ini
213 known vulnerabilities · 2 critical · 13 high
ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse
Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
Malicious code in @diotoborg/cum-saepe-minima (npm)
OpenZeppelin Contracts initializer reentrancy may lead to double initialization
Malicious code in paypay-ecommerce-miniapp (npm)
Incorrect Handling of Non-Boolean Comparisons During Minification in uglify-js
Malicious code in @cplace-paw-fe/cf-training-extended (npm)
Malicious code in training-kit (npm)
Malicious code in training-platform-web (npm)
Malicious code in gemini-adapter (npm)
Malicious code in spotify-event-definitions (npm)
Malicious code in theme_dbtraining (npm)
parse-ini is vulnerable to Prototype Pollution in index.js()
Malicious code in administracja_reklamowa (npm)
Malicious code in dwux-init (npm)
Secret disclosure when containing characters that become URI encoded
Malicious code in minimal-ts-webpack (npm)
Malicious code in bender-event-definition-loader (npm)
Malicious code in suchinind (npm)
Malicious code in authinit (npm)
Malicious code in cloudsplaining (npm)
Modified package published to npm, containing malware that exfiltrates private key material
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
Malicious code in @google-pay-trust/finish (npm)
Malicious code in minipay-minidapps (npm)
Malicious code in ckeditor5-minimap (npm)
Malicious code in training-client (npm)
Malicious code in gemini-test (npm)
tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload
Duplicate Advisory: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter
Malicious code in @google-pay-trust/init-google-pay (npm)
Malicious code in com.unity.render-pipelines.high-definition-config (npm)
Malicious code in @antv/x6-plugin-minimap (npm)
Malicious code in @service-suppliers/fetch-initial-suppliers-watcher-saga (npm)
Malicious code in @service-suppliers/fetch_initial_suppliers_action_saga (npm)
Malicious code in @service-suppliers/set_initial_loaded (npm)
Malicious code in azure-purview-administration (npm)
OpenClaw: Shell init-file options could satisfy exec allowlist script matching
Malicious code in identity-module-miniapp (npm)
Malicious code in imagecompress-mini (npm)
Malicious code in trinity-pkg-ss (npm)
Malicious code in 6ini (npm)
Malicious code in ninimis (npm)
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
Malicious code in purplebricks-administration (npm)
Malicious code in shuup-definite-theme (npm)
Malicious code in project-init-tools (npm)
Malicious code in minikit-monorepo (npm)
Malicious code in minicom-node (npm)
Malicious code in minimhc (npm)
Malicious code in minimum-flow-parser (npm)
Malicious code in @momo-miniapp/apix (npm)
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
Malicious code in @zitterorg/reiciendis-minima-excepturi (npm)
Malicious code in @diotoborg/minima-omnis (npm)
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
smol-toml: Denial of Service via TOML documents containing thousands of consecutive commented lines
evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API
Malicious code in @zitterorg/tempore-debitis-minima (npm)
Malicious code in manual-billing-system-miniapp-api (npm)
Malicious code in get-your-sht-together-how-to-stop-worrying-about-what-you-should-do-so-you-can-finish-what-you-need- (npm)
OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter
OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions
Malicious code in init-router (npm)
Malicious code in paytm-mini-programs-nodejs-sdk (npm)
Malicious code in eslintplunginimpwrt (npm)
Malicious code in node-db-init (npm)
Malicious code in gemini-ai-checker (npm)
Malicious code in gemini-cli-vscode-ide-companion (npm)
Malicious code in exclusiveminimum (npm)
Malicious code in aboba-initial (npm)
conf-cfg-ini Prototype Pollution via malicious INI file before v1.2.2
js-ini Prorotype Pollution when malicious INI files submitted to an application that parses it with `parse`
Malicious code in o-autoinit (npm)
Malicious code in minimal-mistakes (npm)
Malicious code in vue3-infinite-scroll (npm)
Malicious code in korea-administrative-area-geo-json-util (npm)
Malicious code in initial-path (npm)
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Malicious code in initappd (npm)
Malicious code in chawla-init-3 (npm)
Malicious code in apinitro (npm)
Malicious code in minification (npm)
Malicious code in shop-minis-docs (npm)
Malicious code in ngx-infinite-scroll-fixed (npm)
Malicious code in executable-stories-init (npm)
`chainId` may be outdated if user changes chains as part of connection in @web3-react
Malicious code in o7nyfinished (npm)
Malicious code in babpuuginimport (npm)
Malicious code in minicom-support-client (npm)
Malicious code in picking-miniapp (npm)
Malicious code in azure-purview-administration-samples-js (npm)
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Malicious code in twinit-cdk (npm)
Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS
Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer
file-type vulnerable to Infinite Loop via malformed MKV file
Malicious code in digitalexp-datasource-definitions (npm)
Malicious code in init-spa (npm)
Malicious code in mini-builder (npm)
Malicious code in woocommerce-infinitepay (npm)
Malicious code in xverginia4u (npm)
@claviska/jquery-minicolors vulnerable to Cross-site Scripting
Malicious code in avail-able-albu-m-down-load-114925-rainier-fog-nuh7o-acneyh (npm)
Malicious code in raydium-sdk-liquidity-init (npm)
Malicious code in gemini-internal (npm)
Malicious code in vscode-spring-initializr (npm)
MongoDB Driver may publish events containing authentication-related data
Malicious code in @apple-pay-trust/finish (npm)
Malicious code in inipyrser (npm)
Malicious code in init-epic-link-multiselect (npm)
jsrsasign: Division by Zero Allows Invalid JWK Modulus to Cause Deterministic Zero Output in RSA Operations
image-size Denial of Service via Infinite Loop during Image Processing
ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`
Malicious code in intrinio-adapter (npm)
Malicious code in @infinid-indonesia/ui-kit (npm)
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
Malicious code in @cloudplatform-single-spa/svp-anti-affinity (npm)
Malicious code in @zitterorg/nihil-illo-minima (npm)
Malicious code in @ikyyofc/gemini-cli (npm)
Malicious code in minicssextractpluin (npm)
Malicious code in smeeh-administration (npm)
Malicious code in chai-as-init (npm)
Malicious code in situs-bocoran-rtp-live-bocoran-agen-judi-rtp-slot-hari-ini-terpercaya (npm)
Malicious code in @momo-miniapp/api (npm)
Malicious code in htmlminifire (npm)
Malicious code in the-self-taught-programmer-the-definitive-guide-to-programming-professionally-by-cory-althoff-on-kin (npm)
Malicious code in @bcs-bank/init (npm)
Malicious code in transform-minify-booleans (npm)
Malicious code in minify-replace (npm)
Malicious code in initializers (npm)
Malicious code in @google-pay-trust/init-google-pay-result (npm)
Malicious code in postcss-minify-selector (npm)
Malicious code in gemini-dev (npm)
Malicious code in miniprogram-project (npm)
Malicious code in sample-mini (npm)
Malicious code in gemini-exports (npm)
Malicious code in @lbnqduy11805/miniature-garbanzo (npm)
Malicious code in @lbnqduy11805/miniature-train (npm)
LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader
Malicious code in @juiggitea/earum-in-minima-maiores (npm)
Clerk has an authorization bypass when combining organization, billing, or reverification checks
Malicious code in deferred-initialization (npm)
node-tar has a race condition leading to uninitialized memory exposure
Malicious code in gemini-main (npm)
OpenClaw: Sandboxed sessions_spawn(runtime="acp") bypassed sandbox inheritance and allowed host ACP initialization
Malicious code in redux-init (npm)
file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header
Malicious code in pear-apps-utils-avatar-initials (npm)
Malicious code in minify-mangle-names (npm)
Malicious code in mini-suggest (npm)
Malicious code in blahblahblah-definitely-not-a-real-package-name (npm)
Malicious code in @juiggitea/sapiente-soluta-minima-fuga (npm)
Malicious code in arcademinigame (npm)
Malicious code in @zitterorg/minima-magnam (npm)
Convict has prototype pollution via load(), loadFile(), and schema initialization
SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials
Malicious code in cors-init (npm)
Malicious code in segment-anything-mini-demo (npm)
Malicious code in initial-path21 (npm)
Malicious code in initial-path32 (npm)
Malicious code in adobe-alloy-mini-site (npm)
Malicious code in @antv/l7-mini (npm)
Malicious code in miniapp-api (npm)
Malicious code in @juiggitea/minima-iure-necessitatibus-corporis (npm)
Malicious code in init-discord (npm)
Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
Malicious code in open-telemetry-mini-client (npm)
Malicious code in @diotoborg/doloribus-minima-velit (npm)
Malicious code in shop-minis (npm)
Malicious code in chainix (npm)
Malicious code in turbiniactl-status (npm)
Malicious code in stripe-cli-init-plugin (npm)
Malicious code in @mastra/voice-google-gemini-live (npm)
Malicious code in @juiggitea/minima-illum-deserunt (npm)
ws: Uninitialized memory disclosure
Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader
Malicious code in minis-samples (npm)
Malicious code in plugin-bugfix-v8-spread-parameters-in-optional-chaining (npm)
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
Malicious code in @xfinity/fetlife-assets (npm)
Malicious code in @cloudplatform-single-spa/administration (npm)
Malicious code in purview-administration (npm)
Duplicate Advisory: gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
Malicious code in postcss-minify-selector-parser (npm)
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
Malicious code in @diotoborg/rem-minima (npm)
Malicious code in initidiscord (npm)
Malicious code in iron-shield-miniapp (npm)
Malicious code in actionbars-infinitescroll-searchbar (npm)
Malicious code in interaction-photos-infinitescroll (npm)