injection in sequelize

Published Feb 18, 2019
CVE-2022-41878HIGH

Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers

Published Nov 9, 2022
MAL-2025-191172

Malicious code in @accordproject/concerto-linter (npm)

Published Nov 25, 2025
GHSA-4rc3-7j7w-m548

liquidjs has a Denial of Service via circular block reference in layout

Published Apr 24, 2026
MAL-2025-191173

Malicious code in @accordproject/concerto-linter-default-ruleset (npm)

Published Nov 25, 2025
CVE-2016-10652HIGH

prebuild-lwip downloads Resources over HTTP

Published Feb 18, 2019
MAL-2022-1028

Malicious code in anyswap-rewards (npm)

Published Jul 18, 2022
MAL-2024-8090

Malicious code in sweet-ruin-immortals-after-dark-16-by-kresley-cole-on-audiobook-full-volumes- (npm)

Published Aug 29, 2024
GHSA-4x48-cgf9-q33f

Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection

Published Apr 14, 2026
CVE-2024-47529

OpenC3 stores passwords in clear text (`GHSL-2024-129`)

Published Oct 2, 2024
CVE-2016-10531MEDIUM

Sanitization bypass using HTML Entities in marked

Published Feb 18, 2019
MAL-2022-5341

Malicious code in pipedrive-embeddable-ringcentral-phone-spa (npm)

Published Jun 20, 2022
CVE-2021-46704CRITICAL

OS Command Injection in GenieACS

Published Mar 7, 2022
GHSA-28g4-38q8-3cwc

Flowise: Cypher Injection in GraphCypherQAChain

Published Apr 16, 2026
CVE-2019-10802CRITICAL

OS Command Injection in giting

Published Apr 13, 2021
CVE-2016-10661HIGH

Downloads Resources over HTTP in phantomjs-cheniu

Published Feb 18, 2019
MAL-2024-8099

Malicious code in @diotoborg/a-quas (npm)

Published Sep 2, 2024
MAL-2024-81

Malicious code in schibsted-style (npm)

Published Jan 11, 2024
MAL-2025-191186

Malicious code in @alexcolls/nuxt-ux (npm)

Published Nov 25, 2025
MAL-2025-191191

Malicious code in @antstackio/shelbysam (npm)

Published Nov 25, 2025
MAL-2022-5471

Malicious code in prod_assets_web_modules (npm)

Published Jun 20, 2022
MAL-2022-5472

Malicious code in product-tools (npm)

Published Jun 20, 2022
CVE-2025-45143

string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)

Published Jun 30, 2025
CVE-2022-37262HIGH

steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments

Published Sep 16, 2022
MAL-2024-8108

Malicious code in @diotoborg/ad-non (npm)

Published Sep 2, 2024
CVE-2026-32061

OpenClaw vulnerable to arbitrary file read via $include directive

Published Mar 3, 2026
GHSA-58q2-7r52-jq62

OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read

Published Apr 3, 2026
CVE-2022-2237MEDIUM

keycloak-connect contains Open redirect vulnerability in the Node.js adapter

Published Mar 2, 2023
MAL-2025-191248

Malicious code in @oku-ui/alert-dialog (npm)

Published Nov 25, 2025
MAL-2025-191265

Malicious code in @oku-ui/presence (npm)

Published Nov 25, 2025
MAL-2023-152

Malicious code in caas-canvas (npm)

Published Mar 31, 2023
MAL-2024-10263

Malicious code in kbc-ui.templates (npm)

Published Oct 29, 2024
MAL-2024-12119

Malicious code in stablecoin-aptos (npm)

Published Dec 24, 2024
CVE-2016-5682MEDIUM

Cross-Site Scripting in swagger-ui

Published Sep 1, 2020
CVE-2020-28500MEDIUM

Regular Expression Denial of Service (ReDoS) in lodash

Published Jan 6, 2022
GHSA-47wq-cj9q-wpmp

Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys

Published Apr 16, 2026
MAL-2024-8122

Malicious code in @diotoborg/aliquam-fugit-culpa (npm)

Published Sep 2, 2024
MAL-2025-191294

Malicious code in @posthog/laudspeaker-plugin (npm)

Published Nov 25, 2025
CVE-2022-24278HIGH

Directory traversal in convert-svg-core

Published Jun 11, 2022
MAL-2024-382

Malicious code in wlwz-2312-2305 (npm)

Published Jan 24, 2024
MAL-2024-519

Malicious code in wlwz-2312-3807 (npm)

Published Jan 24, 2024
MAL-2024-529

Malicious code in wlwz-2312-3908 (npm)

Published Jan 24, 2024
CVE-2020-7677HIGH

thenify before 3.3.1 made use of unsafe calls to `eval`.

Published Jul 18, 2022
MAL-2025-191410

Malicious code in quickswap-smart-order-router (npm)

Published Nov 24, 2025
MAL-2025-191171

Malicious code in @accordproject/concerto-analysis (npm)

Published Nov 25, 2025
CVE-2024-27088

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
MAL-2024-8133

Malicious code in @diotoborg/aperiam-cum (npm)

Published Sep 2, 2024
MAL-2024-8041

Malicious code in system-library-gameanalytics-slotanalytics (npm)

Published Aug 26, 2024
MAL-2024-8109

Malicious code in @diotoborg/ad-rerum (npm)

Published Sep 2, 2024
CVE-2023-29020MEDIUM

CSRF token fixation in fastify-passport

Published Apr 21, 2023
CVE-2017-16079HIGH

smb is malware

Published Aug 29, 2018
CVE-2017-16016MEDIUM

Cross-Site Scripting in sanitize-html

Published Nov 9, 2018
MAL-2025-191433

Malicious code in tcsp (npm)

Published Nov 25, 2025
CVE-2026-25641

@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses

Published Feb 5, 2026
CVE-2018-3722HIGH

Prototype Pollution in merge-deep

Published Jul 26, 2018
MAL-2024-8145

Malicious code in @diotoborg/aspernatur-id (npm)

Published Sep 2, 2024
MAL-2024-8146

Malicious code in @diotoborg/aspernatur-in (npm)

Published Sep 2, 2024
CVE-2017-16007MEDIUM

Invalid Curve Attack in node-jose

Published Jul 20, 2018
MAL-2025-191435

Malicious code in tiptap-shadcn-vue (npm)

Published Nov 24, 2025
MAL-2024-8258

Malicious code in @diotoborg/dolorum-atque (npm)

Published Sep 2, 2024
MAL-2024-8259

Malicious code in @diotoborg/dolorum-autem (npm)

Published Sep 2, 2024
MAL-2024-8446

Malicious code in @diotoborg/natus-facere-esse (npm)

Published Sep 2, 2024
MAL-2024-8481

Malicious code in @diotoborg/nulla-optio (npm)

Published Sep 2, 2024
CVE-2022-25973HIGH

mc-kill-port vulnerable to Arbitrary Command Execution via kill function

Published Aug 11, 2022
GHSA-4jpm-cgx2-8h37

Flowise: Sensitive Data Leak in public-chatbotConfig

Published Apr 16, 2026
CVE-2022-27263CRITICAL

Unrestricted Upload of File with Dangerous Type in Strapi

Published Apr 13, 2022
MAL-2024-8151

Malicious code in @diotoborg/assumenda-saepe-mollitia (npm)

Published Sep 2, 2024
MAL-2025-191469

Malicious code in bip40 (npm)

Published Nov 25, 2025
MAL-2025-191473

Malicious code in chai-jsons (npm)

Published Nov 26, 2025
CVE-2017-16095HIGH

Directory Traversal in serverliujiayi1

Published Sep 1, 2020
CVE-2017-16201HIGH

Directory Traversal in zjjserver

Published Sep 1, 2020
MAL-2025-190584

Malicious code in @kiwiiw/ez-lib (npm)

Published Nov 20, 2025
GHSA-2ch6-x3g4-7759

OpenClaw's commands.allowFrom sender authorization accepted conversation identifiers via ctx.From

Published Mar 3, 2026
CVE-2018-1000086HIGH

pym.js CSRF Vulnerability

Published Mar 13, 2018
CVE-2018-16491CRITICAL

Prototype Pollution in node.extend

Published Feb 7, 2019
CVE-2018-11537MEDIUM

Auth0 angular-jwt misinterprets allowlist as regex

Published May 14, 2022
MAL-2022-1086

Malicious code in argocd-diff-action (npm)

Published Jun 20, 2022
MAL-2024-8163

Malicious code in @diotoborg/autem-dolor (npm)

Published Sep 2, 2024
MAL-2024-8164

Malicious code in @diotoborg/autem-id (npm)

Published Sep 2, 2024
MAL-2025-191480

Malicious code in accounts-base (npm)

Published Nov 27, 2025
MAL-2025-191482

Malicious code in wartsila-application-json (npm)

Published Nov 27, 2025
MAL-2025-191174

Malicious code in @accordproject/concerto-metamodel (npm)

Published Nov 25, 2025
CVE-2026-24888

Maker.js has Unsafe Property Copying in makerjs.extendObject

Published Jan 29, 2026
GHSA-2cq5-mf3v-mx44

OpenClaw: busybox and toybox applet execution weakened exec approval binding

Published Apr 17, 2026
CVE-2023-23630HIGH

XSS Attack with Express API

Published Jan 31, 2023
MAL-2024-8167

Malicious code in @diotoborg/autem-vero (npm)

Published Sep 2, 2024
MAL-2025-191495

Malicious code in @bingads-webui-clientcenter/instrumentation (npm)

Published Dec 1, 2025
CVE-2021-43307MEDIUM

Regular expression denial of service in semver-regex

Published Jun 3, 2022
CVE-2018-3714MEDIUM

Path Traversal in node-srv

Published Jul 26, 2018
MAL-2025-191497

Malicious code in handtalk-test-app (npm)

Published Dec 1, 2025
MAL-2025-191199

Malicious code in @browserbasehq/stagehand-docs (npm)

Published Nov 25, 2025
MAL-2025-191276

Malicious code in @oku-ui/tabs (npm)

Published Nov 25, 2025
MAL-2025-191302

Malicious code in @productdevbook/auth (npm)

Published Nov 25, 2025
CVE-2026-28793

TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete

Published Mar 12, 2026
CVE-2023-7078HIGH

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 29, 2023
CVE-2023-46998MEDIUM

Bootbox.js Cross Site Scripting vulnerability

Published Nov 14, 2023
MAL-2022-1030

Malicious code in aocrn (npm)

Published Aug 19, 2022
MAL-2024-818

Malicious code in wlwz-2312-7200 (npm)

Published Jan 24, 2024
CVE-2011-4969MEDIUM

jQuery vulnerable to Cross-Site Scripting (XSS)

Published May 14, 2022
MAL-2025-191359

Malicious code in @voiceflow/nestjs-rate-limit (npm)

Published Nov 25, 2025
MAL-2025-191511

Malicious code in iife-sample (npm)

Published Dec 1, 2025
MAL-2025-191417

Malicious code in rediff-viewer (npm)

Published Nov 24, 2025
CVE-2023-27563HIGH

n8n Privilege Escalation vulnerability

Published May 10, 2023
MAL-2025-191418

Malicious code in revenuecat (npm)

Published Nov 24, 2025
CVE-2026-32003

OpenClaw has system.run shell-wrapper env injection via SHELLOPTS/PS4 can bypass allowlist intent (RCE)

Published Mar 3, 2026
CVE-2021-33040MEDIUM

Cross-site Scripting in epubjs

Published Jan 21, 2022
CVE-2017-1000006MEDIUM

Cross Site Scripting (XSS) in plotly.js

Published Oct 24, 2017
CVE-2019-10769CRITICAL

Sandbox Breakout / Arbitrary Code Execution in safer-eval

Published Dec 11, 2019
CVE-2019-15658HIGH

SQL Injection in connect-pg-simple

Published Aug 26, 2019
MAL-2025-191517

Malicious code in mongodb-atlas-cli-toc-generator (npm)

Published Dec 1, 2025
CVE-2019-25225MEDIUM

sanitize-html is vulnerable to XSS through incomprehensive sanitization

Published Sep 8, 2025
MAL-2025-191518

Malicious code in mongodb-compass (npm)

Published Dec 1, 2025
MAL-2025-191519

Malicious code in mongodb-stitch-server-testutils (npm)

Published Dec 1, 2025
MAL-2025-191520

Malicious code in nnc-web (npm)

Published Dec 1, 2025
MAL-2025-191424

Malicious code in shell-exec (npm)

Published Nov 24, 2025
MAL-2025-191441

Malicious code in uniswap-router-sdk (npm)

Published Nov 24, 2025
CVE-2022-3145MEDIUM

@okta/oidc-middlewareOpen Redirect vulnerability

Published Jan 9, 2023
CVE-2024-21505HIGH

web3-utils Prototype Pollution vulnerability

Published Mar 27, 2024
CVE-2025-69873

ajv has ReDoS when using `$data` option

Published Feb 11, 2026
CVE-2024-21536HIGH

Denial of service in http-proxy-middleware

Published Oct 19, 2024
CVE-2020-12648MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Aug 11, 2020
MAL-2025-191538

Malicious code in hl-naduccio (npm)

Published Dec 1, 2025
MAL-2022-1486

Malicious code in bdesse (npm)

Published Aug 19, 2022
MAL-2024-8191

Malicious code in @diotoborg/corporis-quia (npm)

Published Sep 2, 2024
MAL-2025-191543

Malicious code in stream-xor-chain (npm)

Published Dec 2, 2025
MAL-2025-191546

Malicious code in chai-status (npm)

Published Dec 2, 2025
MAL-2024-8192

Malicious code in @diotoborg/corporis-repellat-dicta (npm)

Published Sep 2, 2024
MAL-2025-191491

Malicious code in babel-plugin-standalone (npm)

Published Nov 30, 2025
MAL-2025-191554

Malicious code in tensorfi-secure-hash (npm)

Published Dec 2, 2025
GHSA-647h-p824-99w7

@grackle-ai/mcp has a workspace authorization bypass in its knowledge_search MCP tool

Published Mar 25, 2026
CVE-2021-31597CRITICAL

Improper Certificate Validation in xmlhttprequest-ssl

Published May 24, 2021
MAL-2024-8198

Malicious code in @diotoborg/culpa-at-cumque (npm)

Published Sep 2, 2024
MAL-2025-191498

Malicious code in kmf-cookieservice (npm)

Published Dec 1, 2025
MAL-2025-191502

Malicious code in pluxee-design-system (npm)

Published Dec 1, 2025
MAL-2025-191512

Malicious code in kubebuilder (npm)

Published Dec 1, 2025
MAL-2025-191513

Malicious code in kubernetes-controller-tools (npm)

Published Dec 1, 2025
MAL-2025-191516

Malicious code in markdownlint-cli2-action (npm)

Published Dec 1, 2025
MAL-2025-191551

Malicious code in solana-dexfi-suite (npm)

Published Dec 2, 2025
CVE-2023-45884MEDIUM

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Published Nov 9, 2023
CVE-2023-37466CRITICAL

vm2 Sandbox Escape vulnerability

Published Jul 13, 2023
CVE-2023-23636MEDIUM

Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name

Published Feb 3, 2023
CVE-2023-39655CRITICAL

CouchAuth host header injection vulnerability leaks the password reset token

Published Jan 3, 2024
MAL-2025-191576

Malicious code in jqxcore (npm)

Published Dec 1, 2025
MAL-2025-191583

Malicious code in redirect-5k9q5v (npm)

Published Dec 1, 2025
GHSA-2h6j-mhcp-9j9h

GenieACS has an unauthenticated access vulnerability via the NBI API endpoint

Published Apr 7, 2026
CVE-2023-27490HIGH

Missing proper state, nonce and PKCE checks for OAuth authentication

Published Mar 13, 2023
GHSA-5fw2-mwhh-9947

Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials

Published Apr 17, 2026
MAL-2025-191584

Malicious code in redirect-clrm2u (npm)

Published Dec 1, 2025
CVE-2025-68457

Orejime has executable code in HTML attributes

Published Dec 19, 2025
CVE-2022-25349MEDIUM

materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input

Published May 3, 2022
MAL-2025-2658

Malicious code in cln-logger (npm)

Published Mar 25, 2025
MAL-2025-6190

Malicious code in obvbd (npm)

Published Jul 22, 2025
MAL-2025-7074

Malicious code in @amber-team/storybook-utils (npm)

Published Aug 14, 2025
CVE-2026-2265MEDIUM
Risk: 32.52/100

Replicator deserializes untrusted user input

Published Apr 1, 2026
CVE-2022-1650HIGH

Exposure of Sensitive Information in eventsource

Published May 13, 2022
GHSA-ccx3-fw7q-rr2r

OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks

Published Apr 9, 2026
CVE-2022-37623CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 31, 2022
MAL-2022-1031

Malicious code in aoe_playstyle (npm)

Published Jun 20, 2022
MAL-2025-191965

Malicious code in karemm3 (npm)

Published Dec 3, 2025
MAL-2025-191973

Malicious code in elf-stats-fuzzy-fir-973 (npm)

Published Dec 3, 2025
MAL-2024-8206

Malicious code in @diotoborg/cum-saepe-minima (npm)

Published Sep 2, 2024
MAL-2025-191977

Malicious code in elf-stats-rooftop-stockpile-626 (npm)

Published Dec 3, 2025
MAL-2025-191988

Malicious code in elf-stats-aurora-candy-291 (npm)

Published Dec 3, 2025
MAL-2025-191989

Malicious code in elf-stats-aurora-garland-513 (npm)

Published Dec 3, 2025
MAL-2024-8207

Malicious code in @diotoborg/cum-ut-iure (npm)

Published Sep 2, 2024
MAL-2025-191990

Malicious code in elf-stats-aurora-workbench-513 (npm)

Published Dec 3, 2025
CVE-2021-3223HIGH

Path traversal in Node-RED-Dashboard

Published Jan 29, 2021
CVE-2020-7755HIGH

Regular Expression Denial of Service in dat.gui

Published May 10, 2021
CVE-2025-57329

web3-core-method is vulnerable to prototype pollution

Published Sep 24, 2025
MAL-2025-191993

Malicious code in elf-stats-bright-cushion-246 (npm)

Published Dec 3, 2025
MAL-2025-191996

Malicious code in elf-stats-candlelit-toy-571 (npm)

Published Dec 3, 2025
MAL-2022-1033

Malicious code in ap-election-adapter (npm)

Published Jun 20, 2022
MAL-2024-8215

Malicious code in @diotoborg/delectus-recusandae-aut (npm)

Published Sep 2, 2024
MAL-2025-192020

Malicious code in elf-stats-evergreen-chimney-857 (npm)

Published Dec 3, 2025
MAL-2024-8216

Malicious code in @diotoborg/delectus-voluptatibus (npm)

Published Sep 2, 2024
MAL-2025-192025

Malicious code in elf-stats-evergreen-sled-681 (npm)

Published Dec 3, 2025
MAL-2025-7964

Malicious code in @frozen-team-qa/types (npm)

Published Aug 14, 2025
MAL-2025-9264

Malicious code in @protos-team/frontend-server (npm)

Published Aug 14, 2025
CVE-2024-36422MEDIUM

Flowise Cross-site Scripting in api/v1/chatflows/id

Published Aug 5, 2024
CVE-2023-32235HIGH

Path Traversal in Ghost

Published May 5, 2023
CVE-2020-24660CRITICAL

Lack of URL normalization may lead to authorization bypass when URL access rules are used

Published Sep 9, 2020
CVE-2022-39266CRITICAL

isolated-vm has vulnerable CachedDataOptions in API

Published Sep 30, 2022
CVE-2021-26073HIGH

Broken Authentication in Atlassian Connect Express

Published May 24, 2022
CVE-2020-7632CRITICAL

OS Command Injection in node-mpv

Published Jan 7, 2022
MAL-2024-8224

Malicious code in @diotoborg/dicta-recusandae-veniam (npm)

Published Sep 2, 2024
MAL-2024-8225

Malicious code in @diotoborg/dignissimos-aliquam (npm)

Published Sep 2, 2024
MAL-2025-192033

Malicious code in elf-stats-flickering-candy-280 (npm)

Published Dec 3, 2025
MAL-2025-192034

Malicious code in elf-stats-flickering-fir-572 (npm)

Published Dec 3, 2025
GHSA-cr3w-cw5w-h3fj

Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE

Published Jan 26, 2026
CVE-2026-27122

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

Published Feb 19, 2026
MAL-2026-1062

Malicious code in express-core-validator (npm)

Published Feb 27, 2026
CVE-2021-23335HIGH

LDAP Injection in is-user-valid

Published Apr 13, 2021
MAL-2026-3257

Malicious code in @omni-corp-infra/sso-bridge-core (npm)

Published Apr 29, 2026
CVE-2020-7681HIGH

Path Traversal in marscode

Published May 7, 2021
MAL-2026-3258

Malicious code in @tech-global/internal-gateway-core (npm)

Published Apr 29, 2026
GHSA-5w25-hxp5-h8c9

Duplicate Advisory: Improper Verification of Cryptographic Signature

Published Jun 21, 2021
MAL-2024-8235

Malicious code in @diotoborg/dolor-earum-quia (npm)

Published Sep 2, 2024
CVE-2023-22493HIGH

RSSHub SSRF vulnerability

Published Jan 11, 2023
MAL-2026-3260

Malicious code in google-storage-cloud (npm)

Published Apr 29, 2026
MAL-2025-192078

Malicious code in elf-stats-lanternlit-sled-571 (npm)

Published Dec 3, 2025
MAL-2024-8236

Malicious code in @diotoborg/dolor-iure (npm)

Published Sep 2, 2024
MAL-2025-192085

Malicious code in elf-stats-merry-chimney-765 (npm)

Published Dec 3, 2025
MAL-2026-3261

Malicious code in internal-auth-provider (npm)

Published Apr 29, 2026
MAL-2026-3262

Malicious code in react-native-parallax-scroll-view-updated (npm)

Published Apr 29, 2026
CVE-2022-36079HIGH

Parse Server vulnerable to brute force guessing of user sensitive data via search patterns

Published Sep 16, 2022
MAL-2022-1042

Malicious code in api-routes-rest (npm)

Published Jul 21, 2022
MAL-2024-8249

Malicious code in @diotoborg/dolores-fugiat-autem (npm)

Published Sep 2, 2024
MAL-2025-192086

Malicious code in elf-stats-merry-cookiejar-754 (npm)

Published Dec 3, 2025
MAL-2025-192087

Malicious code in elf-stats-merry-cookiejar-915 (npm)

Published Dec 3, 2025
CVE-2019-10771MEDIUM

Cross-Site Scripting in iobroker.web

Published Dec 2, 2019
CVE-2026-30920

OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding

Published Mar 9, 2026
CVE-2020-7763HIGH

Arbitrary File Read in phantom-html-to-pdf

Published Nov 6, 2020
MAL-2026-3263

Malicious code in @bcs-adapters/core-adapter (npm)

Published May 4, 2026
MAL-2024-8260

Malicious code in @diotoborg/dolorum-dolorum (npm)

Published Sep 2, 2024
CVE-2021-43812MEDIUM

Open redirect in @auth0/nextjs-auth0

Published Dec 16, 2021
CVE-2016-10559HIGH

Downloads Resources over HTTP in selenium-download

Published Feb 18, 2019
MAL-2024-8261

Malicious code in @diotoborg/dolorum-ipsam (npm)

Published Sep 2, 2024
MAL-2025-192132

Malicious code in elf-stats-shimmering-workshop-590 (npm)

Published Dec 3, 2025
CVE-2024-29027CRITICAL

Server crashes on invalid Cloud Function or Cloud Job name

Published Mar 19, 2024
CVE-2020-7629CRITICAL

OS Command Injection in install-package

Published Feb 10, 2022
MAL-2024-8262

Malicious code in @diotoborg/dolorum-iste-excepturi (npm)

Published Sep 2, 2024
MAL-2025-192134

Malicious code in elf-stats-silvered-mitten-503 (npm)

Published Dec 3, 2025
MAL-2026-2135

Malicious code in yelp-react-component-photo-upload (npm)

Published Mar 24, 2026
MAL-2026-3280

Malicious code in pi-exa-mcp (npm)

Published May 4, 2026
MAL-2026-3281

Malicious code in pos-next-react-native (npm)

Published May 4, 2026
MAL-2025-192139

Malicious code in elf-stats-snowdusted-bauble-104 (npm)

Published Dec 3, 2025
MAL-2026-3282

Malicious code in shopify-draggable (npm)

Published May 4, 2026
CVE-2016-10694HIGH

Downloads Resources over HTTP in alto-saxophone

Published Jul 31, 2018
MAL-2024-8271

Malicious code in @diotoborg/eaque-illum-qui (npm)

Published Sep 2, 2024
MAL-2024-8272

Malicious code in @diotoborg/eaque-iste (npm)

Published Sep 2, 2024
CVE-2025-69262

pnpm vulnerable to Command Injection via environment variable substitution

Published Jan 7, 2026
MAL-2025-192140

Malicious code in elf-stats-snowdusted-fireplace-396 (npm)

Published Dec 3, 2025
CVE-2025-8101

Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)

Published Jul 26, 2025
CVE-2025-24012

XSS/HTML Injection Vulnerability in Umbraco Backoffice Components

Published Jan 21, 2025
MAL-2025-192141

Malicious code in elf-stats-snowdusted-saddlebag-790 (npm)

Published Dec 3, 2025
GHSA-6pfc-6m7w-m8fx

OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper

Published Mar 31, 2026
CVE-2020-9038MEDIUM

Cross-site Scripting in Joplin

Published Oct 13, 2020
MAL-2026-3283

Malicious code in temhe-dev (npm)

Published May 4, 2026
MAL-2026-3284

Malicious code in tinfoil-shops (npm)

Published May 4, 2026
CVE-2026-27001

OpenClaw: Unsanitized CWD path injection into LLM prompts

Published Feb 18, 2026
GHSA-534w-2vm4-89xr

OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch

Published Mar 3, 2026
CVE-2020-7617MEDIUM

Prototype Pollution in ini-parser

Published Jun 10, 2020
CVE-2023-1001LOW

vxe-table Cross-site Scripting vulnerability

Published May 24, 2024
GHSA-2qqc-p94c-hxwh

Flowise: Weak Default Express Session Secret

Published Apr 16, 2026
MAL-2025-192154

Malicious code in elf-stats-sparkly-cocoa-863 (npm)

Published Dec 3, 2025
MAL-2025-192159

Malicious code in elf-stats-sprucey-snowman-250 (npm)

Published Dec 3, 2025
MAL-2025-192160

Malicious code in elf-stats-sprucey-train-471 (npm)

Published Dec 3, 2025
CVE-2025-29927

Authorization Bypass in Next.js Middleware

Published Mar 21, 2025
CVE-2021-25913CRITICAL

Prototype Pollution in set-or-get

Published Apr 12, 2021
CVE-2026-23889

pnpm has Windows-specific tarball Path Traversal

Published Jan 26, 2026
CVE-2023-46308CRITICAL

plotly.js prototype pollution vulnerability

Published Jan 3, 2024
MAL-2024-828

Malicious code in wlwz-2312-7301 (npm)

Published Jan 24, 2024
MAL-2026-3285

Malicious code in vpi-guides (npm)

Published May 4, 2026
MAL-2024-8280

Malicious code in @diotoborg/eius-animi-ullam (npm)

Published Sep 2, 2024
MAL-2026-3286

Malicious code in wagner-horizon (npm)

Published May 4, 2026
CVE-2021-39171MEDIUM

Unlimited transforms allowed for signed nodes

Published Aug 30, 2021
CVE-2016-10552HIGH

Resources Downloaded over Insecure Protocol in igniteui

Published Feb 18, 2019
CVE-2017-20160MEDIUM

express-param vulnerable to Improper Handling of Extra Parameters

Published Dec 31, 2022
CVE-2016-10598HIGH

arrayfire-js downloads Resources over HTTP

Published Feb 18, 2019
MAL-2025-192181

Malicious code in elf-stats-twinkling-marshmallow-913 (npm)

Published Dec 3, 2025
CVE-2025-5276

Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Published May 29, 2025
MAL-2025-192197

Malicious code in elf-stats-wintry-icicle-283 (npm)

Published Dec 3, 2025
MAL-2022-109

Malicious code in @azure-tests/perf-service-bus (npm)

Published Jun 20, 2022
CVE-2016-10519HIGH

Remote Memory Disclosure in bittorrent-dht

Published Sep 1, 2020
CVE-2024-22891CRITICAL

Nteract Remote Code Execution vulnerability

Published Mar 1, 2024
MAL-2022-1090

Malicious code in arkane-network (npm)

Published Jun 20, 2022
MAL-2025-192204

Malicious code in elf-stats-caroling-mailbag-397 (npm)

Published Dec 3, 2025
MAL-2026-3287

Malicious code in ams-ssk (npm)

Published May 2, 2026
CVE-2019-5485CRITICAL

Command Injection in gitlabhook

Published Sep 16, 2019
CVE-2022-39384MEDIUM

OpenZeppelin Contracts initializer reentrancy may lead to double initialization

Published Dec 14, 2021
CVE-2016-10688HIGH

Downloads Resources over HTTP in haxe3

Published Aug 17, 2018
CVE-2025-57752

Next.js Affected by Cache Key Confusion for Image Optimization API Routes

Published Aug 29, 2025
CVE-2020-36650MEDIUM

gry vulnerable to Command Injection

Published Jan 11, 2023
MAL-2024-8290

Malicious code in @diotoborg/esse-accusantium-ratione (npm)

Published Sep 2, 2024
CVE-2020-17480MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Jan 30, 2020
CVE-2024-51434

Froala WYSIWYG editor allows cross-site scripting (XSS)

Published Nov 8, 2024
MAL-2024-8291

Malicious code in @diotoborg/esse-distinctio-repellat (npm)

Published Sep 2, 2024
MAL-2025-192210

Malicious code in elf-stats-frostbitten-reindeer-875 (npm)

Published Dec 3, 2025
MAL-2025-192212

Malicious code in elf-stats-ginger-reindeer-411 (npm)

Published Dec 3, 2025
MAL-2026-3288

Malicious code in common-tg-service (npm)

Published May 2, 2026
MAL-2026-3322

Malicious code in microsoft-agents-auth-service (npm)

Published May 4, 2026
GHSA-2rqg-gjgv-84jm

OpenClaw: Gateway `agent` calls could override the workspace boundary

Published Mar 13, 2026
CVE-2016-10553CRITICAL

Potential SQL Injection in sequelize

Published Feb 18, 2019
MAL-2025-192213

Malicious code in elf-stats-gingersnap-ornament-469 (npm)

Published Dec 3, 2025
MAL-2025-192214

Malicious code in elf-stats-glittering-fir-252 (npm)

Published Dec 3, 2025
CVE-2020-7639MEDIUM

eivindfjeldstad-dot contains prototype pollution vulnerability

Published May 25, 2021
MAL-2024-8303

Malicious code in @diotoborg/et-voluptatum-mollitia (npm)

Published Sep 2, 2024
MAL-2025-192215

Malicious code in elf-stats-glittering-nutcracker-709 (npm)

Published Dec 3, 2025
GHSA-5g3j-89fr-r2vp

skilleton has improper input handling in repository/path processing

Published Apr 8, 2026
CVE-2020-7682HIGH

Path Traversal in marked-tree

Published May 7, 2021
CVE-2022-29257MEDIUM

AutoUpdater module fails to validate certain nested components of the bundle

Published Jun 16, 2022
GHSA-3298-56p6-rpw2

OpenClaw has incomplete Fix for CVE-2026-27486: Unvalidated SIGKILL in `!stop` Chat Command via `shell-utils.ts`

Published Mar 30, 2026
CVE-2026-22029

React Router vulnerable to XSS via Open Redirects

Published Jan 8, 2026
GHSA-g87j-gm7p-6vw2

Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 19, 2026
GHSA-2w79-r9g8-wmcr

OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062)

Published Apr 3, 2026
CVE-2021-23354MEDIUM

printf vulnerable to Regular Expression Denial of Service (ReDoS)

Published Mar 19, 2021
MAL-2024-8316

Malicious code in @diotoborg/eveniet-officia (npm)

Published Sep 2, 2024
CVE-2021-34080CRITICAL

OS Command injection in ssl-utils

Published Jun 3, 2022
CVE-2025-66031

node-forge has ASN.1 Unbounded Recursion

Published Nov 26, 2025
CVE-2023-31999HIGH

@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state

Published Jul 5, 2023
CVE-2021-23348MEDIUM

Arbitrary Command Injection in portprocesses

Published Apr 6, 2021
MAL-2024-8317

Malicious code in @diotoborg/eveniet-pariatur-esse (npm)

Published Sep 2, 2024
MAL-2024-8318

Malicious code in @diotoborg/ex-quo-odio (npm)

Published Sep 2, 2024
MAL-2026-3323

Malicious code in paypal-payouts-bridge (npm)

Published May 4, 2026
GHSA-7853-gqqm-vcwx

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools

Published Apr 8, 2026
MAL-2025-192218

Malicious code in elf-stats-merry-cookiejar-442 (npm)

Published Dec 3, 2025
MAL-2026-3326

Malicious code in paychex-common-vendor-lib (npm)

Published May 4, 2026
CVE-2019-14772MEDIUM

Cross-Site Scripting (XSS) in Verdaccio

Published May 29, 2019
MAL-2025-192229

Malicious code in elf-stats-sleighing-nutcracker-806 (npm)

Published Dec 3, 2025
MAL-2026-3327

Malicious code in capacitor-plugin-service-worker (npm)

Published May 4, 2026
MAL-2026-3328

Malicious code in pocpoc2626 (npm)

Published May 4, 2026
CVE-2025-53889

Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows

Published Jul 15, 2025
MAL-2025-192266

Malicious code in elf-stats-silvered-star-676 (npm)

Published Dec 3, 2025
CVE-2024-34712MEDIUM

Oceanic allows unsanitized user input to lead to path traversal in URLs

Published May 14, 2024
MAL-2025-192267

Malicious code in elf-stats-snowdusted-lantern-234 (npm)

Published Dec 3, 2025
GHSA-7fqq-q52p-2jjg

OpenCC has an Out-of-bounds read when processing truncated UTF-8 input

Published Mar 29, 2026
CVE-2023-37298MEDIUM

Joplin Cross-site Scripting vulnerability

Published Jun 30, 2023
MAL-2026-3329

Malicious code in api-typings (npm)

Published May 4, 2026
MAL-2026-3330

Malicious code in seek-pass (npm)

Published May 4, 2026
GHSA-7jp6-r74r-995q

OpenClaw: Matrix profile config persistence was reachable from operator.write message tools

Published Apr 17, 2026
MAL-2026-3331

Malicious code in lazyhtml-scripts (npm)

Published May 4, 2026
MAL-2026-3334

Malicious code in fanduel (npm)

Published May 4, 2026
MAL-2026-3335

Malicious code in @bank-widgets/whats-new (npm)

Published May 4, 2026
MAL-2026-3336

Malicious code in @channel_bot/xa0 (npm)

Published May 4, 2026
MAL-2026-3337

Malicious code in @t-in-one/save_application_hid_to_storage (npm)

Published May 4, 2026
MAL-2026-3338

Malicious code in ms.analytics-web (npm)

Published May 4, 2026
CVE-2021-43849MEDIUM

cordova-plugin-fingerprint-aio DoS vulnerability

Published Nov 2, 2023
MAL-2025-192368

Malicious code in paysera-checkout-modal (npm)

Published Dec 7, 2025
MAL-2025-192370

Malicious code in elf-stats-snowdusted-cookiejar-250 (npm)

Published Dec 4, 2025
CVE-2025-4643

Payload does not invalidate JWTs after log out

Published Aug 29, 2025
CVE-2026-33468

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

Published Mar 20, 2026
CVE-2021-21423MEDIUM

Rebuild-bot workflow may allow unauthorised repository modifications

Published Apr 6, 2021
CVE-2021-25916CRITICAL

Prototype pollution vulnerability in 'patchmerge'

Published Oct 13, 2021
MAL-2025-192473

Malicious code in elf-stats-candlelit-train-228 (npm)

Published Dec 11, 2025
MAL-2025-192480

Malicious code in elf-stats-caroling-hammer-382 (npm)

Published Dec 11, 2025
CVE-2022-24728MEDIUM

Cross-site Scripting in CKEditor4

Published Mar 16, 2022
GHSA-855c-r2vq-c292

Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

Published Apr 16, 2026
CVE-2025-48054

radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published May 27, 2025
CVE-2022-23494MEDIUM

Cross-site scripting vulnerability in TinyMCE alerts

Published Dec 8, 2022
CVE-2018-7651MEDIUM

Regular Expression Denial of Service in ssri

Published Mar 7, 2018
CVE-2023-6460MEDIUM

Logging of the firestore key within nodejs-firestore

Published Dec 4, 2023
CVE-2026-26832

node-tesseract-ocr is vulnerable to OS Command Injection through unsanitized recognize() function parameter

Published Mar 25, 2026
MAL-2024-8370

Malicious code in @diotoborg/inventore-quasi (npm)

Published Sep 2, 2024
CVE-2026-1615

jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions

Published Feb 9, 2026
CVE-2022-2064HIGH

Insufficient Session Expiration in NocoDB

Published Jun 14, 2022
MAL-2024-8371

Malicious code in @diotoborg/ipsa-deleniti-ab (npm)

Published Sep 2, 2024
MAL-2025-192539

Malicious code in elf-stats-twinkling-bell-867 (npm)

Published Dec 11, 2025
MAL-2025-192541

Malicious code in mui-wrapper-icons (npm)

Published Dec 11, 2025
CVE-2020-1914CRITICAL

Always-Incorrect Control Flow Implementation in Facebook Hermes

Published May 24, 2022
CVE-2018-3732HIGH

Path Traversal in resolve-path

Published Jul 18, 2018
CVE-2025-64765

Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

Published Nov 19, 2025
CVE-2026-25752

FUXA Unauthenticated Remote Arbitrary Device Tag Write

Published Feb 5, 2026
CVE-2016-4055MEDIUM

Regular Expression Denial of Service in moment

Published Oct 24, 2017
MAL-2025-192545

Malicious code in bfruitmaliciousxmlparser (npm)

Published Dec 12, 2025
MAL-2024-8380

Malicious code in @diotoborg/iste-laborum (npm)

Published Sep 2, 2024
MAL-2024-8381

Malicious code in @diotoborg/itaque-aliquid-quisquam (npm)

Published Sep 2, 2024
MAL-2025-192567

Malicious code in uba-plugins (npm)

Published Dec 12, 2025
CVE-2020-28433HIGH

node-latex-pdf is susceptible to command injection

Published Aug 3, 2022
MAL-2024-8392

Malicious code in @diotoborg/labore-atque (npm)

Published Sep 2, 2024
MAL-2025-192620

Malicious code in android_teminator_x (npm)

Published Dec 19, 2025
MAL-2025-192626

Malicious code in elf-stats-cocoa-workshop-459 (npm)

Published Dec 19, 2025
CVE-2019-15479MEDIUM

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Published Sep 23, 2019
CVE-2018-21268CRITICAL

Node-Traceroute RCE Vulnerability

Published May 24, 2022
CVE-2021-40823MEDIUM

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

Published Sep 14, 2021
MAL-2022-1098

Malicious code in arm-attestation (npm)

Published Jun 20, 2022
MAL-2022-1099

Malicious code in arm-azurestack (npm)

Published Jun 20, 2022
MAL-2025-192674

Malicious code in xnetgpt (npm)

Published Dec 19, 2025
CVE-2016-10520HIGH

Regular Expression Denial of Service in jadedown

Published Feb 18, 2019
CVE-2020-28436HIGH

google-cloudstorage-commands Command Injection vulnerability

Published Jul 26, 2022
MAL-2022-11

Malicious code in 01template1 (npm)

Published Jun 20, 2022
MAL-2025-192682

Malicious code in @nosinovacao/nosid-mfe-common (npm)

Published Dec 20, 2025
MAL-2025-192692

Malicious code in @vienna_cancer_center_portal/js (npm)

Published Dec 22, 2025
GHSA-89r3-6x4j-v7wf

OpenClaw: Voice-call Plivo replay mutates in-process callback origin before replay rejection

Published Apr 2, 2026
GHSA-63f5-hhc7-cx6p

OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval

Published Mar 16, 2026
CVE-2022-21164LOW

Unhandled case in node-lmdb

Published Mar 17, 2022
GHSA-h97f-6pqj-q452

OpenClaw has a IPv6 multicast SSRF classifier bypass

Published Mar 3, 2026
MAL-2024-8406

Malicious code in @diotoborg/libero-ratione-delectus (npm)

Published Sep 2, 2024
CVE-2026-22177

OpenClaw's config env vars allowed startup env injection into service runtime

Published Mar 3, 2026
GHSA-8g29-8xwr-qmhr

@grackle-ai/server JSON.parse lacks try-catch logic in its gRPC Service AdapterConfig Handling

Published Mar 25, 2026
MAL-2025-192709

Malicious code in amazon-testpackage (npm)

Published Dec 23, 2025
MAL-2025-192710

Malicious code in amournapraia (npm)

Published Dec 23, 2025
GHSA-9vq7-9h42-j88h

MCPHub has an authentication bypass

Published Apr 14, 2026
CVE-2019-10795MEDIUM

Prototype Pollution in undefsafe

Published Feb 9, 2022
MAL-2022-1488

Malicious code in bdwngkairzovfpje (npm)

Published Jul 11, 2022
CVE-2015-5688MEDIUM

Directory Traversal in geddy

Published Oct 24, 2017
MAL-2024-8428

Malicious code in @diotoborg/molestiae-doloribus (npm)

Published Sep 2, 2024
MAL-2025-192740

Malicious code in elf-stats-caroling-wreath-635 (npm)

Published Dec 23, 2025
MAL-2024-8429

Malicious code in @diotoborg/molestiae-maxime (npm)

Published Sep 2, 2024
MAL-2025-192754

Malicious code in chai-max (npm)

Published Dec 23, 2025
MAL-2025-192771

Malicious code in elf-stats-glittering-cookie-844 (npm)

Published Dec 23, 2025
CVE-2017-16054HIGH

nodefabric is malware

Published Jul 23, 2018
CVE-2026-0621

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

Published Jan 5, 2026
CVE-2025-31128

gifplayer XSS vulnerability

Published Mar 31, 2025
MAL-2025-192951

Malicious code in ugc-kit (npm)

Published Dec 27, 2025
GHSA-939r-rj45-g2rj

OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins

Published Apr 17, 2026
CVE-2015-8857CRITICAL

Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js

Published Oct 24, 2017
MAL-2025-192965

Malicious code in awsmcc (npm)

Published Dec 30, 2025
CVE-2026-29185

Backstage vulnerable to potential reading of SCM URLs using built in token

Published Mar 5, 2026
MAL-2025-194

Malicious code in ie8-dom-define (npm)

Published Jan 20, 2025
CVE-2017-16072HIGH

nodemailer.js is malware

Published Aug 29, 2018
CVE-2017-16153HIGH

Directory Traversal in gaoxuyan

Published Sep 1, 2020
MAL-2024-8471

Malicious code in @diotoborg/nobis-facilis (npm)

Published Sep 2, 2024
CVE-2026-25047

deepHas vulnerable to Prototype Pollution via constructor.prototype

Published Jan 29, 2026
MAL-2025-2014

Malicious code in configs-web-react (npm)

Published Mar 3, 2025
CVE-2026-27609

Parse Dashboard is Missing CSRF Protection for its Agent Endpoint

Published Feb 25, 2026
CVE-2020-7725CRITICAL

Prototype Pollution in worksmith

Published May 6, 2021
CVE-2025-56200

validator.js has a URL validation bypass vulnerability in its isURL function

Published Sep 30, 2025
MAL-2025-2017

Malicious code in aws-features-signin-proxy-client (npm)

Published Mar 3, 2025
MAL-2024-8472

Malicious code in @diotoborg/nobis-mollitia (npm)

Published Sep 2, 2024
MAL-2025-2035

Malicious code in console-node-ts (npm)

Published Mar 3, 2025
CVE-2017-16098HIGH

Regular Expression Denial of Service in charset

Published Aug 9, 2018
CVE-2021-25946CRITICAL

Prototype pollution in nconf-toml

Published Jun 7, 2021
CVE-2026-30959

OneUptime has WhatsApp Resend Verification Authorization Bypass

Published Mar 10, 2026
GHSA-jjw7-3vjf-fg5j

OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get

Published Apr 2, 2026
CVE-2023-30843HIGH

Hidden fields can be leaked on readable collections in Payload

Published Apr 26, 2023
MAL-2024-849

Malicious code in wlwz-2312-7504 (npm)

Published Jan 24, 2024
MAL-2025-2092

Malicious code in aws-ui-component-select (npm)

Published Mar 4, 2025
MAL-2025-2109

Malicious code in lappsec-testpackage (npm)

Published Mar 4, 2025
MAL-2025-2230

Malicious code in pixelary (npm)

Published Mar 11, 2025
CVE-2017-16126MEDIUM

Tracking Module in botbait

Published Sep 1, 2020
MAL-2025-2264

Malicious code in linear-open-issue (npm)

Published Mar 11, 2025
CVE-2021-21306MEDIUM

Regular Expression Denial of Service (REDoS) in Marked

Published Feb 8, 2021
CVE-2021-39157HIGH

Improper Handling of Exceptional Conditions in detect-character-encoding

Published Aug 25, 2021
MAL-2024-85

Malicious code in tsb-authorization (npm)

Published Jan 12, 2024
CVE-2020-7683HIGH

Directory traversal in rollup-plugin-server

Published Jul 29, 2020
CVE-2024-21511CRITICAL

MySQL2 for Node Arbitrary Code Injection

Published Apr 23, 2024
CVE-2020-26938HIGH

oauth2-server through 3.1.1 vulnerable to Open Redirect

Published Aug 30, 2022
MAL-2025-2696

Malicious code in ofjaaah-dependency-confusion (npm)

Published Mar 25, 2025
MAL-2025-2716

Malicious code in vistar-ad-clienttestadv3 (npm)

Published Mar 25, 2025
CVE-2017-16065HIGH

openssl.js is malware

Published Aug 29, 2018
CVE-2021-46871MEDIUM

phoenix_html allows Cross-site Scripting in HEEx class attributes

Published Jan 10, 2023
MAL-2024-8503

Malicious code in @diotoborg/officiis-nam-dignissimos (npm)

Published Sep 2, 2024
CVE-2016-10564HIGH

Downloads Resources over HTTP in apk-parser

Published Sep 1, 2020
MAL-2025-3246

Malicious code in fatfingers-hello (npm)

Published Apr 17, 2025
MAL-2025-3247

Malicious code in fatfingers-helloo (npm)

Published Apr 17, 2025
MAL-2025-3509

Malicious code in echo-color (npm)

Published Apr 24, 2025
CVE-2018-14731HIGH

Missing Origin Validation in parcel-bundler

Published Oct 30, 2018
MAL-2024-8512

Malicious code in @diotoborg/optio-voluptatum (npm)

Published Sep 2, 2024
MAL-2025-3532

Malicious code in nsemea-core-poc (npm)

Published Apr 29, 2025
CVE-2026-32033

OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths

Published Mar 3, 2026
MAL-2024-8515

Malicious code in @diotoborg/perferendis-odit (npm)

Published Sep 2, 2024
CVE-2025-30359

webpack-dev-server users' source code may be stolen when they access a malicious web site

Published Jun 4, 2025
MAL-2024-8523

Malicious code in @diotoborg/placeat-placeat (npm)

Published Sep 2, 2024
CVE-2024-29194HIGH

OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

Published Mar 25, 2024
MAL-2025-3618

Malicious code in cordova-plugin-permissions (npm)

Published May 6, 2025
MAL-2025-3926

Malicious code in wagmi-ethers-connectors (npm)

Published May 16, 2025
MAL-2025-397

Malicious code in bookingcom-auth (npm)

Published Jan 24, 2025
CVE-2022-23080MEDIUM

Server-Side Request Forgery in Directus

Published Jun 23, 2022
MAL-2024-8541

Malicious code in @diotoborg/quaerat-dicta (npm)

Published Sep 2, 2024
MAL-2025-3974

Malicious code in wegenenverkeer (npm)

Published May 5, 2025
MAL-2025-4134

Malicious code in string-multiutils (npm)

Published May 21, 2025
CVE-2024-21908MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Oct 22, 2021
MAL-2025-4135

Malicious code in system-v11 (npm)

Published May 21, 2025
MAL-2025-4464

Malicious code in airdrop-interface-markets (npm)

Published May 27, 2025
CVE-2021-23341HIGH

Denial of service in prismjs

Published Mar 1, 2021
MAL-2025-4493

Malicious code in nayan-videos-downloaders (npm)

Published May 27, 2025
CVE-2025-27109

Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)

Published Feb 25, 2025
CVE-2020-5251HIGH

Information disclosure in parse-server

Published Mar 4, 2020
CVE-2021-32851MEDIUM

Mind-elixir Cross-site Scripting vulnerability

Published Feb 21, 2023
MAL-2024-8576

Malicious code in @diotoborg/quo-dolorem-ducimus (npm)

Published Sep 2, 2024
CVE-2022-21211MEDIUM

Unhandled crash in npm posix

Published Jun 11, 2022
MAL-2025-47866

Malicious code in zenith.svg-loader (npm)

Published Sep 26, 2025
CVE-2018-16487MEDIUM

Prototype Pollution in lodash

Published Feb 7, 2019
MAL-2025-47887

Malicious code in lovable-js (npm)

Published Oct 2, 2025
GHSA-hf68-49fm-59cq

OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve

Published Mar 26, 2026
MAL-2024-8583

Malicious code in @diotoborg/quos-accusantium (npm)

Published Sep 2, 2024
CVE-2019-5483MEDIUM

Sensitive Data Exposure in seneca

Published Sep 11, 2019
CVE-2022-29244HIGH

Packing does not respect root-level ignore files in workspaces

Published Jun 2, 2022
GHSA-52vj-fvrv-7q82

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

Published Apr 10, 2026
GHSA-5jg4-p4qw-cgfr

@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags

Published Apr 4, 2026
MAL-2024-8584

Malicious code in @diotoborg/quos-eos (npm)

Published Sep 2, 2024
CVE-2023-30541MEDIUM

OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated

Published Apr 17, 2023
MAL-2025-47892

Malicious code in pycodestyle (npm)

Published Oct 2, 2025
MAL-2025-49356

Malicious code in aes-valid-ipherv (npm)

Published Nov 5, 2025
MAL-2025-5451

Malicious code in plonkscript-docs (npm)

Published Jun 18, 2025
CVE-2022-29230MEDIUM

Potential Cross-site Scripting vulnerability in Hydrogen

Published May 19, 2022
MAL-2026-1515

Malicious code in developit (npm)

Published Mar 16, 2026
CVE-2016-10695HIGH

Downloads Resources over HTTP in npm-test-sqlite3-trunk

Published Sep 1, 2020
CVE-2016-10623HIGH

Downloads Resources over HTTP in macaca-chromedriver-zxa

Published Feb 18, 2019
MAL-2025-5973

Malicious code in web3js-wallet (npm)

Published Jul 15, 2025
MAL-2025-6186

Malicious code in nf-cons-log (npm)

Published Jul 22, 2025
MAL-2025-626

Malicious code in hardhat-configs (npm)

Published Jan 30, 2025
MAL-2025-6334

Malicious code in style-postprocessor (npm)

Published Jul 28, 2025
MAL-2025-6335

Malicious code in uidraftism (npm)

Published Jul 28, 2025
CVE-2024-29271MEDIUM

VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability

Published Mar 22, 2024
GHSA-6f7g-v4pp-r667

Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise

Published Apr 16, 2026
MAL-2026-1135

Malicious code in yuji-baileys (npm)

Published Mar 2, 2026
MAL-2026-1150

Malicious code in libsignal-yazxz (npm)

Published Mar 3, 2026
MAL-2026-1581

Malicious code in whatnot-events (npm)

Published Mar 19, 2026
MAL-2026-1679

Malicious code in chai-promised-async (npm)

Published Mar 18, 2026
MAL-2026-1690

Malicious code in chain-promised-cli (npm)

Published Mar 18, 2026
MAL-2026-2419

Malicious code in express-session-js (npm)

Published Apr 2, 2026
CVE-2026-29607

OpenClaw's allow-always wrapper persistence could bypass future approvals and enable command execution

Published Mar 2, 2026
MAL-2026-2420

Malicious code in @_wnpm/wnpm-cli (npm)

Published Apr 2, 2026
CVE-2020-28280CRITICAL

Prototype pollution vulnerability in 'predefine'

Published Oct 12, 2021
MAL-2026-2696

Malicious code in bfx-hf-strategy-perf (npm)

Published Apr 15, 2026
CVE-2026-26316

OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust

Published Feb 17, 2026
MAL-2026-2709

Malicious code in @appleseed-apple/ac-sass-kit (npm)

Published Apr 16, 2026
MAL-2026-2905

Malicious code in simple-auth-basic (npm)

Published Apr 15, 2026
CVE-2021-37916MEDIUM

Joplin vulnerable to Cross-site Scripting in notes

Published May 24, 2022
MAL-2026-2914

Malicious code in modern-events (npm)

Published Apr 16, 2026
MAL-2026-2915

Malicious code in bitu-staking (npm)

Published Apr 12, 2026
GHSA-6pcv-j4jx-m4vx

Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request

Published Apr 16, 2026
GHSA-6r77-hqx7-7vw8

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

Published Apr 16, 2026
CVE-2022-0087MEDIUM

Reflected cross-site scripting (XSS) vulnerability

Published Jan 12, 2022
GHSA-hv93-r4j3-q65f

OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing

Published Feb 17, 2026
CVE-2025-26042

Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Mar 31, 2025
CVE-2026-33409

Parse Server has an auth provider validation bypass on login via partial authData

Published Mar 19, 2026
GHSA-8783-3wgf-jggf

Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints

Published Apr 16, 2026
MAL-2026-2987

Malicious code in @bmg-web/bmg-external-link (npm)

Published Apr 22, 2026
MAL-2026-2988

Malicious code in @bmg-web/bmg-grid (npm)

Published Apr 22, 2026
CVE-2026-28792

TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

Published Mar 12, 2026
MAL-2026-2989

Malicious code in @bmg-web-features/bmg-user-interaction-tracker (npm)

Published Apr 22, 2026
GHSA-mwv9-gp5h-frr4

Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties

Published Mar 12, 2026
CVE-2026-32731

ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

Published Mar 18, 2026
MAL-2026-2990

Malicious code in etsyapp (npm)

Published Apr 22, 2026
MAL-2026-2991

Malicious code in pgserve (npm)

Published Apr 22, 2026
MAL-2026-2992

Malicious code in @automagik/genie (npm)

Published Apr 22, 2026
CVE-2023-34245HIGH

@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme

Published Jun 9, 2023
CVE-2019-15599CRITICAL

Command Injection in tree-kill

Published Sep 4, 2020
CVE-2021-46320HIGH

Improper Initialization in OpenZeppelin

Published Feb 5, 2022
CVE-2017-16203HIGH

coffe-script is malware

Published Aug 6, 2018
CVE-2025-12735

expr-eval does not restrict functions passed to the evaluate function

Published Nov 5, 2025
CVE-2023-26159HIGH

Follow Redirects improperly handles URLs in the url.parse() function

Published Jan 2, 2024
CVE-2025-53364

Parse Server exposes the data schema via GraphQL API

Published Jul 10, 2025
CVE-2025-61917

n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

Published Feb 4, 2026
MAL-2026-3004

Malicious code in @nklkas/hyperliquid (npm)

Published Apr 23, 2026
MAL-2026-3005

Malicious code in changelog-cli-logger (npm)

Published Apr 23, 2026
MAL-2026-3006

Malicious code in changelog-utils-structured-logger (npm)

Published Apr 23, 2026
CVE-2024-43788MEDIUM

Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS

Published Aug 27, 2024
CVE-2023-28443MEDIUM

directus vulnerable to Insertion of Sensitive Information into Log File

Published Mar 23, 2023
CVE-2022-0639MEDIUM

url-parse Incorrectly parses URLs that include an '@'

Published Feb 18, 2022
CVE-2017-16190HIGH

Directory Traversal in dcdcdcdcdc

Published Sep 1, 2020
MAL-2026-3010

Malicious code in separadordeinfocc (npm)

Published Apr 23, 2026
MAL-2026-3011

Malicious code in ts-bing (npm)

Published Apr 23, 2026
MAL-2026-3012

Malicious code in ts-moduler (npm)

Published Apr 23, 2026
MAL-2026-3013

Malicious code in undicy-http (npm)

Published Apr 23, 2026
MAL-2026-3014

Malicious code in vime-azl (npm)

Published Apr 23, 2026
MAL-2026-888

Malicious code in pyright-root (npm)

Published Feb 13, 2026
MAL-2026-889

Malicious code in responses-starter-app (npm)

Published Feb 13, 2026
CVE-2026-22176

OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 3, 2026
CVE-2016-10576HIGH

fuseki downloads Resources over HTTP

Published Feb 18, 2019
MAL-2026-895

Malicious code in json-mapping-src (npm)

Published Feb 13, 2026
CVE-2018-16486CRITICAL

Prototype Pollution in defaults-deep

Published Feb 7, 2019
CVE-2016-10703HIGH

Denial of Service in ecstatic

Published Dec 28, 2017
MAL-2026-955

Malicious code in crypto-locale (npm)

Published Feb 20, 2026
MAL-2022-1499

Malicious code in ben1 (npm)

Published Jul 8, 2022
CVE-2020-7684HIGH

Path traversal in rollup-plugin-serve

Published May 18, 2021
GHSA-4jpw-hj22-2xmc

OpenClaw: Pairing-scoped device tokens could mint `operator.admin` and reach node RCE

Published Mar 13, 2026
MAL-2024-8542

Malicious code in @diotoborg/quaerat-eius (npm)

Published Sep 2, 2024
MAL-2025-192249

Malicious code in elf-stats-shimmering-muffin-598 (npm)

Published Dec 3, 2025
CVE-2020-7636CRITICAL

OS Command Injection in adb-driver

Published Dec 9, 2021
GHSA-c276-fj82-f2pq

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Published Apr 16, 2026
CVE-2026-33671

Picomatch has a ReDoS vulnerability via extglob quantifiers

Published Mar 25, 2026
CVE-2026-27970

Angular i18n vulnerable to Cross-Site Scripting

Published Feb 27, 2026
CVE-2016-10536MEDIUM

Insecure Defaults Allow MITM Over TLS in engine.io-client

Published Feb 18, 2019
CVE-2022-22984MEDIUM

Snyk plugins vulnerable to Command Injection

Published Nov 30, 2022
GHSA-vp62-r36r-9xqp

Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace

Published Apr 21, 2026
CVE-2025-22150

Use of Insufficiently Random Values in undici

Published Jan 21, 2025
CVE-2015-9235CRITICAL

Verification Bypass in jsonwebtoken

Published Oct 9, 2018
CVE-2026-22028

Preact has JSON VNode Injection issue

Published Jan 7, 2026
CVE-2026-31862

@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters

Published Mar 11, 2026
CVE-2021-23369MEDIUM

Remote code execution in handlebars when compiling templates

Published May 6, 2021
CVE-2026-34780HIGH
Risk: 41.51/100

Electron: Context Isolation bypass via contextBridge VideoFrame transfer

Published Apr 3, 2026
CVE-2024-56159

Astro's server source code is exposed to the public if sourcemaps are enabled

Published Dec 19, 2024
GHSA-4c3q-x735-j3r5

Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

Published Apr 17, 2026
CVE-2026-34768LOW
Risk: 19.5/100

Electron: Unquoted executable path in app.setLoginItemSettings on Windows

Published Apr 3, 2026
GHSA-fvx6-pj3r-5q4q

OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 6, 2026
CVE-2021-27524MEDIUM

Margox Braft-Editor Cross-site Scripting Vulnerability

Published Aug 11, 2023
CVE-2018-16474MEDIUM

Stored Cross-Site Scripting in tianma-static

Published Nov 6, 2018
GHSA-jhm7-29pj-4xvf

@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codes

Published Apr 16, 2026
GHSA-gwhp-pf74-vj37

Fastify's connection header abuse enables stripping of proxy-added headers

Published Apr 16, 2026
CVE-2024-43796MEDIUM

express vulnerable to XSS via response.redirect()

Published Sep 10, 2024
CVE-2025-70948

@perfood/couch-auth has a host header injection vulnerability

Published Mar 5, 2026
CVE-2018-3752CRITICAL

Prototype Pollution in merge-options

Published Oct 9, 2018
CVE-2016-10680HIGH

Downloads Resources over HTTP in adamvr-geoip-lite

Published Sep 1, 2020
CVE-2023-30548MEDIUM

Path traversal vulnerability in gatsby-plugin-sharp

Published Apr 20, 2023
CVE-2025-53535

Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes

Published Jul 7, 2025
CVE-2017-16078HIGH

Shadowsock is malware

Published Aug 27, 2018
GHSA-h3hw-29fv-2x75

@envelop/graphql-modules has a Race Condition vulnerability

Published Jan 21, 2026
CVE-2026-4867

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Published Mar 27, 2026
CVE-2019-9154HIGH

Improper Key Verification in openpgp

Published Aug 23, 2019
CVE-2026-28395

OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback

Published Feb 17, 2026
CVE-2023-25653HIGH

Improper calculations in ECC implementation can trigger a Denial-of-Service (DoS)

Published Feb 16, 2023
CVE-2017-16034

Command Injection in pidusage

Published Sep 1, 2020
CVE-2026-27013

Fabric.js Affected by Stored XSS via SVG Export

Published Feb 18, 2026
CVE-2017-16195HIGH

Directory Traversal in pytservce

Published Sep 1, 2020
CVE-2014-10066HIGH

Directory Traversal in fancy-server

Published Aug 31, 2020
GHSA-2858-xg23-26fp

OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots

Published Mar 3, 2026
CVE-2020-28426HIGH

Command injection in kill-process-on-port

Published Mar 19, 2021
MAL-2025-192725

Malicious code in chai-pack (npm)

Published Dec 23, 2025
CVE-2017-16163HIGH

Directory Traversal in dylmomo

Published Sep 1, 2020
CVE-2021-23384MEDIUM

Open Redirect in koa-remove-trailing-slashes

Published Feb 10, 2022
MAL-2026-1027

Malicious code in rtxbbtyols (npm)

Published Feb 24, 2026
MAL-2024-8626

Malicious code in @diotoborg/sed-tempora-natus (npm)

Published Sep 2, 2024
MAL-2024-8627

Malicious code in @diotoborg/sed-veniam-cupiditate (npm)

Published Sep 2, 2024
CVE-2026-25128

fast-xml-parser has RangeError DoS Numeric Entities Bug

Published Jan 30, 2026
CVE-2023-23936MEDIUM

CRLF Injection in Nodejs ‘undici’ via host

Published Feb 16, 2023
CVE-2026-30962

Parse Server has a protected fields bypass via logical query operators

Published Mar 11, 2026
CVE-2020-28450HIGH

Prototype Pollution in decal

Published Apr 13, 2021
CVE-2013-6393MEDIUM

Heap Based Buffer Overflow in libyaml

Published Aug 31, 2020
CVE-2022-31069MEDIUM

Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
CVE-2024-27296MEDIUM

Directus version number disclosure

Published Mar 1, 2024
MAL-2022-1059

Malicious code in apollocli8ent (npm)

Published Aug 19, 2022
CVE-2026-1664

Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing

Published Feb 3, 2026
GHSA-m866-6qv5-p2fg

OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Published Mar 31, 2026
GHSA-rf75-g96h-j3rm

Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 2, 2026
MAL-2022-106

Malicious code in @azure-tests/perf-keyvault-secrets (npm)

Published Jun 20, 2022
MAL-2024-8646

Malicious code in @diotoborg/suscipit-officia (npm)

Published Sep 2, 2024
CVE-2025-59142

color-string@2.1.1 contains malware after npm account takeover

Published Sep 15, 2025
CVE-2026-33979

Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk)

Published Mar 27, 2026
GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

Published Apr 6, 2026
MAL-2024-8647

Malicious code in @diotoborg/suscipit-vitae (npm)

Published Sep 2, 2024
MAL-2024-8648

Malicious code in @diotoborg/tempora-consequatur (npm)

Published Sep 2, 2024
CVE-2016-10673HIGH

ipip-coffee downloads Resources over HTTP

Published Feb 18, 2019
MAL-2022-1060

Malicious code in apollolinhttp (npm)

Published Aug 19, 2022
MAL-2024-8658

Malicious code in @diotoborg/temporibus-quasi-quasi (npm)

Published Sep 2, 2024
CVE-2017-16024MEDIUM

Tmp files readable by other users in sync-exec

Published Nov 9, 2018
CVE-2016-10626HIGH

Downloads Resources over HTTP in mystem3

Published Feb 18, 2019
GHSA-r849-826x-wgqm

Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 19, 2026
CVE-2025-54798

tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

Published Aug 6, 2025
MAL-2024-8659

Malicious code in @diotoborg/tenetur-eos-commodi (npm)

Published Sep 2, 2024
CVE-2026-32055

OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 12, 2026
CVE-2026-35442HIGH
Risk: 47.05/100

Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries

Published Apr 4, 2026
CVE-2026-21852

Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

Published Jan 21, 2026
CVE-2021-26700HIGH

Remote code execution in vscode-npm-script

Published May 24, 2022
MAL-2024-8674

Malicious code in @diotoborg/velit-placeat (npm)

Published Sep 2, 2024
MAL-2024-8675

Malicious code in @diotoborg/velit-reiciendis-velit (npm)

Published Sep 2, 2024
CVE-2022-21670MEDIUM

Uncontrolled Resource Consumption in markdown-it

Published Jan 12, 2022
GHSA-mhr7-2xmv-4c4q

OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode

Published Apr 3, 2026
GHSA-767m-xrhc-fxm7

OpenClaw: Gateway operator.write Can Reach Admin-Class Telegram Config and Cron Persistence via send

Published Apr 7, 2026
CVE-2026-28482

OpenClaw's unsanitized session ID enables path traversal in transcript file operations

Published Feb 18, 2026
CVE-2017-16039HIGH

Directory Traversal in hftp

Published Jul 24, 2018
CVE-2023-27564HIGH

n8n Information Disclosure vulnerability

Published May 10, 2023
MAL-2022-1065

Malicious code in app.1inch.io (npm)

Published Jul 25, 2022
MAL-2024-870

Malicious code in wlwz-2312-7707 (npm)

Published Jan 24, 2024
CVE-2021-21413HIGH

Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate

Published Apr 6, 2021
CVE-2017-16118HIGH

Regular Expression Denial of Service in forwarded

Published Jul 24, 2018
CVE-2025-68157

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

Published Feb 5, 2026
CVE-2026-34767MEDIUM
Risk: 29.51/100

Electron: HTTP Response Header Injection in custom protocol handlers and webRequest

Published Apr 3, 2026
CVE-2015-9545HIGH

Improper Input Validation in xdLocalStorage

Published Dec 9, 2021
CVE-2022-21144HIGH

Denial of service vulnerability exists in libxmljs

Published May 3, 2022
CVE-2020-28470HIGH

Cross-site Scripting (XSS) in @scullyio/scully

Published Apr 13, 2021
CVE-2023-31133HIGH

Ghost vulnerable to information disclosure of private API fields

Published May 3, 2023
CVE-2017-16222MEDIUM

Directory Traversal in elding

Published Aug 6, 2018
MAL-2024-8719

Malicious code in muthu (npm)

Published Sep 3, 2024
CVE-2022-35143CRITICAL

Raneto v0.17.0 employs weak password complexity requirements

Published Aug 5, 2022
CVE-2020-6506MEDIUM

Android WebView Universal Cross-site Scripting

Published Oct 2, 2020
CVE-2025-56572

Finance.js vulnerable to DoS via the seekZero() parameter

Published Sep 30, 2025
CVE-2023-42282CRITICAL

NPM IP package incorrectly identifies some private IP addresses as public

Published Feb 8, 2024
CVE-2020-15156MEDIUM

XSS due to lack of CSRF validation for replying/publishing

Published Aug 26, 2020
CVE-2021-23562MEDIUM

Code injection in plupload

Published Dec 16, 2021
CVE-2024-41818HIGH

fast-xml-parser vulnerable to ReDOS at currency parsing

Published Jul 29, 2024
CVE-2020-4045HIGH

Information disclosure in SSB-DB

Published Jun 11, 2020
CVE-2019-18608HIGH

Cezerin Unauthorized Acces

Published May 24, 2022
CVE-2008-6681MEDIUM

Cross-Site Scripting in dojo

Published Sep 1, 2020
CVE-2022-31367HIGH

Strapi mishandles hidden attributes within admin API responses

Published Sep 28, 2022
GHSA-mqpr-49jj-32rc

n8n: Webhook Forgery on Github Webhook Trigger

Published Feb 26, 2026
CVE-2026-33768

Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

Published Mar 26, 2026
CVE-2018-1000620CRITICAL

Insufficient Entropy in cryptiles

Published Sep 11, 2018
MAL-2022-1492

Malicious code in bebekair (npm)

Published Jun 9, 2022
MAL-2024-8819

Malicious code in 0g-storage-contracts (npm)

Published Sep 5, 2024
GHSA-39pp-xp36-q6mg

OpenClaw has Inconsistent Host Exec Environment Override Sanitization

Published Mar 26, 2026
GHSA-39q2-94rc-95cp

DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation

Published Apr 16, 2026
CVE-2021-29491

Use of Potentially Dangerous Function in mixme

Published May 6, 2021
CVE-2021-34078HIGH

OS Command Injection in lifion-verify-deps

Published Jun 3, 2022
MAL-2024-882

Malicious code in wlwz-2312-7901 (npm)

Published Jan 24, 2024
MAL-2024-8821

Malicious code in apigeeclientlib (npm)

Published Sep 5, 2024
GHSA-mvv8-v4jj-g47j

Directus: Sensitive fields exposed in revision history

Published Apr 4, 2026
CVE-2025-57320

json-schema-editor-visual vulnerable to prototype pollution

Published Sep 24, 2025
CVE-2018-1999024MEDIUM

Macro in MathJax running untrusted Javascript within a web browser

Published Jul 27, 2018
CVE-2017-16061HIGH

tkinter is malware

Published Nov 1, 2018
MAL-2024-8822

Malicious code in tappp-tv-ui-lib (npm)

Published Sep 5, 2024
CVE-2020-7712HIGH

trentm/json vulnerable to command injection

Published May 6, 2021
CVE-2026-30947

Parse Server has a bypass of class-level permissions in LiveQuery

Published Mar 11, 2026
CVE-2018-3731HIGH

Path Traversal in public

Published Jul 18, 2018
CVE-2026-28363

OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode

Published Mar 3, 2026
CVE-2023-2850MEDIUM

Unintentional leakage of private information via cross-origin websocket session hijacking

Published Jul 25, 2023
CVE-2026-28446

OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)

Published Feb 17, 2026
MAL-2024-8867

Malicious code in node-integration-test (npm)

Published Sep 11, 2024
MAL-2024-8868

Malicious code in passports-js (npm)

Published Sep 11, 2024
CVE-2016-1000238

Spoofing attack due to unvalidated KDC in node-krb5

Published Sep 1, 2020
CVE-2018-1002204MEDIUM

Arbitrary File Write in adm-zip

Published Jul 27, 2018
GHSA-3f6h-2hrp-w5wx

@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

Published Apr 10, 2026
MAL-2024-8895

Malicious code in bamoe-standalone-dmn-editor (npm)

Published Sep 18, 2024
CVE-2022-23623HIGH

Validation bypass in frourio

Published Feb 7, 2022
GHSA-72c6-fx6q-fr5w

@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

Published Apr 16, 2026
CVE-2017-16224MEDIUM

Open Redirect in st

Published Aug 6, 2018
MAL-2022-1068

Malicious code in app_intelligence (npm)

Published Jun 20, 2022
MAL-2026-1368

Malicious code in json-specparse (npm)

Published Mar 12, 2026
CVE-2026-22818

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

Published Jan 13, 2026
CVE-2026-33131

h3 has a middleware bypass with one gadget

Published Mar 18, 2026
CVE-2022-24717MEDIUM

Cross Site Scripting (XSS) in @finastra/ssr-pages

Published Mar 1, 2022
CVE-2022-37257CRITICAL

steal vulnerable to Prototype Pollution via requestedVersion variable

Published Sep 16, 2022
CVE-2025-25977

canvg Prototype Pollution vulnerability

Published Mar 10, 2025
MAL-2024-8943

Malicious code in ml-translate-vis (npm)

Published Sep 22, 2024
CVE-2026-0540

DOMPurify contains a Cross-site Scripting vulnerability

Published Mar 3, 2026
CVE-2017-16068HIGH

ffmepg is malware

Published Aug 29, 2018
CVE-2020-8215HIGH

Buffer overflow in canvas

Published May 7, 2021
CVE-2026-24001

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Published Jan 14, 2026
CVE-2025-61686

React Router has Path Traversal in File Session Storage

Published Jan 8, 2026
CVE-2021-23434MEDIUM

Prototype Pollution in object-path

Published Sep 1, 2021
MAL-2024-9006

Malicious code in inclusive-ai-dao-website (npm)

Published Sep 27, 2024
CVE-2025-57164

FlowiseAI Pre-Auth Arbitrary Code Execution

Published Sep 15, 2025
CVE-2024-57066

@ndhoule/defaults prototype pollution

Published Feb 6, 2025
CVE-2026-34773MEDIUM
Risk: 23.51/100

Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

Published Apr 3, 2026
CVE-2026-27203

eBay API MCP Server Affected by Environment Variable Injection

Published Feb 19, 2026
CVE-2022-36077HIGH

Exfiltration of hashed SMB credentials on Windows via file:// redirect

Published Nov 10, 2022
CVE-2025-59057

React Router has XSS Vulnerability

Published Jan 8, 2026
MAL-2024-9050

Malicious code in hedgedoc-api (npm)

Published Sep 30, 2024
CVE-2019-20920HIGH

Arbitrary Code Execution in Handlebars

Published Feb 10, 2022
CVE-2025-31476

tarteaucitron.js allows url scheme injection via unfiltered inputs

Published Apr 7, 2025
CVE-2022-31150MEDIUM

undici before v5.8.0 vulnerable to CRLF injection in request headers

Published Jul 21, 2022
CVE-2022-29823CRITICAL

Feather-Sequelize cleanQuery method vulnerable to Prototype Pollution

Published Oct 26, 2022
CVE-2024-34708MEDIUM

Directus allows redacted data extraction on the API through "alias"

Published May 13, 2024
CVE-2020-7626CRITICAL

karma-mojo enables OS Command Injection

Published Feb 10, 2022
CVE-2020-7779MEDIUM

Regular Expression Denial of Service in djvalidator

Published Feb 9, 2022
CVE-2017-16053HIGH

fabric-js is malware

Published Jul 23, 2018
MAL-2024-9090

Malicious code in hilla-components-dependencies (npm)

Published Oct 4, 2024
CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
CVE-2025-69264

pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

Published Jan 7, 2026
CVE-2022-24433HIGH

Command injection in simple-git

Published Mar 12, 2022
MAL-2022-107

Malicious code in @azure-tests/perf-monitor-query (npm)

Published Jun 20, 2022
MAL-2024-9118

Malicious code in 29ge1l (npm)

Published Oct 9, 2024
CVE-2025-59536

Claude Code can execute commands prior to the startup trust dialog

Published Oct 3, 2025
CVE-2026-28486

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

Published Mar 2, 2026
CVE-2022-2216CRITICAL

Server-Side Request Forgery in parse-url

Published Jun 28, 2022
CVE-2016-1000226

Cross-Site Scripting in swagger-ui

Published Sep 1, 2020
CVE-2026-32000

OpenClaw has command injection via Windows shell fallback in Lobster tool execution

Published Mar 3, 2026
CVE-2020-8244MEDIUM

Remote Memory Exposure in bl

Published Sep 2, 2020
MAL-2022-4659

Malicious code in mock-solc-0.6 (npm)

Published Jun 8, 2022
MAL-2024-11088

Malicious code in seller-webchat-service (npm)

Published Nov 27, 2024
CVE-2025-54073

mcp-package-docs vulnerable to command injection in several tools

Published Aug 5, 2025
CVE-2022-25848HIGH

static-dev-server vulnerable to path traversal

Published Nov 29, 2022
CVE-2026-3455

mailparser vulnerable to Cross-site Scripting

Published Mar 3, 2026
GHSA-3fv3-6p2v-gxwj

OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths

Published Apr 9, 2026
CVE-2024-53983

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

Published Dec 2, 2024
MAL-2022-3611

Malicious code in here_base (npm)

Published Jun 20, 2022
CVE-2023-28103HIGH

Prototype pollution in matrix-react-sdk

Published Mar 29, 2023
MAL-2025-4337

Malicious code in e-learning-garena (npm)

Published May 23, 2025
MAL-2025-4344

Malicious code in fc-accordion (npm)

Published May 23, 2025
CVE-2025-56515

Fiora chat group avatar is vulnerable to XSS via SVG files

Published Oct 1, 2025
CVE-2023-35931LOW

Shescape potential environment variable exposure on Windows with CMD

Published Jun 22, 2023
CVE-2026-25547

@isaacs/brace-expansion has Uncontrolled Resource Consumption

Published Feb 3, 2026
CVE-2025-69211

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

Published Dec 30, 2025
CVE-2024-38987MEDIUM

@aofl/cli-lib Prototype Pollution vulnerability

Published Jul 1, 2024
MAL-2024-9169

Malicious code in new-code-script-gt-a-samp-h-a-c-k-down-lo-ad-lkk02y (npm)

Published Oct 9, 2024
CVE-2026-26319

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Published Feb 17, 2026
CVE-2026-30921

OneUptime: Synthetic Monitor RCE via exposed Playwright browser object

Published Mar 7, 2026
CVE-2020-24939HIGH

Prototype pollution in supermixer

Published Dec 10, 2021
MAL-2025-3140

Malicious code in ac-async-helpers (npm)

Published Apr 7, 2025
MAL-2025-47058

Malicious code in epxressoo (npm)

Published Sep 11, 2025
CVE-2020-19850MEDIUM

Directus API vulnerable to denial of service

Published Apr 4, 2023
CVE-2025-59343

tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball

Published Sep 24, 2025
GHSA-3h2q-j2v4-6w5r

OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappers

Published Mar 9, 2026
CVE-2026-33713

n8n has SQL Injection in Data Table Node via orderByColumn Expression

Published Mar 26, 2026
CVE-2025-62410

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

Published Oct 15, 2025
MAL-2025-3864

Malicious code in yamoney-guidelines (npm)

Published May 16, 2025
MAL-2026-3158

Malicious code in apple-internal-pki-trust (npm)

Published Apr 29, 2026
MAL-2026-3209

Malicious code in apple-internal-security-library-v99 (npm)

Published May 1, 2026
MAL-2026-3215

Malicious code in archetype-style (npm)

Published May 1, 2026
CVE-2024-37890HIGH

ws affected by a DoS when handling a request with many HTTP headers

Published Jun 17, 2024
CVE-2017-16063HIGH

node-opensl is malware

Published Oct 3, 2018
CVE-2016-10649HIGH

frames-compiler downloads Resources over HTTP

Published Sep 1, 2020
CVE-2026-3449

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

Published Mar 3, 2026
CVE-2026-32053

OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized per parse

Published Mar 3, 2026
CVE-2022-25907HIGH

ts-deepmerge before 2.0.2 vulnerable to Prototype Pollution

Published Aug 10, 2022
CVE-2020-8137CRITICAL

Code injection in blamer

Published May 6, 2021
MAL-2025-4355

Malicious code in gop_status_frontend (npm)

Published May 23, 2025
CVE-2021-40663CRITICAL

Prototype Pollution in deep.assign

Published Jul 1, 2022
CVE-2026-32019

OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard

Published Mar 4, 2026
CVE-2026-33287

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

Published Mar 25, 2026
CVE-2017-16155HIGH

Directory Traversal in fast-http-cli

Published Jul 23, 2018
CVE-2024-43035MEDIUM

Fonoster is vulnerable to directory traversal

Published Mar 5, 2026
MAL-2022-1511

Malicious code in bfs-hello-world (npm)

Published Jun 20, 2022
GHSA-vr6p-vq2p-6j74

Withdrawn Advisory: LikeC4 has RCE through vulnerable React and Next.js versions

Published Dec 15, 2025
CVE-2026-25533

Sandbox escape via infinite recursion and error objects

Published Feb 5, 2026
MAL-2022-1512

Malicious code in bfvcjmwgayetoizd (npm)

Published Jul 11, 2022
MAL-2024-9276

Malicious code in o-typography (npm)

Published Oct 11, 2024
CVE-2026-33943

Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code

Published Mar 26, 2026
MAL-2025-4357

Malicious code in gunbazaar (npm)

Published May 23, 2025
MAL-2025-4567

Malicious code in log5j-v2 (npm)

Published May 26, 2025
MAL-2025-48924

Malicious code in energy-portal (npm)

Published Oct 28, 2025
CVE-2026-28470

OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes

Published Feb 17, 2026
CVE-2021-4326LOW

Imperative CLI vulnerable to Command Injection

Published Mar 1, 2023
CVE-2021-41182MEDIUM

XSS in the `altField` option of the Datepicker widget in jquery-ui

Published Oct 26, 2021
MAL-2022-1070

Malicious code in appboy (npm)

Published Jun 20, 2022
CVE-2020-7686HIGH

Directory traversal in rollup-plugin-server

Published Jul 29, 2020
CVE-2022-24822HIGH

Denial of Service vulnerability in @podium/layout and @podium/proxy

Published Apr 7, 2022
GHSA-9gp8-hjxr-6f34

OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls

Published Apr 3, 2026
CVE-2024-46488

Heap-based Buffer Overflow in sqlite-vec

Published Sep 25, 2024
MAL-2024-9277

Malicious code in opti-distube (npm)

Published Oct 11, 2024
MAL-2024-9278

Malicious code in ts-jest-starter-kit (npm)

Published Oct 11, 2024
MAL-2025-47063

Malicious code in hrpdesign (npm)

Published Sep 9, 2025
MAL-2025-47347

Malicious code in rxnt-kue (npm)

Published Sep 16, 2025
CVE-2026-24768

NocoDB has Unvalidated Redirect in Login Flow via continueAfterSignIn Parameter

Published Jan 28, 2026
GHSA-vrhm-gvg7-fpcf

Memory exhaustion in SvelteKit remote form deserialization (experimental only)

Published Feb 19, 2026
MAL-2022-1107

Malicious code in arm-storsimple8000series (npm)

Published Jun 20, 2022
CVE-2021-24044CRITICAL

Access of Resource Using Incompatible Type in Hermes

Published Jan 16, 2022
CVE-2025-66479

Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing

Published Dec 4, 2025
MAL-2024-9310

Malicious code in 4tj82n (npm)

Published Oct 16, 2024
MAL-2025-47888

Malicious code in lovable-react (npm)

Published Oct 2, 2025
CVE-2020-7625CRITICAL

Injection in op-browser

Published Feb 10, 2022
MAL-2025-6098

Malicious code in indexer-worker-service (npm)

Published Jul 21, 2025
MAL-2025-61

Malicious code in express-v4 (npm)

Published Jan 5, 2025
MAL-2025-610

Malicious code in cscchokidar-next (npm)

Published Jan 21, 2025
MAL-2024-9320

Malicious code in a-lbum-do-wnload-avai-lable-file-261573-generations-do7io-mdogom (npm)

Published Oct 16, 2024
CVE-2026-24006

Seroval affected by Denial of Service via Deeply Nested Objects

Published Jan 22, 2026
CVE-2020-7787HIGH

Improper Authentication in react-adal

Published Apr 13, 2021
GHSA-9h9m-rr67-9jpg

coursevault-preview has a path traversal due to improper base-directory boundary validation

Published Apr 8, 2026
CVE-2026-1526

Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

Published Mar 13, 2026
GHSA-9hjh-fr4f-gxc4

OpenClaw: Gateway Backend Reconnect lets Non-Admin Operator Scopes Self-Claim operator.admin

Published Mar 27, 2026
MAL-2025-4905

Malicious code in vite-plugin-svgn (npm)

Published Jun 10, 2025
CVE-2026-23733

Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)

Published Jan 20, 2026
MAL-2025-49077

Malicious code in zeus-me-ops-tool (npm)

Published Oct 29, 2025
CVE-2026-32094

Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash

Published Mar 11, 2026
CVE-2016-1000237MEDIUM

Cross-Site Scripting in sanitize-html

Published Apr 16, 2020
MAL-2025-49078

Malicious code in zeus-mex-user-profile (npm)

Published Oct 29, 2025
CVE-2025-30360

webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser

Published Jun 4, 2025
GHSA-3j8v-cgw4-2g6q

fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)

Published Apr 9, 2026
CVE-2021-41174MEDIUM

XSS vulnerability allowing arbitrary JavaScript execution

Published Nov 8, 2021
CVE-2015-6584MEDIUM

DataTable Vulnerable to Cross-Site Scripting

Published Aug 31, 2020
CVE-2021-25979CRITICAL

Apostrophe CMS Insufficient Session Expiration vulnerability

Published Nov 10, 2021
MAL-2024-9334

Malicious code in ava-ilable-down-load-mp3-today-2013-10071-pure-heroine-vldvc-oyqobe (npm)

Published Oct 16, 2024
CVE-2016-10633HIGH

dwebp-bin downloads Resources over HTTP

Published Feb 18, 2019
MAL-2026-476

Malicious code in @transaction-list/transaction-list-xs (npm)

Published Jan 23, 2026
CVE-2013-2022MEDIUM

jplayer Cross Site Scripting vulnerability

Published May 17, 2022
CVE-2024-1648HIGH

Cross-site Scripting in electron-pdf

Published Feb 20, 2024
CVE-2026-32052

OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text

Published Mar 3, 2026
MAL-2024-9350

Malicious code in do-wnload-available-67250-from-gardens-where-we-feel-secure-1-zuhte-cbguim (npm)

Published Oct 16, 2024
CVE-2021-32804HIGH

Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization

Published Aug 3, 2021
MAL-2025-7075

Malicious code in @amber-team/stylelint-config (npm)

Published Aug 14, 2025
MAL-2024-9351

Malicious code in do-wnload-available-88507-inheaven-dfkvm-eunrso (npm)

Published Oct 16, 2024
CVE-2021-27515MEDIUM

Path traversal in url-parse

Published May 6, 2021
CVE-2020-7679HIGH

Improperly Controlled Modification of Dynamically-Determined Object Attributes in casperjs

Published May 17, 2021
MAL-2024-9358

Malicious code in down-lo-ad-now-zip-mp3-sonic-nurse-a1wgm-jqylaq (npm)

Published Oct 16, 2024
MAL-2022-1119

Malicious code in arm-webservices (npm)

Published Jun 20, 2022
MAL-2022-112

Malicious code in @azure-tests/perf-storage-blob-track-1 (npm)

Published Jun 20, 2022
GHSA-3jx4-q2m7-r496

OpenClaw: Hardlink alias checks could bypass workspace-only file boundaries in specific configurations

Published Mar 4, 2026
CVE-2026-28465

OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations

Published Feb 17, 2026
MAL-2024-9359

Malicious code in down-lo-ad-now-zip-mp3-the-whole-love-f2ts8-cblkgz (npm)

Published Oct 16, 2024
CVE-2020-28460MEDIUM

Prototype pollution in multi-ini

Published Apr 13, 2021
CVE-2026-29784

Ghost has incomplete CSRF protections around OTC use

Published Mar 5, 2026
MAL-2025-7076

Malicious code in @amber-team/tsconfig (npm)

Published Aug 14, 2025
CVE-2019-5423HIGH

Path Traversal in http-live-simulator

Published Apr 8, 2019
CVE-2026-32046

OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser container

Published Mar 3, 2026
MAL-2024-9362

Malicious code in down-load-available-zip-now-365509-chew-the-scenery-ymqd7-xaqqmu (npm)

Published Oct 16, 2024
CVE-2026-24472

Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception

Published Jan 27, 2026
CVE-2022-3783LOW

node-red-dashboard vulnerable to Cross-site Scripting

Published Nov 1, 2022
GHSA-392f-ggf5-fp3c

OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

Published Mar 2, 2026
MAL-2026-272

Malicious code in chakra-ui-2--react (npm)

Published Jan 16, 2026
GHSA-9p93-7j67-5pc2

OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding

Published Mar 27, 2026
CVE-2021-32673HIGH

Remote Command Execution in reg-keygen-git-hash-plugin

Published Jun 8, 2021
CVE-2022-24709HIGH

Cross site scripting in @awsui/components-react

Published Feb 25, 2022
MAL-2024-9382

Malicious code in mp3-file-zip-d-ownload-33971-the-imagination-stage-ar0bb-cvzjxl (npm)

Published Oct 16, 2024
CVE-2018-3771MEDIUM

statics-server Cross-site Scripting vulnerability

Published May 13, 2022
CVE-2018-15494CRITICAL

dojox vulnerable to unescaped string injection

Published Oct 15, 2018
CVE-2023-43794MEDIUM

nocodb SQL Injection vulnerability

Published Oct 17, 2023
GHSA-68v4-hmwv-f43h

OpenClaw: Media download follows cross-origin redirects with Authorization headers intact

Published Apr 3, 2026
CVE-2017-16147HIGH

Directory Traversal in shit-server

Published Sep 1, 2020
MAL-2026-3232

Malicious code in codewhisperer-streaming (npm)

Published May 2, 2026
Check your entire dependency tree at onceRun dependency scan →