OsVault/npm/nes
npm4 critical

nes

165 known vulnerabilities · 4 critical · 10 high

CVE-2017-16025MEDIUM

Denial of Service in nes

Published Jul 24, 2018
CVE-2023-26135HIGH

flatnest Prototype Pollution vulnerability

Published Jun 30, 2023
MAL-2025-191359

Malicious code in @voiceflow/nestjs-rate-limit (npm)

Published Nov 25, 2025
CVE-2022-29257MEDIUM

AutoUpdater module fails to validate certain nested components of the bundle

Published Jun 16, 2022
GHSA-5jg4-p4qw-cgfr

@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags

Published Apr 4, 2026
CVE-2026-22176

OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 3, 2026
GHSA-fvx6-pj3r-5q4q

OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 6, 2026
CVE-2022-31069MEDIUM

Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
GHSA-rf75-g96h-j3rm

Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 2, 2026
CVE-2025-69211

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

Published Dec 30, 2025
MAL-2025-3864

Malicious code in yamoney-guidelines (npm)

Published May 16, 2025
CVE-2026-24006

Seroval affected by Denial of Service via Deeply Nested Objects

Published Jan 22, 2026
CVE-2018-15494CRITICAL

dojox vulnerable to unescaped string injection

Published Oct 15, 2018
CVE-2013-7379MEDIUM

API Admin Auth Weakness in tomato

Published Aug 31, 2020
CVE-2026-32944

Parse Server crash via deeply nested query condition operators

Published Mar 17, 2026
CVE-2020-28283CRITICAL

Prototype pollution vulnerability in 'libnested'

Published Oct 12, 2021
CVE-2022-25352HIGH

Prototype Pollution in libnested

Published Mar 18, 2022
MAL-2026-2737

Malicious code in business-data (npm)

Published Apr 16, 2026
MAL-2022-1362

Malicious code in azure-pipelines-dependency-track (npm)

Published Jun 1, 2022
CVE-2025-15536

Open Chinese Convert has Out-of-bounds Write

Published Jan 18, 2026
CVE-2026-31856

Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL

Published Mar 11, 2026
CVE-2019-16303CRITICAL

JHipster Kotlin using insecure source of randomness `RandomStringUtils` before v1.2.0

Published Jun 26, 2020
GHSA-82gw-wqw6-r2cf

Duplicate Advisory: Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 19, 2026
CVE-2020-15131HIGH

False-positive validity for NFT1 genesis transactions

Published Jul 30, 2020
MAL-2022-2101

Malicious code in com.unity.render-pipelines.high-definition-config (npm)

Published May 16, 2022
MAL-2022-2113

Malicious code in comcast.business.web.ui.trident (npm)

Published Jun 20, 2022
MAL-2022-2116

Malicious code in commandlinesage (npm)

Published Aug 19, 2022
CVE-2022-31070MEDIUM

Potential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
CVE-2026-33331

oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify

Published Mar 20, 2026
MAL-2022-2474

Malicious code in dinesh-dev-nagajikkktest11223qa (npm)

Published Jun 20, 2022
CVE-2026-34211HIGH
Risk: 50.42/100

SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser

Published Apr 3, 2026
GHSA-7q64-3rg2-h9pf

Duplicate Advisory: Nest has a Fastify URL Encoding Middleware Bypass

Published Feb 27, 2026
GHSA-7q9x-8g6p-3x75

@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template

Published Mar 25, 2026
MAL-2022-5517

Malicious code in pug-web-readiness (npm)

Published Jul 26, 2022
MAL-2022-132

Malicious code in @bmw-chris/onlinesession-default-frontend (npm)

Published Jun 20, 2022
MAL-2022-2961

Malicious code in facebook-nodejs-business-sdk-tests (npm)

Published Jun 20, 2022
MAL-2022-226

Malicious code in @edwardjones/fetlife-assets (npm)

Published Jun 20, 2022
CVE-2026-35515
Risk: 44.14/100

@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')

Published Apr 6, 2026
CVE-2015-9240HIGH

Authentication Weakness in keystone

Published Jun 7, 2018
CVE-2026-22178

OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction

Published Mar 2, 2026
MAL-2023-186

Malicious code in cms-businesslogic (npm)

Published Mar 15, 2023
MAL-2022-247

Malicious code in @epc-libraries/kinesis-service (npm)

Published May 16, 2022
MAL-2024-58

Malicious code in @linesearch/swiper (npm)

Published Jan 10, 2024
CVE-2026-33532

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Published Mar 25, 2026
CVE-2021-23425MEDIUM

Uncontrolled Resource Consumption in trim-off-newlines

Published Sep 2, 2021
MAL-2023-725

Malicious code in react-liveness (npm)

Published Jun 23, 2023
CVE-2026-33128

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

Published Mar 18, 2026
MAL-2024-7157

Malicious code in @zitterorg/deserunt-nesciunt (npm)

Published Jul 4, 2024
MAL-2024-7459

Malicious code in nesiahanzz (npm)

Published Jul 11, 2024
CVE-2021-23329HIGH

Prototype pollution in nested-object-assign

Published Feb 1, 2021
CVE-2026-27576

OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs

Published Feb 20, 2026
CVE-2020-15130HIGH

False-positive validity for NFT1 genesis transactions in SLPJS

Published Jul 30, 2020
GHSA-cjq8-m7wj-xmq9

Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 21, 2026
CVE-2023-26108LOW

@nestjs/core vulnerable to Information Exposure via StreamableFile pipe

Published Mar 6, 2023
MAL-2024-8104

Malicious code in @diotoborg/accusamus-nesciunt (npm)

Published Sep 2, 2024
CVE-2022-35917MEDIUM

Solana Pay Vulnerable to Weakness in Transfer Validation Logic

Published Aug 6, 2022
MAL-2025-1578

Malicious code in cmp-ocr-liveness-acquisition (npm)

Published Feb 28, 2025
MAL-2024-7280

Malicious code in @zitterorg/mollitia-laborum-nesciunt (npm)

Published Jul 4, 2024
GHSA-v3rj-xjv7-4jmq

smol-toml: Denial of Service via TOML documents containing thousands of consecutive commented lines

Published Mar 25, 2026
MAL-2025-1362

Malicious code in genesys-richmedia (npm)

Published Feb 13, 2025
MAL-2025-191361

Malicious code in @voiceflow/nestjs-timeout (npm)

Published Nov 25, 2025
MAL-2024-8240

Malicious code in @diotoborg/dolore-nesciunt (npm)

Published Sep 2, 2024
MAL-2023-187

Malicious code in cms-businesslogic-extensions (npm)

Published Mar 15, 2023
CVE-2024-47875

DOMpurify has a nesting-based mXSS

Published Oct 11, 2024
CVE-2025-68115

Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables

Published Dec 16, 2025
MAL-2025-2114

Malicious code in link-outside-nest (npm)

Published Mar 4, 2025
MAL-2025-2674

Malicious code in generate_genesis_values (npm)

Published Mar 25, 2025
CVE-2026-32058

OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 2, 2026
CVE-2021-25947CRITICAL

Prototype pollution in nestie

Published Jun 7, 2021
MAL-2026-2655

Malicious code in tailwind-lines-clamp (npm)

Published Apr 14, 2026
CVE-2026-30938

Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement

Published Mar 10, 2026
CVE-2026-2293

Nest has a Fastify URL Encoding Middleware Bypass

Published Mar 2, 2026
CVE-2017-16031HIGH

Insecure randomness in socket.io

Published Nov 7, 2018
CVE-2023-48219MEDIUM

TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes

Published Nov 15, 2023
MAL-2022-5009

Malicious code in obyte-witness (npm)

Published Jul 18, 2022
MAL-2022-5660

Malicious code in react-nesting-example-legacy (npm)

Published Nov 14, 2022
CVE-2026-33011

Nest Fastify HEAD Request Middleware Bypass

Published Mar 17, 2026
MAL-2025-191360

Malicious code in @voiceflow/nestjs-redis (npm)

Published Nov 25, 2025
MAL-2025-191010

Malicious code in set-nested-prop (npm)

Published Nov 24, 2025
CVE-2026-33941

Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

Published Mar 27, 2026
CVE-2024-48949

Elliptic's verify function omits uniqueness validation

Published Oct 10, 2024
MAL-2025-190944

Malicious code in wellness-expert-ng-gallery (npm)

Published Nov 24, 2025
MAL-2022-2058

Malicious code in com.unity.editorcoroutines (npm)

Published Jun 20, 2022
MAL-2022-1727

Malicious code in bulldog-e-business (npm)

Published Jul 26, 2022
MAL-2025-3732

Malicious code in com.unity.render-pipelines.universal-config (npm)

Published May 11, 2025
MAL-2022-3562

Malicious code in harness-helm-plugin (npm)

Published Oct 5, 2022
CVE-2021-33623HIGH

Uncontrolled Resource Consumption in trim-newlines

Published Jun 7, 2021
GHSA-hpwf-8g29-85qm

Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)

Published Apr 14, 2026
MAL-2022-571

Malicious code in @sbbol/business (npm)

Published Jun 20, 2022
MAL-2022-3104

Malicious code in forge-app-bones (npm)

Published Jul 21, 2022
MAL-2022-7014

Malicious code in vzyfxaumldnesjor (npm)

Published Jul 11, 2022
MAL-2022-5422

Malicious code in possnested (npm)

Published Aug 19, 2022
GHSA-qx2v-qp2m-jg93

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Published Apr 24, 2026
MAL-2025-4549

Malicious code in @stepstone-genesis/components (npm)

Published May 24, 2025
CVE-2026-27904

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

Published Feb 26, 2026
MAL-2022-257

Malicious code in @exness/select-component-ab (npm)

Published Jun 20, 2022
MAL-2025-199

Malicious code in kubeflow-pipelines (npm)

Published Jan 20, 2025
CVE-2026-30830

defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag

Published Mar 6, 2026
MAL-2022-258

Malicious code in @exnessimo/style (npm)

Published Jun 20, 2022
CVE-2026-34769HIGH
Risk: 38.51/100

Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference

Published Apr 3, 2026
MAL-2026-1519

Malicious code in import-newlines (npm)

Published Mar 16, 2026
MAL-2022-1687

Malicious code in broccolifuknnes (npm)

Published Aug 19, 2022
MAL-2022-2115

Malicious code in commandinesrgs (npm)

Published Aug 19, 2022
MAL-2022-6194

Malicious code in snyk-azure-pipelines-task (npm)

Published Jun 20, 2022
MAL-2024-8460

Malicious code in @diotoborg/nesciunt-ullam (npm)

Published Sep 2, 2024
MAL-2025-6379

Malicious code in vite-postcss-nested (npm)

Published Jul 30, 2025
MAL-2026-3116

Malicious code in @business_promocode/apply_promocode (npm)

Published Apr 27, 2026
MAL-2026-3117

Malicious code in @business_promocode/cancel_promocode (npm)

Published Apr 27, 2026
MAL-2026-1959

Malicious code in node-business (npm)

Published Mar 20, 2026
MAL-2026-199

Malicious code in vet-bones (npm)

Published Jan 10, 2026
MAL-2024-1231

Malicious code in @lbnqduy11805/reimagined-happiness (npm)

Published Apr 10, 2024
MAL-2022-259

Malicious code in @exnessimus/hooks (npm)

Published Jul 21, 2022
MAL-2025-4011

Malicious code in nestjs-translator (npm)

Published May 19, 2025
MAL-2023-182

Malicious code in clientcore-onesrv-businesslogic (npm)

Published Mar 15, 2023
MAL-2023-183

Malicious code in clientcore-onesrv-serviceclients (npm)

Published Mar 15, 2023
MAL-2022-5661

Malicious code in react-nesting-example-modern (npm)

Published Jun 20, 2022
MAL-2025-74

Malicious code in romanes-eunt-domus-jd-1337 (npm)

Published Jan 13, 2025
MAL-2022-3604

Malicious code in helm-harness (npm)

Published Oct 5, 2022
MAL-2026-108

Malicious code in @nestor_hexom/garfield (npm)

Published Jan 7, 2026
MAL-2024-7450

Malicious code in icnes (npm)

Published Jul 11, 2024
MAL-2022-4801

Malicious code in nestjs-ldap-auth (npm)

Published Jun 20, 2022
MAL-2022-4802

Malicious code in nestjs-proxy (npm)

Published Jun 20, 2022
MAL-2023-180

Malicious code in clientcore-catalyst-businesslogic (npm)

Published Mar 15, 2023
MAL-2024-8349

Malicious code in @diotoborg/harum-nesciunt-dolores (npm)

Published Sep 2, 2024
MAL-2022-5343

Malicious code in pipelines-javascript (npm)

Published Jun 20, 2022
CVE-2023-29198MEDIUM

Electron context isolation bypass via nested unserializable return value

Published Sep 6, 2023
MAL-2022-848

Malicious code in adc-harness-state (npm)

Published Jun 20, 2022
MAL-2024-7293

Malicious code in @zitterorg/nesciunt-quas (npm)

Published Jul 4, 2024
MAL-2022-955

Malicious code in amazon-kinesis-video-streams-webrtc-sdk-js (npm)

Published Jun 20, 2022
MAL-2023-1513

Malicious code in business_api_client (npm)

Published Aug 21, 2023
MAL-2023-178

Malicious code in clientcore-base-businesslogic (npm)

Published Mar 15, 2023
MAL-2024-8461

Malicious code in @diotoborg/nesciunt-veniam (npm)

Published Sep 2, 2024
MAL-2026-1841

Malicious code in safeness-sb-new (npm)

Published Mar 18, 2026
MAL-2024-8537

Malicious code in @diotoborg/quae-nesciunt (npm)

Published Sep 2, 2024
MAL-2024-8571

Malicious code in @diotoborg/quis-soluta-nesciunt (npm)

Published Sep 2, 2024
MAL-2025-191070

Malicious code in barebones-css (npm)

Published Nov 24, 2025
MAL-2022-3210

Malicious code in freekws-devportal-api-client-nestjs (npm)

Published Aug 22, 2022
MAL-2023-8456

Malicious code in exnessimo (npm)

Published Nov 6, 2023
MAL-2024-11154

Malicious code in safeness-backup (npm)

Published Nov 29, 2024
MAL-2022-5868

Malicious code in runkit-engines (npm)

Published Aug 18, 2022
MAL-2025-190966

Malicious code in httpness (npm)

Published Nov 24, 2025
MAL-2022-3336

Malicious code in genesis-volatility-adapter (npm)

Published Jun 20, 2022
MAL-2022-3337

Malicious code in genesys-frontend-facade (npm)

Published Jun 20, 2022
MAL-2024-8289

Malicious code in @diotoborg/error-nesciunt-qui (npm)

Published Sep 2, 2024
MAL-2022-3338

Malicious code in genshin-impact-free-primogems-and-genesis-crystals-2022 (npm)

Published Jun 20, 2022
MAL-2022-4169

Malicious code in kinesis-app-panel (npm)

Published Jul 21, 2022
MAL-2024-7244

Malicious code in @zitterorg/itaque-nesciunt-voluptatibus (npm)

Published Jul 4, 2024
MAL-2025-2284

Malicious code in valentinesgiftt (npm)

Published Mar 11, 2025
MAL-2025-3573

Malicious code in ui-platform-business-elements (npm)

Published May 2, 2025
MAL-2024-1454

Malicious code in @juiggitea/nesciunt-ut-culpa-ad (npm)

Published Jun 3, 2024
MAL-2024-9054

Malicious code in jquery-ui-smoothness (npm)

Published Sep 30, 2024
MAL-2024-9347

Malicious code in do-wnload-available-2014-20032-happiness-is-happening-2iby6-rsrcqq (npm)

Published Oct 16, 2024
MAL-2025-191357

Malicious code in @voiceflow/nestjs-common (npm)

Published Nov 25, 2025
MAL-2025-191358

Malicious code in @voiceflow/nestjs-mongodb (npm)

Published Nov 25, 2025
MAL-2024-7378

Malicious code in @zitterorg/similique-nesciunt (npm)

Published Jul 4, 2024
MAL-2025-190884

Malicious code in @posthog/kinesis-plugin (npm)

Published Nov 24, 2025
MAL-2022-6153

Malicious code in skype4business (npm)

Published Jun 20, 2022
GHSA-gh4j-gqv2-49f6

fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters

Published Apr 22, 2026
MAL-2025-41447

Malicious code in unescaped (npm)

Published Aug 28, 2025
MAL-2025-47346

Malicious code in rxnt-healthchecks-nestjs (npm)

Published Sep 16, 2025
MAL-2025-48023

Malicious code in buildkite-pipelines (npm)

Published Oct 8, 2025
MAL-2024-1393

Malicious code in nespresso-design-system (npm)

Published May 30, 2024
MAL-2026-109

Malicious code in @nestor_hexom/garfield1 (npm)

Published Jan 7, 2026
MAL-2026-1445

Malicious code in nest-moralis (npm)

Published Mar 16, 2026
MAL-2026-110

Malicious code in @nestor_hexom/qyxb (npm)

Published Jan 7, 2026
Check your entire dependency tree at onceRun dependency scan →