OsVault/npm/st
npm31 critical

st

1001 known vulnerabilities · 31 critical · 71 high

CVE-2017-16224MEDIUM

Open Redirect in st

Published Aug 6, 2018
CVE-2014-3744HIGH

Directory Traversal in st

Published Aug 31, 2020
GHSA-49rj-9fvp-4h2h

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

Published Jun 3, 2026
MAL-2025-129

Malicious code in jssdk-infrastructure (npm)

Published Jan 16, 2025
MAL-2022-7443

Malicious code in @getstep/sdk (npm)

Published Jun 20, 2022
GHSA-2vx9-7wpg-88jq

n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

Published May 19, 2026
CVE-2025-27098

Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler

Published Feb 16, 2023
GHSA-32mq-hpph-xfvr

@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes

Published May 19, 2026
GHSA-3875-8gcx-7v46

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

Published May 19, 2026
CVE-2023-26135HIGH

flatnest Prototype Pollution vulnerability

Published Jun 30, 2023
MAL-2025-1532

Malicious code in int_pinterest_sfra (npm)

Published Feb 23, 2025
GHSA-2qrv-rc5x-2g2h

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

Published Apr 7, 2026
MAL-2025-1625

Malicious code in sddst-ui (npm)

Published Feb 28, 2025
GHSA-6vr3-7wcx-v5g5

browserstack-runner vulnerable to Remote Code Execution via vm sandbox escape in _log HTTP handler

Published Jun 3, 2026
GHSA-c4cf-2hgv-2qv6

vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain

Published May 29, 2026
CVE-2022-28397CRITICAL

Arbitrary file upload in Ghost

Published Apr 13, 2022
MAL-2025-1689

Malicious code in @f2p-mml-frontends/mml-styles (npm)

Published Mar 3, 2025
GHSA-4fg7-f244-3j49

HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

Published May 19, 2026
MAL-2026-4257

Malicious code in @cloudways-lab/unified-design-system (npm)

Published May 22, 2026
GHSA-9g8x-92q2-p28f

NodeVM observability builtins leak host process and HTTP request data

Published May 29, 2026
CVE-2026-29053

Ghost Vulnerable to Remote Code Execution via Malicious Themes

Published Mar 3, 2026
CVE-2024-23725MEDIUM

Cross-site Scripting in Ghost

Published Jan 21, 2024
MAL-2025-190958

Malicious code in email-deliverability-tester (npm)

Published Nov 24, 2025
GHSA-8cph-rgr4-g5vj

Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers

Published May 29, 2026
CVE-2025-12758

Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements

Published Nov 27, 2025
GHSA-m4wx-m65x-ghrr

vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE

Published May 29, 2026
MAL-2024-8040

Malicious code in system-library-gameanalytics-common (npm)

Published Aug 26, 2024
GHSA-8646-j5j9-6r62

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

Published Jun 3, 2026
GHSA-4948-f92q-f432

@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading

Published Apr 22, 2026
CVE-2023-29019HIGH

Session fixation in fastify-passport

Published Apr 21, 2023
GHSA-8rpw-6cqh-2v9h

browserstack-runner has an unauthenticated arbitrary file read via path traversal in HTTP server

Published Jun 3, 2026
MAL-2022-6498

Malicious code in test494 (npm)

Published Jun 20, 2022
GHSA-8x6r-g9mw-2r78

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

Published Jun 3, 2026
GHSA-q3fm-4wcw-g57x

vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter

Published May 29, 2026
MAL-2024-81

Malicious code in schibsted-style (npm)

Published Jan 11, 2024
CVE-2025-45143

string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)

Published Jun 30, 2025
CVE-2022-37262HIGH

steal vulnerable to Regular Expression Denial of Service via source and sourceWithComments

Published Sep 16, 2022
MAL-2024-12119

Malicious code in stablecoin-aptos (npm)

Published Dec 24, 2024
MAL-2025-191294

Malicious code in @posthog/laudspeaker-plugin (npm)

Published Nov 25, 2025
GHSA-rp36-8xq3-r6c4

NodeVM builtin denylist bypass via process and inspector/promises allows host code execution

Published May 29, 2026
CVE-2024-27088

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
MAL-2024-8041

Malicious code in system-library-gameanalytics-slotanalytics (npm)

Published Aug 26, 2024
GHSA-f22v-gfqf-p8f3

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

Published Jun 3, 2026
CVE-2022-27263CRITICAL

Unrestricted Upload of File with Dangerous Type in Strapi

Published Apr 13, 2022
GHSA-h9fj-c2qr-76g2

FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString

Published Jun 8, 2026
GHSA-c73c-x77g-854r

OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS

Published May 12, 2026
GHSA-6xwp-cp5h-q856

Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm

Published May 19, 2026
MAL-2025-191199

Malicious code in @browserbasehq/stagehand-docs (npm)

Published Nov 25, 2025
CVE-2023-7078HIGH

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 29, 2023
MAL-2025-191359

Malicious code in @voiceflow/nestjs-rate-limit (npm)

Published Nov 25, 2025
GHSA-7mqx-wwh4-f9fw

Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying

Published May 13, 2026
GHSA-wjjv-3mj2-39hf

AgenticMail API/storage and outbound relay hardening fixes

Published May 29, 2026
GHSA-g3xq-3gmv-qq8g

claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh

Published May 13, 2026
MAL-2025-191491

Malicious code in babel-plugin-standalone (npm)

Published Nov 30, 2025
GHSA-hvp3-26wx-g2w4

Strapi: Password Reset Does Not Revoke Existing Refresh Sessions

Published May 13, 2026
GHSA-9r33-xhw8-4qqp

HAX CMS: Denial of Service using Malicious Import Request

Published May 19, 2026
CVE-2023-45884MEDIUM

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Published Nov 9, 2023
CVE-2023-27490HIGH

Missing proper state, nonce and PKCE checks for OAuth authentication

Published Mar 13, 2023
GHSA-5fw2-mwhh-9947

Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials

Published Apr 17, 2026
GHSA-fhh6-4qxv-rpqj

9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

Published May 19, 2026
MAL-2025-7074

Malicious code in @amber-team/storybook-utils (npm)

Published Aug 14, 2025
CVE-2026-2265MEDIUM
Risk: 32.52/100

Replicator deserializes untrusted user input

Published Apr 1, 2026
CVE-2021-31597CRITICAL

Improper Certificate Validation in xmlhttprequest-ssl

Published May 24, 2021
MAL-2022-1031

Malicious code in aoe_playstyle (npm)

Published Jun 20, 2022
MAL-2025-191993

Malicious code in elf-stats-bright-cushion-246 (npm)

Published Dec 3, 2025
MAL-2025-182

Malicious code in dotgov-list (npm)

Published Jan 20, 2025
CVE-2023-32235HIGH

Path Traversal in Ghost

Published May 5, 2023
GHSA-7q9x-8g6p-3x75

@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template

Published Mar 25, 2026
MAL-2022-1042

Malicious code in api-routes-rest (npm)

Published Jul 21, 2022
CVE-2026-30920

OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding

Published Mar 9, 2026
MAL-2025-192085

Malicious code in elf-stats-merry-chimney-765 (npm)

Published Dec 3, 2025
CVE-2020-7629CRITICAL

OS Command Injection in install-package

Published Feb 10, 2022
MAL-2024-8262

Malicious code in @diotoborg/dolorum-iste-excepturi (npm)

Published Sep 2, 2024
MAL-2024-8272

Malicious code in @diotoborg/eaque-iste (npm)

Published Sep 2, 2024
MAL-2025-192140

Malicious code in elf-stats-snowdusted-fireplace-396 (npm)

Published Dec 3, 2025
MAL-2025-192141

Malicious code in elf-stats-snowdusted-saddlebag-790 (npm)

Published Dec 3, 2025
GHSA-6pfc-6m7w-m8fx

OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper

Published Mar 31, 2026
MAL-2025-48539

Malicious code in zdachboostv3 (npm)

Published Oct 21, 2025
GHSA-534w-2vm4-89xr

OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch

Published Mar 3, 2026
MAL-2025-192154

Malicious code in elf-stats-sparkly-cocoa-863 (npm)

Published Dec 3, 2025
MAL-2025-192159

Malicious code in elf-stats-sprucey-snowman-250 (npm)

Published Dec 3, 2025
CVE-2020-26768MEDIUM

Formstone Vulnerable to Reflected XSS

Published May 24, 2022
MAL-2025-192181

Malicious code in elf-stats-twinkling-marshmallow-913 (npm)

Published Dec 3, 2025
CVE-2025-5276

Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Published May 29, 2025
MAL-2025-192197

Malicious code in elf-stats-wintry-icicle-283 (npm)

Published Dec 3, 2025
MAL-2022-109

Malicious code in @azure-tests/perf-service-bus (npm)

Published Jun 20, 2022
MAL-2024-8291

Malicious code in @diotoborg/esse-distinctio-repellat (npm)

Published Sep 2, 2024
MAL-2025-192210

Malicious code in elf-stats-frostbitten-reindeer-875 (npm)

Published Dec 3, 2025
MAL-2025-192212

Malicious code in elf-stats-ginger-reindeer-411 (npm)

Published Dec 3, 2025
MAL-2025-192213

Malicious code in elf-stats-gingersnap-ornament-469 (npm)

Published Dec 3, 2025
MAL-2025-192214

Malicious code in elf-stats-glittering-fir-252 (npm)

Published Dec 3, 2025
CVE-2020-7639MEDIUM

eivindfjeldstad-dot contains prototype pollution vulnerability

Published May 25, 2021
CVE-2022-29257MEDIUM

AutoUpdater module fails to validate certain nested components of the bundle

Published Jun 16, 2022
GHSA-3298-56p6-rpw2

OpenClaw has incomplete Fix for CVE-2026-27486: Unvalidated SIGKILL in `!stop` Chat Command via `shell-utils.ts`

Published Mar 30, 2026
GHSA-g87j-gm7p-6vw2

Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 19, 2026
CVE-2023-31999HIGH

@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state

Published Jul 5, 2023
GHSA-7853-gqqm-vcwx

openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools

Published Apr 8, 2026
MAL-2025-192218

Malicious code in elf-stats-merry-cookiejar-442 (npm)

Published Dec 3, 2025
MAL-2025-192229

Malicious code in elf-stats-sleighing-nutcracker-806 (npm)

Published Dec 3, 2025
MAL-2025-192266

Malicious code in elf-stats-silvered-star-676 (npm)

Published Dec 3, 2025
MAL-2025-192267

Malicious code in elf-stats-snowdusted-lantern-234 (npm)

Published Dec 3, 2025
GHSA-7jp6-r74r-995q

OpenClaw: Matrix profile config persistence was reachable from operator.write message tools

Published Apr 17, 2026
MAL-2026-3337

Malicious code in @t-in-one/save_application_hid_to_storage (npm)

Published May 4, 2026
MAL-2025-192370

Malicious code in elf-stats-snowdusted-cookiejar-250 (npm)

Published Dec 4, 2025
CVE-2026-33468

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

Published Mar 20, 2026
MAL-2025-192473

Malicious code in elf-stats-candlelit-train-228 (npm)

Published Dec 11, 2025
GHSA-g839-vp47-wgh8

Duplicate Advisory: OpenClaw's Slack reaction/pin sender-policy consistency issue in non-message ingress

Published Mar 21, 2026
CVE-2023-6460MEDIUM

Logging of the firestore key within nodejs-firestore

Published Dec 4, 2023
MAL-2025-192539

Malicious code in elf-stats-twinkling-bell-867 (npm)

Published Dec 11, 2025
MAL-2024-8380

Malicious code in @diotoborg/iste-laborum (npm)

Published Sep 2, 2024
CVE-2019-15479MEDIUM

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Published Sep 23, 2019
MAL-2022-1098

Malicious code in arm-attestation (npm)

Published Jun 20, 2022
MAL-2022-1099

Malicious code in arm-azurestack (npm)

Published Jun 20, 2022
GHSA-63f5-hhc7-cx6p

OpenClaw bootstrap setup codes could be replayed to escalate pending pairing scopes before approval

Published Mar 16, 2026
GHSA-h97f-6pqj-q452

OpenClaw has a IPv6 multicast SSRF classifier bypass

Published Mar 3, 2026
MAL-2022-1850

Malicious code in cd-system (npm)

Published Jul 5, 2022
CVE-2026-22177

OpenClaw's config env vars allowed startup env injection into service runtime

Published Mar 3, 2026
MAL-2025-192709

Malicious code in amazon-testpackage (npm)

Published Dec 23, 2025
MAL-2024-8428

Malicious code in @diotoborg/molestiae-doloribus (npm)

Published Sep 2, 2024
MAL-2025-192740

Malicious code in elf-stats-caroling-wreath-635 (npm)

Published Dec 23, 2025
MAL-2024-8429

Malicious code in @diotoborg/molestiae-maxime (npm)

Published Sep 2, 2024
MAL-2025-192771

Malicious code in elf-stats-glittering-cookie-844 (npm)

Published Dec 23, 2025
GHSA-939r-rj45-g2rj

OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins

Published Apr 17, 2026
CVE-2026-29185

Backstage vulnerable to potential reading of SCM URLs using built in token

Published Mar 5, 2026
CVE-2026-25047

deepHas vulnerable to Prototype Pollution via constructor.prototype

Published Jan 29, 2026
MAL-2026-4973

Malicious code in @cloudplatform-single-spa/static-page (npm)

Published May 28, 2026
MAL-2022-4828

Malicious code in nextcloud-js-tests (npm)

Published Jun 20, 2022
CVE-2025-30359

webpack-dev-server users' source code may be stolen when they access a malicious web site

Published Jun 4, 2025
CVE-2024-29194HIGH

OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

Published Mar 25, 2024
CVE-2022-23080MEDIUM

Server-Side Request Forgery in Directus

Published Jun 23, 2022
MAL-2025-4134

Malicious code in string-multiutils (npm)

Published May 21, 2025
MAL-2022-5427

Malicious code in postcssmipot (npm)

Published Aug 19, 2022
MAL-2026-5044

Malicious code in @t-in-one/restore_application_hid_from_storage (npm)

Published May 29, 2026
MAL-2026-5045

Malicious code in @t-in-one/safe_local_storage_token (npm)

Published May 29, 2026
MAL-2025-47892

Malicious code in pycodestyle (npm)

Published Oct 2, 2025
CVE-2016-10695HIGH

Downloads Resources over HTTP in npm-test-sqlite3-trunk

Published Sep 1, 2020
MAL-2025-6334

Malicious code in style-postprocessor (npm)

Published Jul 28, 2025
MAL-2022-5461

Malicious code in privacy-test-pages (npm)

Published Jun 20, 2022
CVE-2026-26316

OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust

Published Feb 17, 2026
MAL-2026-2915

Malicious code in bitu-staking (npm)

Published Apr 12, 2026
CVE-2025-12735

expr-eval does not restrict functions passed to the evaluate function

Published Nov 5, 2025
MAL-2026-3006

Malicious code in changelog-utils-structured-logger (npm)

Published Apr 23, 2026
MAL-2026-5061

Malicious code in chai-use-test (npm)

Published May 29, 2026
MAL-2026-5062

Malicious code in codex-devcontainer-install (npm)

Published May 29, 2026
MAL-2026-5063

Malicious code in customerdigital-service-lib (npm)

Published May 29, 2026
CVE-2016-10703HIGH

Denial of Service in ecstatic

Published Dec 28, 2017
MAL-2025-192249

Malicious code in elf-stats-shimmering-muffin-598 (npm)

Published Dec 3, 2025
GHSA-jh3h-rpxg-fr36

Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover

Published May 19, 2026
GHSA-c276-fj82-f2pq

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Published Apr 16, 2026
CVE-2026-33896CRITICAL
Risk: 88/100

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Published Mar 26, 2026
CVE-2024-56159

Astro's server source code is exposed to the public if sourcemaps are enabled

Published Dec 19, 2024
CVE-2023-38507HIGH

Strapi Improper Rate Limiting vulnerability

Published Sep 13, 2023
CVE-2021-23398MEDIUM

Cross-site scripting in react-bootstrap-table

Published Dec 10, 2021
GHSA-gwhp-pf74-vj37

Fastify's connection header abuse enables stripping of proxy-added headers

Published Apr 16, 2026
CVE-2025-70948

@perfood/couch-auth has a host header injection vulnerability

Published Mar 5, 2026
GHSA-pcw7-5633-82vv

Strapi Upload Plugin MIME Validation Bypass via Content API

Published May 14, 2026
GHSA-2858-xg23-26fp

OpenClaw: Node camera URL payload host-binding bypass allowed gateway fetch pivots

Published Mar 3, 2026
CVE-2023-23936MEDIUM

CRLF Injection in Nodejs ‘undici’ via host

Published Feb 16, 2023
CVE-2022-31069MEDIUM

Potential Authorization Header Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
GHSA-m866-6qv5-p2fg

OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Published Mar 31, 2026
MAL-2022-106

Malicious code in @azure-tests/perf-keyvault-secrets (npm)

Published Jun 20, 2022
MAL-2022-7077

Malicious code in web-stories-renderer (npm)

Published Jul 21, 2022
MAL-2022-7078

Malicious code in web-stories-wp (npm)

Published Jun 20, 2022
CVE-2016-10626HIGH

Downloads Resources over HTTP in mystem3

Published Feb 18, 2019
GHSA-r849-826x-wgqm

Duplicate Advisory: Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 19, 2026
CVE-2026-32055

OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 12, 2026
CVE-2026-21852

Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

Published Jan 21, 2026
GHSA-mhr7-2xmv-4c4q

OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode

Published Apr 3, 2026
CVE-2015-9545HIGH

Improper Input Validation in xdLocalStorage

Published Dec 9, 2021
CVE-2022-21144HIGH

Denial of service vulnerability exists in libxmljs

Published May 3, 2022
CVE-2023-31133HIGH

Ghost vulnerable to information disclosure of private API fields

Published May 3, 2023
CVE-2024-41818HIGH

fast-xml-parser vulnerable to ReDOS at currency parsing

Published Jul 29, 2024
CVE-2026-33768

Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`

Published Mar 26, 2026
MAL-2024-8819

Malicious code in 0g-storage-contracts (npm)

Published Sep 5, 2024
MAL-2022-6221

Malicious code in sovryn-node-integration-tests (npm)

Published Jun 20, 2022
MAL-2022-6223

Malicious code in sp-bootstrap (npm)

Published Jun 13, 2022
GHSA-mvv8-v4jj-g47j

Directus: Sensitive fields exposed in revision history

Published Apr 4, 2026
CVE-2026-25128

fast-xml-parser has RangeError DoS Numeric Entities Bug

Published Jan 30, 2026
MAL-2022-6228

Malicious code in sparhandy-speedtest (npm)

Published Jul 21, 2022
MAL-2022-6006

Malicious code in seller-listing-service (npm)

Published Nov 9, 2022
GHSA-r7p2-r9g4-4xph

Duplicate Advisory: OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients

Published Apr 24, 2026
MAL-2024-8867

Malicious code in node-integration-test (npm)

Published Sep 11, 2024
CVE-2025-68157

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

Published Feb 5, 2026
CVE-2024-36361MEDIUM

Pug allows JavaScript code execution if an application accepts untrusted input

Published May 24, 2024
MAL-2024-3800

Malicious code in usaa-a11y-test (npm)

Published Jun 25, 2024
GHSA-72c6-fx6q-fr5w

@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

Published Apr 16, 2026
CVE-2022-24717MEDIUM

Cross Site Scripting (XSS) in @finastra/ssr-pages

Published Mar 1, 2022
CVE-2022-37257CRITICAL

steal vulnerable to Prototype Pollution via requestedVersion variable

Published Sep 16, 2022
MAL-2022-6299

Malicious code in state.aggregator (npm)

Published Jun 20, 2022
MAL-2022-63

Malicious code in @aia-digital/request-module (npm)

Published Jun 20, 2022
MAL-2022-6301

Malicious code in statusim-mobile (npm)

Published Jun 20, 2022
MAL-2022-6303

Malicious code in steamdb-browser-extension (npm)

Published Jun 20, 2022
CVE-2025-61686

React Router has Path Traversal in File Session Storage

Published Jan 8, 2026
CVE-2014-8883

Directory Traversal in nhouston

Published Aug 31, 2020
MAL-2022-6308

Malicious code in stnylelint-config-tandrad (npm)

Published Aug 19, 2022
MAL-2022-6309

Malicious code in storage-blob-changefeed (npm)

Published Jun 20, 2022
MAL-2022-6316

Malicious code in storageblob (npm)

Published Jun 20, 2022
MAL-2022-6318

Malicious code in stories-carousel (npm)

Published Jun 20, 2022
MAL-2022-6323

Malicious code in streamer-market-dashboard (npm)

Published Jun 20, 2022
CVE-2022-31150MEDIUM

undici before v5.8.0 vulnerable to CRLF injection in request headers

Published Jul 21, 2022
CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
MAL-2022-6324

Malicious code in stressfault (npm)

Published Jun 20, 2022
MAL-2022-6331

Malicious code in stripe-demo-connect-standard-saas-platform (npm)

Published Jul 25, 2022
MAL-2022-107

Malicious code in @azure-tests/perf-monitor-query (npm)

Published Jun 20, 2022
CVE-2025-59536

Claude Code can execute commands prior to the startup trust dialog

Published Oct 3, 2025
CVE-2026-28486

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

Published Mar 2, 2026
CVE-2022-2216CRITICAL

Server-Side Request Forgery in parse-url

Published Jun 28, 2022
MAL-2022-6340

Malicious code in stylelint-config-monorepo-palantir (npm)

Published Jun 20, 2022
MAL-2022-6342

Malicious code in stylis-ifl4 (npm)

Published Jun 2, 2022
CVE-2022-31367HIGH

Strapi mishandles hidden attributes within admin API responses

Published Sep 28, 2022
MAL-2022-6343

Malicious code in stylleint (npm)

Published Aug 19, 2022
CVE-2026-28446

OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)

Published Feb 17, 2026
CVE-2024-47529

OpenC3 stores passwords in clear text (`GHSL-2024-129`)

Published Oct 2, 2024
CVE-2024-53983

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

Published Dec 2, 2024
MAL-2022-6347

Malicious code in suggests (npm)

Published Jun 20, 2022
CVE-2025-69211

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

Published Dec 30, 2025
CVE-2026-26319

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Published Feb 17, 2026
CVE-2024-31217MEDIUM

@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling

Published Jun 12, 2024
CVE-2025-62410

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

Published Oct 15, 2025
MAL-2026-3158

Malicious code in apple-internal-pki-trust (npm)

Published Apr 29, 2026
GHSA-5jg4-p4qw-cgfr

@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags

Published Apr 4, 2026
MAL-2022-1379

Malicious code in azure-storage-common-cpp (npm)

Published Jun 20, 2022
MAL-2022-6352

Malicious code in super-streams (npm)

Published Jun 20, 2022
CVE-2024-37890HIGH

ws affected by a DoS when handling a request with many HTTP headers

Published Jun 17, 2024
MAL-2025-4355

Malicious code in gop_status_frontend (npm)

Published May 23, 2025
CVE-2026-33287

LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

Published Mar 25, 2026
CVE-2017-16155HIGH

Directory Traversal in fast-http-cli

Published Jul 23, 2018
CVE-2024-43035MEDIUM

Fonoster is vulnerable to directory traversal

Published Mar 5, 2026
GHSA-9gp8-hjxr-6f34

OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls

Published Apr 3, 2026
MAL-2024-9277

Malicious code in opti-distube (npm)

Published Oct 11, 2024
GHSA-vrhm-gvg7-fpcf

Memory exhaustion in SvelteKit remote form deserialization (experimental only)

Published Feb 19, 2026
MAL-2022-1107

Malicious code in arm-storsimple8000series (npm)

Published Jun 20, 2022
CVE-2026-24006

Seroval affected by Denial of Service via Deeply Nested Objects

Published Jan 22, 2026
CVE-2021-25979CRITICAL

Apostrophe CMS Insufficient Session Expiration vulnerability

Published Nov 10, 2021
MAL-2026-476

Malicious code in @transaction-list/transaction-list-xs (npm)

Published Jan 23, 2026
CVE-2026-32052

OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text

Published Mar 3, 2026
MAL-2025-7075

Malicious code in @amber-team/stylelint-config (npm)

Published Aug 14, 2025
MAL-2022-112

Malicious code in @azure-tests/perf-storage-blob-track-1 (npm)

Published Jun 20, 2022
CVE-2026-29784

Ghost has incomplete CSRF protections around OTC use

Published Mar 5, 2026
GHSA-392f-ggf5-fp3c

OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

Published Mar 2, 2026
MAL-2024-9382

Malicious code in mp3-file-zip-d-ownload-33971-the-imagination-stage-ar0bb-cvzjxl (npm)

Published Oct 16, 2024
CVE-2018-3771MEDIUM

statics-server Cross-site Scripting vulnerability

Published May 13, 2022
CVE-2020-28436HIGH

google-cloudstorage-commands Command Injection vulnerability

Published Jul 26, 2022
MAL-2026-3232

Malicious code in codewhisperer-streaming (npm)

Published May 2, 2026
CVE-2018-20676MEDIUM

XSS vulnerability that affects bootstrap

Published Jan 17, 2019
GHSA-mj7r-x3h3-7rmr

ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

Published Apr 16, 2026
MAL-2022-6465

Malicious code in test-aaa-yyyy-zzz (npm)

Published Jul 8, 2022
MAL-2022-6467

Malicious code in test-code-012 (npm)

Published Jun 20, 2022
GHSA-6785-pvv7-mvg7

vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion

Published May 7, 2026
CVE-2026-25474

OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass

Published Feb 17, 2026
MAL-2024-9445

Malicious code in reqstus (npm)

Published Oct 22, 2024
GHSA-3pm9-5j7m-59vc

OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config

Published Apr 3, 2026
MAL-2022-6470

Malicious code in test-code-012111 (npm)

Published Jun 20, 2022
MAL-2022-6482

Malicious code in test-inherited-attrs (npm)

Published Nov 15, 2022
MAL-2022-6483

Malicious code in test-marek-common (npm)

Published Jun 20, 2022
MAL-2022-6484

Malicious code in test-npm-mal-kfir (npm)

Published Aug 25, 2022
CVE-2026-28450

OpenClaw's unauthenticated Nostr profile HTTP endpoints allow remote profile/config tampering

Published Feb 17, 2026
CVE-2025-64745

Astro development server error page is vulnerable to reflected Cross-site Scripting

Published Nov 13, 2025
CVE-2024-37145MEDIUM

Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id

Published Aug 5, 2024
MAL-2022-6517

Malicious code in testhackhacks (npm)

Published Jun 20, 2022
MAL-2022-6519

Malicious code in testherejson (npm)

Published Dec 7, 2022
CVE-2023-5572CRITICAL

Server-Side Request Forgery (SSRF) in vriteio/vrite

Published Oct 13, 2023
GHSA-6r77-hqx7-7vw8

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

Published Apr 16, 2026
CVE-2022-31089HIGH

Invalid file request can crash server

Published Jun 20, 2022
MAL-2022-6520

Malicious code in testing-npm-random (npm)

Published Jun 20, 2022
MAL-2022-6523

Malicious code in testingtesttencencent (npm)

Published Jun 20, 2022
CVE-2026-27488

OpenClaw hardened cron webhook delivery against SSRF

Published Feb 20, 2026
MAL-2024-987

Malicious code in @globalsearch/productstub (npm)

Published Feb 10, 2024
GHSA-3q42-xmxv-9vfr

OpenClaw: Gateway operator.write Can Reach Admin-Class Talk Voice Config Persistence via chat.send

Published Apr 7, 2026
CVE-2024-39008CRITICAL

robinweser fast-loops vulnerable to prototype pollution

Published Jul 1, 2024
GHSA-w48f-fwg7-ww6p

@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding

Published Apr 4, 2026
MAL-2022-6525

Malicious code in testmatrix (npm)

Published Jun 20, 2022
CVE-2026-32944

Parse Server crash via deeply nested query condition operators

Published Mar 17, 2026
MAL-2022-6527

Malicious code in testnpmad12 (npm)

Published Jun 20, 2022
MAL-2022-6528

Malicious code in testpackagehere (npm)

Published Jun 20, 2022
CVE-2018-6835CRITICAL

Etherpad Lite Access Restriction Bypass

Published May 13, 2022
CVE-2020-28283CRITICAL

Prototype pollution vulnerability in 'libnested'

Published Oct 12, 2021
GHSA-wp5r-2gw5-m7q7

vm2's Transformer Fast-Path Bypass Exposes Internal State Variable

Published May 7, 2026
CVE-2024-39338HIGH

Server-Side Request Forgery in axios

Published Aug 12, 2024
CVE-2023-38698MEDIUM

.eth registrar controller can shorten the duration of registered names

Published Aug 1, 2023
CVE-2026-32895

OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers

Published Mar 12, 2026
CVE-2016-10664HIGH

mystem downloads Resources over HTTP

Published Feb 18, 2019
MAL-2022-866

Malicious code in administracja_reklamowa (npm)

Published Jun 20, 2022
GHSA-48m6-ch88-55mj

Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association

Published Apr 16, 2026
CVE-2025-24010

Websites were able to send any requests to the development server and read the response in vite

Published Jan 21, 2025
CVE-2026-26280

Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path

Published Feb 18, 2026
GHSA-2cwr-f5hx-gg3w

Duplicate Advisory: OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace

Published Mar 19, 2026
GHSA-9f79-7pw8-3fj8

Duplicate Advisory: OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf

Published Mar 21, 2026
MAL-2026-2110

Malicious code in react-tailwindcss-style (npm)

Published Mar 23, 2026
CVE-2026-30229

parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user

Published Mar 6, 2026
GHSA-9gvx-vj57-vqqx

Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication

Published Apr 10, 2026
CVE-2022-25931HIGH

easy-static-server vulnerable to Directory Traversal

Published Dec 20, 2022
CVE-2026-29772

Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

Published Mar 24, 2026
CVE-2022-32213MEDIUM

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

Published Jul 15, 2022
CVE-2020-8134HIGH

Server-side request forgery in Ghost CMS

Published May 6, 2021
CVE-2023-45857MEDIUM

Axios Cross-Site Request Forgery Vulnerability

Published Nov 8, 2023
CVE-2022-24718HIGH

Path Traversal in @finastra/ssr-pages

Published Mar 1, 2022
MAL-2022-148

Malicious code in @bootstrap-base-nabtrade-design/components (npm)

Published Jun 20, 2022
MAL-2022-6769

Malicious code in umbqstxngoajrkpi (npm)

Published Jul 11, 2022
CVE-2024-56198

path-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability

Published Jan 2, 2025
GHSA-5cwg-9f6j-9jvx

Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows

Published Apr 17, 2026
GHSA-wh77-3x4m-4q9g

Moderate severity vulnerability that affects bootstrap and bootstrap-sass

Published Feb 22, 2019
CVE-2018-15494CRITICAL

dojox vulnerable to unescaped string injection

Published Oct 15, 2018
GHSA-855c-r2vq-c292

Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

Published Apr 16, 2026
GHSA-qj22-xqjr-v83v

OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection

Published Mar 3, 2026
CVE-2026-31991

OpenClaw has Signal group allowlist authorization bypass via DM pairing-store leakage

Published Mar 2, 2026
CVE-2021-42228HIGH

Cross Site Request Forgery in kindeditor

Published Oct 18, 2021
MAL-2022-6293

Malicious code in starbuckssystem.website (npm)

Published Jul 21, 2022
CVE-2016-10679HIGH

Downloads Resources over HTTP in selenium-standalone-painful

Published Feb 18, 2019
GHSA-wmgj-hrx3-23gj

Duplicate Advisory: OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity

Published Mar 29, 2026
MAL-2025-1359

Malicious code in assisted-chat (npm)

Published Feb 13, 2025
CVE-2026-28471

OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching

Published Feb 17, 2026
GHSA-48vw-m3qc-wr99

OpenClaw's Trusted-proxy Control UI sessions retain privileged scopes without device identity on device-less allow paths

Published Mar 26, 2026
MAL-2025-191546

Malicious code in chai-status (npm)

Published Dec 2, 2025
CVE-2026-27492

Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reused

Published Feb 20, 2026
CVE-2026-32237

@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint

Published Mar 12, 2026
CVE-2025-65959

Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'

Published Dec 4, 2025
MAL-2025-49045

Malicious code in spaintest1 (npm)

Published Oct 29, 2025
CVE-2020-28360CRITICAL

Server-Side Request Forgery in private-ip

Published Apr 13, 2021
MAL-2026-3462

Malicious code in @tanstack/eslint-plugin-start (npm)

Published May 11, 2026
MAL-2026-3500

Malicious code in @tanstack/vue-start-server (npm)

Published May 11, 2026
CVE-2026-33724

n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no

Published Mar 25, 2026
CVE-2024-47183

Parse Server's custom object ID allows to acquire role privileges

Published Oct 4, 2024
MAL-2025-6318

Malicious code in testinghs (npm)

Published Jul 25, 2025
CVE-2021-26272MEDIUM

Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

Published Oct 13, 2021
CVE-2016-10566HIGH

install-nw downloads Resources over HTTP

Published Feb 18, 2019
CVE-2021-34079CRITICAL

Command injection in docker-tester

Published Jun 3, 2022
CVE-2021-29369CRITICAL

Code injection in @rkesters/gnuplot

Published Feb 10, 2022
GHSA-w7j5-j98m-w679

OpenClaw has multiple E2E/test Dockerfiles that run all processes as root

Published Mar 3, 2026
GHSA-wr4h-v87w-p3r7

h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read

Published Mar 18, 2026
CVE-2026-28461

OpenClaw has unbounded memory growth in Zalo webhook via query-string key churn (unauthenticated DoS)

Published Mar 2, 2026
CVE-2025-1692

MongoDB Shell may be susceptible to control character injection via pasting

Published Feb 27, 2025
CVE-2020-28482MEDIUM

Cross-site Request Forgery in fastify-csrf

Published Jan 20, 2021
CVE-2024-55500

Avenwu Whistle Cross-Site Request Forgery (CSRF)

Published Dec 10, 2024
GHSA-gg9v-mgcp-v6m7

OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing

Published Apr 3, 2026
CVE-2020-36376CRITICAL

Vulnerability in list function leads to arbitrary code execution via filePath parameters

Published Nov 2, 2021
CVE-2026-27013

Fabric.js Affected by Stored XSS via SVG Export

Published Feb 18, 2026
CVE-2025-68467

Dark Reader gives users the ability to request style sheets from local web servers

Published Mar 4, 2026
MAL-2022-731

Malicious code in @wixui/editor-elements-design-systems (npm)

Published Jun 20, 2022
CVE-2023-26920MEDIUM

fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name

Published Jun 13, 2023
CVE-2023-41646MEDIUM

Buttercup allows attackers to obtain the hash of the master password

Published Sep 8, 2023
CVE-2024-48913

Hono allows bypass of CSRF Middleware by a request without Content-Type header.

Published Oct 15, 2024
CVE-2026-30820

Flowise has Authorization Bypass via Spoofed x-request-from Header

Published Mar 6, 2026
CVE-2025-26042

Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Mar 31, 2025
CVE-2022-23458MEDIUM

Toast UI Grid vulnerable to Cross-site Scripting

Published Sep 23, 2022
CVE-2025-25285

@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
CVE-2025-55284

Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code

Published Aug 18, 2025
CVE-2020-7610CRITICAL

Deserialization of Untrusted Data in bson

Published May 7, 2021
CVE-2018-3729HIGH

Path Traversal in localhost-now

Published Jul 25, 2018
CVE-2022-30618HIGH

Improper Removal of Sensitive Information Before Storage or Transfer in Strapi

Published May 20, 2022
GHSA-g2hm-779g-vm32

OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events

Published Apr 17, 2026
CVE-2022-29256MEDIUM

sharp vulnerable to Command Injection in post-installation over build environment

Published Jun 1, 2022
GHSA-g374-mggx-p6xc

OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode

Published Apr 3, 2026
CVE-2022-26183HIGH

Untrusted Search Path in PNPM

Published Mar 23, 2022
CVE-2025-59155

HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability

Published Sep 15, 2025
CVE-2025-31475

tarteaucitron.js allows prototype pollution via custom text injection

Published Apr 7, 2025
CVE-2025-55303

Astro allows unauthorized third-party images in _image endpoint

Published Aug 19, 2025
MAL-2022-134

Malicious code in @bmw-chris/testmodule-default-frontend (npm)

Published Jun 20, 2022
CVE-2026-33769

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

Published Mar 26, 2026
CVE-2020-36049HIGH

Resource exhaustion in socket.io-parser

Published Jun 30, 2021
CVE-2026-32015

OpenClaw's `tools.exec.safeBins` PATH-hijack allowed trojan binaries to bypass allowlist checks

Published Mar 3, 2026
GHSA-9r7h-6639-v5mw

Cross-Site Scripting in bootstrap-select

Published Sep 3, 2020
CVE-2020-11021MEDIUM

Http request which redirect to another hostname do not strip authorization header in @actions/http-client

Published Apr 29, 2020
GHSA-xh9j-mpc9-2m9p

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 21, 2026
CVE-2021-4264MEDIUM

dustjs-linkedin vulnerable to Prototype Pollution

Published Dec 21, 2022
MAL-2022-1723

Malicious code in buildstamp-monorepo (npm)

Published Jun 20, 2022
MAL-2022-96

Malicious code in @azure-tests/perf-ai-metrics-advisor (npm)

Published Jun 20, 2022
CVE-2016-10521HIGH

Regular Expression Denial of Service in jshamcrest

Published Feb 18, 2019
MAL-2022-1905

Malicious code in circonus-statsd-backend (npm)

Published Jun 20, 2022
CVE-2026-24473

Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)

Published Jan 27, 2026
CVE-2018-3726MEDIUM

Cross-site Scripting (XSS) - Stored in crud-file-server

Published Jul 18, 2018
MAL-2022-116

Malicious code in @azure-tests/perf-template (npm)

Published Jun 20, 2022
MAL-2025-190982

Malicious code in orchestrix (npm)

Published Nov 24, 2025
CVE-2026-24778

Ghost vulnerable to XSS via malicious Portal preview links

Published Jan 28, 2026
CVE-2018-3734HIGH

Path Traversal in stattic

Published Jul 18, 2018
MAL-2022-266

Malicious code in @fbsystem/figma-graphql (npm)

Published Jun 20, 2022
MAL-2026-3720

Malicious code in ethers-wordlist (npm)

Published May 13, 2026
MAL-2022-2735

Malicious code in encryptte-test (npm)

Published Jun 20, 2022
GHSA-chfm-xgc4-47rj

OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API

Published Apr 2, 2026
MAL-2022-1378

Malicious code in azure-storage-blob-changefeed (npm)

Published Jun 20, 2022
MAL-2022-97

Malicious code in @azure-tests/perf-ai-text-analytics (npm)

Published Jun 20, 2022
MAL-2022-2879

Malicious code in etn_validator_list (npm)

Published Jun 20, 2022
MAL-2022-141

Malicious code in @boosted-bounty/cassandra-helpers (npm)

Published Jun 20, 2022
CVE-2026-26980

Ghost has a SQL injection in Content API

Published Feb 18, 2026
GHSA-w6v6-49gh-mc9w

Flowise: Path Traversal in Vector Store basePath

Published Apr 16, 2026
CVE-2025-68470

React Router has unexpected external redirect via untrusted paths

Published Jan 8, 2026
MAL-2022-5986

Malicious code in seacpe-string-regexp (npm)

Published Aug 19, 2022
MAL-2022-319

Malicious code in @harrysforge/number-stepper (npm)

Published Jun 20, 2022
CVE-2021-44906CRITICAL

Prototype Pollution in minimist

Published Mar 18, 2022
MAL-2022-4507

Malicious code in mattermost-webapp-profiling (npm)

Published Jun 20, 2022
MAL-2022-2167

Malicious code in construct-burst (npm)

Published Jun 20, 2022
CVE-2025-55346

Flowise vulnerable to RCE via Dynamic function constructor injection

Published Oct 6, 2025
MAL-2024-7875

Malicious code in boostrapsio (npm)

Published Aug 1, 2024
CVE-2020-8128CRITICAL

Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport

Published Apr 13, 2021
CVE-2021-23430HIGH

Directory Traversal in startserver

Published Sep 2, 2021
MAL-2022-99

Malicious code in @azure-tests/perf-core-rest-pipeline (npm)

Published Jun 20, 2022
MAL-2022-5544

Malicious code in qiwi-substrate-monorepo (npm)

Published Jun 20, 2022
MAL-2022-6495

Malicious code in test1_l3yx (npm)

Published Jun 20, 2022
CVE-2026-32065

OpenClaw: system.run approval identity mismatch could execute a different binary than displayed

Published Mar 2, 2026
MAL-2022-997

Malicious code in angieslist-composed-components (npm)

Published May 17, 2022
MAL-2022-6499

Malicious code in test4948 (npm)

Published Jun 20, 2022
MAL-2022-2447

Malicious code in design-system-base (npm)

Published Jun 20, 2022
MAL-2022-998

Malicious code in angieslist-gulp-build-tasks (npm)

Published May 16, 2022
MAL-2022-4823

Malicious code in newtestforme1008 (npm)

Published Jun 9, 2022
MAL-2022-999

Malicious code in angieslist-styleguide (npm)

Published Jun 20, 2022
CVE-2021-23346MEDIUM

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

Published Mar 18, 2021
CVE-2017-16143HIGH

Directory Traversal in commentapp.stetsonwood

Published Jul 23, 2018
MAL-2023-1001

Malicious code in you-are-a-badass-at-making-money-master-the-mindset-of-wealth-by-jen-sincero-on-mac-new-version- (npm)

Published May 10, 2023
MAL-2025-191456

Malicious code in @medusajs/analytics-posthog (npm)

Published Nov 24, 2025
CVE-2026-25762

AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection

Published Feb 6, 2026
CVE-2025-47828

@lumieducation/h5p-server Fails to Sanitize Plain Text Strings

Published May 11, 2025
MAL-2022-1000

Malicious code in angieslist-styles (npm)

Published Jun 20, 2022
MAL-2025-191502

Malicious code in pluxee-design-system (npm)

Published Dec 1, 2025
CVE-2025-15104

Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability

Published Jan 16, 2026
MAL-2022-1006

Malicious code in angular-dev-test (npm)

Published Jun 20, 2022
CVE-2025-7338

Multer vulnerable to Denial of Service via unhandled exception from malformed request

Published Jul 17, 2025
MAL-2023-1032

Malicious code in eslint-config-scp-custom-rules (npm)

Published Aug 1, 2023
MAL-2023-690

Malicious code in postcss-file-match (npm)

Published Jan 30, 2023
MAL-2024-36

Malicious code in @monokera/react-components-storybook (npm)

Published Jan 5, 2024
MAL-2025-1530

Malicious code in bm_pinterest (npm)

Published Feb 23, 2025
MAL-2023-1033

Malicious code in eslint-plugin-scp-custom-rules (npm)

Published Aug 1, 2023
CVE-2026-33349

Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser

Published Mar 19, 2026
MAL-2022-104

Malicious code in @azure-tests/perf-keyvault-certificates (npm)

Published Jun 20, 2022
MAL-2022-1040

Malicious code in api-extractor-test-01 (npm)

Published May 16, 2022
MAL-2023-1039

Malicious code in storyblok-bridge (npm)

Published Aug 1, 2023
GHSA-569q-mpph-wgww

Better Auth affected by external request basePath modification DoS

Published Dec 1, 2025
MAL-2023-1040

Malicious code in testhacknowz (npm)

Published Aug 1, 2023
CVE-2016-10671HIGH

Downloads Resources over HTTP in mystem-wrapper

Published Feb 18, 2019
MAL-2025-192480

Malicious code in elf-stats-caroling-hammer-382 (npm)

Published Dec 11, 2025
MAL-2025-192626

Malicious code in elf-stats-cocoa-workshop-459 (npm)

Published Dec 19, 2025
GHSA-wxw2-rwmh-vr8f

electerm: electerm_install_script_CommandInjection Vulnerability Report

Published Apr 16, 2026
MAL-2022-1106

Malicious code in arm-storsimple1200series (npm)

Published Jun 20, 2022
MAL-2025-192768

Malicious code in elf-stats-flickering-satchel-815 (npm)

Published Dec 23, 2025
CVE-2026-3419

Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation

Published Mar 5, 2026
GHSA-57gh-m6rq-54cf

OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration

Published Apr 3, 2026
CVE-2016-10620HIGH

Downloads Resources over HTTP in atom-node-module-installer

Published Feb 18, 2019
MAL-2022-115

Malicious code in @azure-tests/perf-storage-file-share-track-1 (npm)

Published Jun 20, 2022
GHSA-cqgw-44wg-44rf

OpenClaw: Discord voice manager bypasses channel-level member access allowlist

Published Apr 3, 2026
GHSA-x428-ghpx-8j92

@fastify/static vulnerable to route guard bypass via encoded path separators

Published Apr 16, 2026
MAL-2022-1157

Malicious code in atlas-custom-behaviour (npm)

Published Jun 20, 2022
MAL-2025-192143

Malicious code in elf-stats-snowy-candy-850 (npm)

Published Dec 3, 2025
MAL-2024-7251

Malicious code in @zitterorg/iusto-iusto-quasi (npm)

Published Jul 4, 2024
MAL-2023-1070

Malicious code in @freestarcapital/collector-pipeline (npm)

Published Aug 9, 2023
GHSA-j4c9-w69r-cw33

OpenClaw: Telegram DM-Scoped Inline Button Callbacks Bypass DM Pairing and Mutate Session State

Published Mar 29, 2026
CVE-2022-27139CRITICAL

Arbitrary file upload in Ghost

Published Apr 13, 2022
CVE-2019-13173HIGH

Arbitrary File Overwrite in fstream

Published May 30, 2019
MAL-2023-109

Malicious code in athulkrishnan_test_package (npm)

Published Jul 26, 2023
GHSA-5c6j-r48x-rmvq

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Published Feb 28, 2026
MAL-2024-10477

Malicious code in chat-history-log-viewer (npm)

Published Nov 6, 2024
MAL-2024-8572

Malicious code in @diotoborg/quis-tempore-distinctio (npm)

Published Sep 2, 2024
MAL-2025-192100

Malicious code in elf-stats-mulled-drum-529 (npm)

Published Dec 3, 2025
MAL-2025-3726

Malicious code in com.unity.cluster-display (npm)

Published May 10, 2025
CVE-2025-57283

BrowserStack Local vulnerable to Command Injection through logfile variable

Published Jan 28, 2026
MAL-2025-192279

Malicious code in elf-stats-candystriped-chimney-879 (npm)

Published Dec 3, 2025
MAL-2025-192297

Malicious code in elf-stats-bright-cocoa-293 (npm)

Published Dec 4, 2025
MAL-2025-40

Malicious code in solana-stable-web-huks (npm)

Published Jan 10, 2025
GHSA-j8j5-7r4h-vj2g

DbGate has cross site scripting via the SVG Icon String Handler component

Published Apr 13, 2026
MAL-2025-192326

Malicious code in elf-stats-candlelit-hollyberry-248 (npm)

Published Dec 5, 2025
GHSA-mj4p-rc52-m843

OpenClaw: Sandbox staged writes could escape the verified parent directory before commit

Published Mar 13, 2026
MAL-2024-11104

Malicious code in ssc-ui-static (npm)

Published Nov 27, 2024
CVE-2026-21894

n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

Published Jan 7, 2026
CVE-2026-32302

OpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy mode

Published Mar 12, 2026
GHSA-xhmj-rg95-44hv

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

Published Apr 16, 2026
MAL-2025-191957

Malicious code in elf-stats-sparkly-hammer-880 (npm)

Published Dec 3, 2025
MAL-2025-192242

Malicious code in elf-stats-whimsical-chimney-949 (npm)

Published Dec 3, 2025
CVE-2026-33940

Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

Published Mar 27, 2026
CVE-2026-22594

Ghost has Staff 2FA bypass

Published Jan 8, 2026
MAL-2024-8250

Malicious code in @diotoborg/dolores-iusto (npm)

Published Sep 2, 2024
CVE-2026-26862

CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage

Published Feb 27, 2026
MAL-2026-1162

Malicious code in xpack-test-3.0 (npm)

Published Mar 3, 2026
GHSA-5gjc-grvm-m88j

OpenClaw: Memory dreaming config persistence was reachable from operator.write commands

Published Apr 17, 2026
MAL-2026-2730

Malicious code in browserstack-utils (npm)

Published Apr 16, 2026
MAL-2022-1312

Malicious code in azure-container-registry-samples-ts (npm)

Published Jun 20, 2022
MAL-2025-2760

Malicious code in f0-state-holder-duke (npm)

Published Mar 28, 2025
MAL-2025-3085

Malicious code in @harvest-finance/harvest-strategy-polygon (npm)

Published Apr 3, 2025
MAL-2025-3224

Malicious code in @bane-mlb/less-styles (npm)

Published Apr 17, 2025
GHSA-736r-jwj6-4w23

OpenClaw: Sandboxed agents could escape exec routing via host=node override

Published Apr 17, 2026
MAL-2023-1303

Malicious code in spring-boot-admin-virgil-custom-ui (npm)

Published May 3, 2023
CVE-2018-3787HIGH

simplehttpserver allows directory traversal and file listing

Published Sep 6, 2018
MAL-2025-192540

Malicious code in elf-stats-twinkling-wishlist-283 (npm)

Published Dec 11, 2025
MAL-2023-1305

Malicious code in stateful-fastclick (npm)

Published May 1, 2023
MAL-2023-1310

Malicious code in stripe-terminal-react-native (npm)

Published May 20, 2023
MAL-2026-3037

Malicious code in standalone-apps (npm)

Published Apr 25, 2026
CVE-2020-7603CRITICAL

OS Command Injection in closure-compiler-stream

Published May 7, 2021
GHSA-xr8f-h2gw-9xh6

OAuth 2.1 Provider: Unprivileged users can register OAuth clients

Published Apr 16, 2026
MAL-2026-2731

Malicious code in buildkite-test-collector-cypress-example (npm)

Published Apr 16, 2026
MAL-2025-1608

Malicious code in material-start (npm)

Published Feb 28, 2025
CVE-2022-37260HIGH

steal vulnerable to Regular Expression Denial of Service via input variable

Published Sep 16, 2022
MAL-2023-1353

Malicious code in zsbpwebsdktest3 (npm)

Published May 1, 2023
CVE-2025-69981

FUXA contains an Unrestricted File Upload vulnerability

Published Feb 3, 2026
MAL-2023-1438

Malicious code in exp-core-style (npm)

Published Aug 10, 2023
MAL-2026-3054

Malicious code in @apple-pay-trust/start (npm)

Published Apr 25, 2026
MAL-2025-190673

Malicious code in @posthog/rrweb (npm)

Published Nov 24, 2025
GHSA-7g8c-cfr3-vqqr

OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input

Published Apr 17, 2026
MAL-2022-110

Malicious code in @azure-tests/perf-service-bus-track-1 (npm)

Published Jun 20, 2022
GHSA-h43v-27wg-5mf9

OpenClaw: Forged Nostr DMs could create pairing state before signature verification

Published Apr 7, 2026
MAL-2026-3055

Malicious code in @apple-pay-trust/validate-merchant (npm)

Published Apr 25, 2026
CVE-2021-27516HIGH

URIjs Hostname spoofing via backslashes in URL

Published Mar 1, 2021
MAL-2025-190715

Malicious code in @asyncapi/java-spring-cloud-stream-template (npm)

Published Nov 24, 2025
MAL-2022-1178

Malicious code in automate-loadtest-action (npm)

Published Jun 20, 2022
MAL-2026-3053

Malicious code in @apple-pay-trust/merchant-session (npm)

Published Apr 25, 2026
MAL-2026-3057

Malicious code in @clearpool/streaming (npm)

Published Apr 26, 2026
CVE-2018-3711HIGH

Denial of Service vulnerability with large JSON payloads in fastify

Published Jul 18, 2018
MAL-2022-1459

Malicious code in bankin_thechnical_test (npm)

Published Jun 20, 2022
CVE-2020-15092HIGH

Stored XSS in TimelineJS3

Published Jul 9, 2020
MAL-2026-3061

Malicious code in @google-pay-trust/authorize-payment (npm)

Published Apr 25, 2026
MAL-2022-146

Malicious code in @bootstrap-base-design/bootstrap-base (npm)

Published Jun 20, 2022
MAL-2026-3062

Malicious code in @google-pay-trust/cancelled (npm)

Published Apr 25, 2026
MAL-2026-3063

Malicious code in @google-pay-trust/finish (npm)

Published Apr 25, 2026
CVE-2021-4299MEDIUM

string-kit Inefficient Regular Expression Complexity vulnerability

Published Jan 2, 2023
CVE-2026-32020

OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read

Published Mar 2, 2026
MAL-2026-3073

Malicious code in @tw-utils/static (npm)

Published Apr 25, 2026
MAL-2025-191277

Malicious code in @oku-ui/toast (npm)

Published Nov 25, 2025
CVE-2016-10643HIGH

Downloads Resources over HTTP in jstestdriver

Published Aug 15, 2018
GHSA-5h2w-qmfp-ggp6

OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`

Published Mar 31, 2026
MAL-2025-192864

Malicious code in stream-chain-xor (npm)

Published Dec 23, 2025
MAL-2025-192174

Malicious code in elf-stats-sugarplum-stockpile-238 (npm)

Published Dec 3, 2025
MAL-2025-192178

Malicious code in elf-stats-tinsel-pantry-856 (npm)

Published Dec 3, 2025
GHSA-pqhr-mp3f-hrpp

Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters

Published Mar 31, 2026
CVE-2022-3224MEDIUM

parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing

Published Sep 16, 2022
MAL-2023-1482

Malicious code in skills-strategy-client (npm)

Published Aug 15, 2023
MAL-2025-192208

Malicious code in elf-stats-cranberry-hollyberry-804 (npm)

Published Dec 3, 2025
MAL-2026-626

Malicious code in react-toast-cold (npm)

Published Jan 28, 2026
MAL-2025-192225

Malicious code in elf-stats-nutmeg-stockpile-999 (npm)

Published Dec 3, 2025
CVE-2022-37266CRITICAL

steal vulnerable to Prototype Pollution via key variable in babel.js

Published Sep 16, 2022
MAL-2022-1313

Malicious code in azure-core-rest-pipeline (npm)

Published Jun 20, 2022
MAL-2022-1314

Malicious code in azure-core-rest-pipeline-js (npm)

Published Jun 20, 2022
CVE-2025-66398

Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)

Published Jan 2, 2026
GHSA-pw7h-9g6p-c378

OpenClaw: Tlon settings empty-allowlist reconciliation bypassed intended revocation

Published Mar 26, 2026
MAL-2025-192284

Malicious code in elf-stats-sprucey-fireplace-355 (npm)

Published Dec 3, 2025
CVE-2026-30945

StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service

Published Mar 11, 2026
MAL-2022-1328

Malicious code in azure-eventhubs-checkpointstore (npm)

Published Jun 20, 2022
MAL-2023-1493

Malicious code in postman-zendesk-support-theme (npm)

Published Aug 19, 2023
MAL-2025-192300

Malicious code in elf-stats-marzipan-cocoa-562 (npm)

Published Dec 4, 2025
GHSA-w626-296m-8f85

Duplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints

Published May 11, 2026
MAL-2025-192335

Malicious code in elf-stats-mulled-snowglobe-636 (npm)

Published Dec 5, 2025
CVE-2026-32978

OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity

Published Mar 13, 2026
MAL-2025-192337

Malicious code in elf-stats-shimmering-garland-476 (npm)

Published Dec 5, 2025
CVE-2026-28398

NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells

Published Mar 3, 2026
MAL-2025-192344

Malicious code in elf-stats-whimsical-pantry-974 (npm)

Published Dec 5, 2025
MAL-2024-9319

Malicious code in a-lbum-do-wnload-avai-lable-file-2016-44588-my-wild-west-fzmj0-gpjzue (npm)

Published Oct 16, 2024
GHSA-qf48-qfv4-jjm9

OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image

Published Mar 31, 2026
MAL-2024-9344

Malicious code in availab-le-alb-um-zip-25931-the-life-aquatic-studio-sessions-mocn6-tnmvnd (npm)

Published Oct 16, 2024
MAL-2022-1361

Malicious code in azure-package-name-test (npm)

Published Jun 20, 2022
MAL-2025-3698

Malicious code in substrate-faucet (npm)

Published May 5, 2025
MAL-2023-1512

Malicious code in browserslist-config-usaa (npm)

Published Aug 21, 2023
MAL-2025-192345

Malicious code in native-component-list (npm)

Published Dec 5, 2025
GHSA-pg8g-f2hf-x82m

Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects

Published Apr 9, 2026
MAL-2025-192481

Malicious code in elf-stats-caroling-sled-530 (npm)

Published Dec 11, 2025
CVE-2026-31856

Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL

Published Mar 11, 2026
MAL-2022-1370

Malicious code in azure-schema-registry-avro (npm)

Published Jun 20, 2022
CVE-2019-16303CRITICAL

JHipster Kotlin using insecure source of randomness `RandomStringUtils` before v1.2.0

Published Jun 26, 2020
MAL-2022-1371

Malicious code in azure-schema-registry-avro-js (npm)

Published Jun 20, 2022
CVE-2023-26492MEDIUM

Directus vulnerable to Server-Side Request Forgery On File Import

Published Mar 3, 2023
MAL-2022-1372

Malicious code in azure-schema-registry-avro-ts (npm)

Published Jun 20, 2022
MAL-2022-1373

Malicious code in azure-schema-registry-js (npm)

Published Jun 20, 2022
MAL-2025-192262

Malicious code in elf-stats-joyous-hollyberry-121 (npm)

Published Dec 3, 2025
MAL-2022-1383

Malicious code in azure-storage-queue (npm)

Published Jun 20, 2022
MAL-2022-1624

Malicious code in blockstream-adapter (npm)

Published Jun 20, 2022
CVE-2024-47762

Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend

Published Oct 3, 2024
MAL-2022-1639

Malicious code in body-string-rest (npm)

Published Jun 20, 2022
MAL-2025-2335

Malicious code in ward-steward (npm)

Published Mar 12, 2025
CVE-2022-2900CRITICAL

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url

Published Sep 15, 2022
CVE-2016-10677HIGH

Downloads Resources over HTTP in google-closure-tools-latest

Published Feb 18, 2019
CVE-2024-29181LOW

@strapi/plugin-content-manager leaks data via relations via the Admin Panel

Published Jun 12, 2024
MAL-2023-1531

Malicious code in usaa-qtest-reporter (npm)

Published Aug 21, 2023
CVE-2022-31170HIGH

OpenZeppelin Contracts's ERC165Checker may revert instead of returning false

Published Jul 21, 2022
MAL-2022-1649

Malicious code in bootstrap-base-design (npm)

Published Jun 20, 2022
GHSA-94pw-c6m8-p9p9

OpenClaw: Gateway operator.write Can Reach Admin-Class Channel Allowlist Persistence via chat.send

Published Mar 30, 2026
MAL-2026-2526

Malicious code in request-js-validator (npm)

Published Apr 6, 2026
CVE-2026-27610

Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

Published Feb 25, 2026
MAL-2022-1650

Malicious code in bootstrap-base-managed-designs (npm)

Published Jun 20, 2022
MAL-2022-1651

Malicious code in bootstrap-base-nabtrade-design (npm)

Published Jun 20, 2022
MAL-2022-1394

Malicious code in azurearctest (npm)

Published Jun 20, 2022
CVE-2018-16474MEDIUM

Stored Cross-Site Scripting in tianma-static

Published Nov 6, 2018
MAL-2025-192964

Malicious code in @peter_wilson12091/internal-json-test-parser (npm)

Published Dec 30, 2025
MAL-2025-48762

Malicious code in shutterstock-cli (npm)

Published Oct 22, 2025
MAL-2025-2703

Malicious code in requestz-promises (npm)

Published Mar 25, 2025
MAL-2025-4924

Malicious code in ac-shared-instance (npm)

Published Jun 11, 2025
CVE-2026-4040

OpenClaw safeBins file-existence oracle information disclosure

Published Feb 19, 2026
MAL-2026-219

Malicious code in firestore-types (npm)

Published Jan 12, 2026
MAL-2022-160

Malicious code in @bynder-private/persistgraphql-webpack-plugin (npm)

Published Jun 20, 2022
CVE-2026-22686

enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain

Published Jan 14, 2026
MAL-2022-1550

Malicious code in bfx-stuff-ui (npm)

Published Jun 20, 2022
MAL-2022-1564

Malicious code in bifrostmigrationmonitor (npm)

Published Jul 21, 2022
CVE-2025-67419

evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API

Published Jan 5, 2026
MAL-2022-1648

Malicious code in bootlstap (npm)

Published Aug 19, 2022
CVE-2026-27670

OpenClaw: ZIP extraction race could write outside destination via parent symlink rebind

Published Mar 3, 2026
MAL-2025-3906

Malicious code in mobile-test-px (npm)

Published May 16, 2025
CVE-2020-27666MEDIUM

Cross-site Scripting in Strapi

Published Oct 29, 2020
CVE-2020-36851

cors-anywhere vulnerable to server-side request forgery

Published Sep 25, 2025
MAL-2022-166

Malicious code in @ch-post-common/common-web-frontend (npm)

Published Jun 20, 2022
MAL-2025-3947

Malicious code in cp-area-nao-correntista-fgts-ui (npm)

Published May 15, 2025
MAL-2026-3494

Malicious code in @tanstack/virtual-file-routes (npm)

Published May 12, 2026
MAL-2024-12009

Malicious code in network-test-poc (npm)

Published Dec 19, 2024
MAL-2026-3544

Malicious code in @uipath/filesystem (npm)

Published May 12, 2026
CVE-2016-10657HIGH

Downloads Resources over HTTP in co-cli-installer

Published Feb 18, 2019
CVE-2026-26318

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

Published Feb 18, 2026
GHSA-82qx-6vj7-p8m2

OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows

Published Apr 17, 2026
CVE-2026-22168

OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing arguments

Published Mar 2, 2026
CVE-2025-66415

fastify-reply-from affected by bypass of reply forwarding

Published Dec 2, 2025
CVE-2021-43783HIGH

Path Traversal in @backstage/plugin-scaffolder-backend

Published Dec 1, 2021
MAL-2024-9278

Malicious code in ts-jest-starter-kit (npm)

Published Oct 11, 2024
MAL-2024-8895

Malicious code in bamoe-standalone-dmn-editor (npm)

Published Sep 18, 2024
MAL-2022-177

Malicious code in @codahosted/fetlife-assets (npm)

Published Jun 20, 2022
CVE-2026-34210HIGH
Risk: 40.51/100

mppx has Stripe charge credential replay via missing idempotency check

Published Mar 29, 2026
MAL-2025-192665

Malicious code in baidu-tester (npm)

Published Dec 19, 2025
MAL-2025-3561

Malicious code in customprefix-auth (npm)

Published May 1, 2025
MAL-2025-47346

Malicious code in rxnt-healthchecks-nestjs (npm)

Published Sep 16, 2025
GHSA-72gr-qfp7-vwhw

h3: Double Decoding in `serveStatic` Bypasses `resolveDotSegments` Path Traversal Protection via `%252e%252e`

Published Mar 20, 2026
MAL-2025-192336

Malicious code in elf-stats-northbound-drum-422 (npm)

Published Dec 5, 2025
CVE-2017-15879HIGH

Keystone is vulnerable to CSV injection

Published Nov 16, 2017
MAL-2025-2377

Malicious code in dingpengtest-ui (npm)

Published Mar 14, 2025
MAL-2025-3166

Malicious code in stormapp765 (npm)

Published Apr 7, 2025
MAL-2025-1341

Malicious code in gemini-test (npm)

Published Feb 13, 2025
GHSA-q2qc-744p-66r2

OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility

Published Mar 29, 2026
MAL-2025-2711

Malicious code in standard-demo (npm)

Published Mar 25, 2025
MAL-2022-181

Malicious code in @contrast-security-inc/design-system-foundations (npm)

Published Jun 20, 2022
MAL-2025-2716

Malicious code in vistar-ad-clienttestadv3 (npm)

Published Mar 25, 2025
MAL-2025-191996

Malicious code in elf-stats-candlelit-toy-571 (npm)

Published Dec 3, 2025
MAL-2022-1203

Malicious code in aws-solutions-constructs (npm)

Published Jun 20, 2022
MAL-2025-192020

Malicious code in elf-stats-evergreen-chimney-857 (npm)

Published Dec 3, 2025
CVE-2016-1000232MEDIUM

ReDoS via long string of semicolons in tough-cookie

Published Oct 10, 2018
MAL-2025-3627

Malicious code in istanbul-reporter-lcov (npm)

Published May 6, 2025
CVE-2020-13961MEDIUM

Improper Input Validation in strapi

Published May 24, 2022
CVE-2018-14040MEDIUM

Bootstrap vulnerable to Cross-Site Scripting (XSS)

Published May 13, 2022
CVE-2026-25957

Cube Core is vulnerable to Denial of Service (DoS) via crafted request

Published Feb 10, 2026
CVE-2026-32017

OpenClaw exec allowlist safeBins short-option bypass could permit arbitrary file write

Published Mar 3, 2026
CVE-2023-28155MEDIUM

Server-Side Request Forgery in Request

Published Mar 16, 2023
CVE-2026-27980

Next.js: Unbounded next/image disk cache growth can exhaust storage

Published Mar 17, 2026
CVE-2018-20677MEDIUM

bootstrap Cross-site Scripting vulnerability

Published Jan 17, 2019
MAL-2022-1856

Malicious code in cdk-fargate-fastautlscaler (npm)

Published Jun 20, 2022
CVE-2026-32731

ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

Published Mar 18, 2026
CVE-2018-16489CRITICAL

Prototype Pollution in just-extend

Published Feb 7, 2019
CVE-2026-32023

OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode

Published Mar 3, 2026
MAL-2022-207

Malicious code in @dqwdqwas/testconf (npm)

Published Jun 20, 2022
MAL-2022-1926

Malicious code in client-sdk-contract-tests (npm)

Published Jun 20, 2022
MAL-2022-1929

Malicious code in clinstestpackage (npm)

Published May 16, 2022
GHSA-ch86-pxr9-j9h9

Duplicate Advisory: OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter

Published Apr 3, 2026
MAL-2026-2696

Malicious code in bfx-hf-strategy-perf (npm)

Published Apr 15, 2026
CVE-2026-33937

Handlebars.js has JavaScript Injection via AST Type Confusion

Published Mar 27, 2026
CVE-2026-32774

Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling

Published Mar 16, 2026
MAL-2026-2094

Malicious code in pulse-scroll-triggered-list-items (npm)

Published Mar 23, 2026
CVE-2019-5416HIGH

Path Traversal in localhost-now

Published Mar 25, 2019
MAL-2022-1991

Malicious code in coldstone-sls (npm)

Published May 16, 2022
MAL-2026-3064

Malicious code in @google-pay-trust/init-google-pay (npm)

Published Apr 25, 2026
MAL-2026-3653

Malicious code in @design-system-coopeuch/web (npm)

Published May 13, 2026
MAL-2026-3215

Malicious code in archetype-style (npm)

Published May 1, 2026
CVE-2025-59471

Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration

Published Jan 27, 2026
MAL-2026-3412

Malicious code in post-purchase-bundler (npm)

Published May 10, 2026
GHSA-wxq7-x3qp-vcr8

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

Published Jun 12, 2026
CVE-2021-25952CRITICAL

Prototype polluation in just-safe-set

Published Dec 10, 2021
CVE-2026-25528

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

Published Feb 9, 2026
CVE-2026-27183

OpenClaw: system.run wrapper-depth boundary could skip shell approval gating

Published Mar 9, 2026
CVE-2019-15478MEDIUM

Cross-Site Scripting in status-board

Published Sep 23, 2019
CVE-2026-32913

OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects

Published Mar 9, 2026
MAL-2022-2432

Malicious code in dependency-confusion-art-test2 (npm)

Published Jun 20, 2022
MAL-2022-5061

Malicious code in omar-evil-test-rpp (npm)

Published Jun 20, 2022
GHSA-6q2v-vfwp-pvwh

Duplicate Advisory: OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path

Published Mar 29, 2026
CVE-2026-32730

ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

Published Mar 18, 2026
MAL-2025-192332

Malicious code in elf-stats-flickering-lantern-502 (npm)

Published Dec 5, 2025
MAL-2025-192333

Malicious code in elf-stats-lanternlit-saddlebag-279 (npm)

Published Dec 5, 2025
GHSA-9ppg-jx86-fqw7

Unauthorized npm publish of cline@2.3.0 with modified postinstall script

Published Feb 19, 2026
MAL-2022-2637

Malicious code in dynamic-virtualized-list (npm)

Published Jun 20, 2022
CVE-2022-22138HIGH

Uncontrolled Resource Consumption in fast-string-search

Published Jun 18, 2022
CVE-2025-27097

Cache variables with the operations when transforms exist on the root level even if variables change in the further requests with the same operation

Published Oct 10, 2023
CVE-2021-36383MEDIUM

Xen Orchestra Mishandles Authorization

Published May 24, 2022
CVE-2026-23634

Pepr Has Overly Permissive RBAC ClusterRole in Admin Mode

Published Jan 15, 2026
GHSA-6rmx-gvvg-vh6j

OpenClaw's hooks count non-POST requests toward auth lockout

Published Mar 9, 2026
CVE-2024-57556

Cross Site Scripting vulnerability in store2

Published Jan 24, 2025
CVE-2025-6514

mcp-remote exposed to OS command injection via untrusted MCP server connections

Published Jul 9, 2025
MAL-2022-2193

Malicious code in core-guest-spa (npm)

Published Jun 20, 2022
CVE-2025-1520

PostHog Plugin Server SQL Injection Vulnerability

Published Apr 23, 2025
MAL-2026-4804

Malicious code in @leviyuan/lodestar (npm)

Published May 26, 2026
MAL-2026-4037

Malicious code in @antv/l7-district (npm)

Published May 19, 2026
CVE-2025-1398

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

Published Mar 17, 2025
MAL-2022-3678

Malicious code in hosted-checkout-tutorial (npm)

Published Jun 20, 2022
MAL-2026-4251

Malicious code in harmony-enablers-test-2026 (npm)

Published May 22, 2026
CVE-2020-7696MEDIUM

Credential leak in react-native-fast-image

Published May 18, 2021
MAL-2022-3680

Malicious code in hpathexists (npm)

Published Aug 19, 2022
MAL-2026-4849

Malicious code in @service-suppliers/fetch_suppliers_country_list_action_saga (npm)

Published May 28, 2026
MAL-2026-4850

Malicious code in @service-suppliers/reset_country_list (npm)

Published May 28, 2026
MAL-2026-4851

Malicious code in @service-suppliers/set_country_list (npm)

Published May 28, 2026
MAL-2026-4855

Malicious code in @service-suppliers/set_suppliers_loading_start (npm)

Published May 28, 2026
CVE-2022-37265CRITICAL

steal vulnerable to Prototype Pollution via alias variable

Published Sep 21, 2022
MAL-2022-1364

Malicious code in azure-purview-administration (npm)

Published Jun 20, 2022
GHSA-7437-7hg8-frrw

OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)

Published Apr 9, 2026
CVE-2023-35926HIGH

Backstage Scaffolder plugin has insecure sandbox

Published Jun 21, 2023
CVE-2017-16165HIGH

Directory Traversal in calmquist.static-server

Published Jul 23, 2018
MAL-2026-4169

Malicious code in paysafe-gbp-virtual-assistant-lib-fe (npm)

Published May 19, 2026
MAL-2026-5645

Malicious code in sn-internal-test (npm)

Published Jun 11, 2026
CVE-2022-31070MEDIUM

Potential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

Published Jun 17, 2022
MAL-2022-4379

Malicious code in logi-bootstrap (npm)

Published Jun 20, 2022
MAL-2026-5646

Malicious code in sn-internal-testjgsakjdkjadkjahsdkjad (npm)

Published Jun 11, 2026
CVE-2021-32809MEDIUM

Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality

Published Aug 23, 2021
MAL-2022-4382

Malicious code in loglongakamairequest (npm)

Published Jun 20, 2022
MAL-2022-238

Malicious code in @epc-infra/clinstestpackage (npm)

Published May 16, 2022
MAL-2022-4492

Malicious code in material-ui-plugin-styles-provider-cache (npm)

Published Jun 30, 2022
CVE-2026-32050

OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 3, 2026
GHSA-wxf3-4fvj-vqqx

Unsafe plugins can be installed via pack import by tenant admins

Published Jul 27, 2023
MAL-2022-4503

Malicious code in mattermost-plugin-docs (npm)

Published Jun 20, 2022
MAL-2026-4934

Malicious code in @cloudplatform-single-spa/ml-ai-agents-agent-system (npm)

Published May 28, 2026
MAL-2022-4504

Malicious code in mattermost-push-proxy (npm)

Published Jun 20, 2022
CVE-2026-32037

OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists

Published Mar 3, 2026
MAL-2022-2591

Malicious code in dreactbvotstrap (npm)

Published Aug 19, 2022
MAL-2022-2646

Malicious code in ea-test-helpers (npm)

Published Jun 20, 2022
GHSA-wpc6-37g7-8q4w

OpenClaw: Shell init-file options could satisfy exec allowlist script matching

Published Apr 7, 2026
MAL-2026-680

Malicious code in frontend-js-state-web (npm)

Published Feb 3, 2026
MAL-2026-5689

Malicious code in ecto-rust-read-f3a9c1 (npm)

Published Jun 12, 2026
CVE-2026-33331

oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify

Published Mar 20, 2026
MAL-2022-6295

Malicious code in starlink2 (npm)

Published Jul 25, 2022
CVE-2026-27959

Koa has Host Header Injection via ctx.hostname

Published Feb 26, 2026
MAL-2022-2474

Malicious code in dinesh-dev-nagajikkktest11223qa (npm)

Published Jun 20, 2022
MAL-2026-5014

Malicious code in @mlspace/dtransfer-history (npm)

Published May 28, 2026
MAL-2026-5703

Malicious code in eslint-plugin-mistica-local-rules (npm)

Published Jun 12, 2026
MAL-2022-4632

Malicious code in mitui-util-test (npm)

Published Jun 20, 2022
CVE-2024-34448HIGH

Ghost allows CSV Injection during member CSV export

Published May 22, 2024
GHSA-x8rx-789c-2pxq

RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests

Published Apr 8, 2026
MAL-2022-4556

Malicious code in mephisto-task-compiler (npm)

Published Jun 20, 2022
MAL-2022-4557

Malicious code in mephisto-worker-experience (npm)

Published Jun 21, 2022
CVE-2023-25571MEDIUM

Cross site scripting Vulnerability in backstage Software Catalog

Published Feb 14, 2023
MAL-2026-5715

Malicious code in workflow-postgres-setup (npm)

Published Jun 12, 2026
CVE-2026-34825
Risk: 0.01/100

NocoBase Has SQL Injection via template variable substitution in workflow SQL node

Published Apr 1, 2026
CVE-2026-32898

OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata

Published Feb 27, 2026
CVE-2025-65964

n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook

Published Dec 8, 2025
MAL-2022-1147

Malicious code in astar-portal-test-depconf (npm)

Published Jul 25, 2022
CVE-2026-28357

NocoDB has Stored Cross-site Scripting via Formula Cell

Published Mar 2, 2026
CVE-2026-31828

Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction

Published Mar 11, 2026
MAL-2026-5076

Malicious code in private-next-instrumentation-client (npm)

Published May 29, 2026
MAL-2022-3234

Malicious code in fstream-package-2 (npm)

Published Jun 20, 2022
MAL-2026-5741

Malicious code in @achuthvp/postinstall-poc (npm)

Published Jun 13, 2026
CVE-2022-24794HIGH

URL Redirection to Untrusted Site ('Open Redirect') in express-openid-connect

Published Mar 31, 2022
MAL-2022-4767

Malicious code in mynewpkgtest (npm)

Published Jun 20, 2022
MAL-2022-4808

Malicious code in netlify-testing-stuff (npm)

Published Jun 20, 2022
MAL-2026-5327

Malicious code in @listings/energy-labels (npm)

Published Jun 8, 2026
MAL-2026-5328

Malicious code in @zimmo/last_search (npm)

Published Jun 8, 2026
MAL-2026-5748

Malicious code in chai-utils-test (npm)

Published Jun 13, 2026
CVE-2024-36287LOW

Mattermost Desktop App allows for bypassing TCC restrictions on macOS

Published Jun 14, 2024
MAL-2024-10545

Malicious code in refocus-sgt-trust1 (npm)

Published Nov 10, 2024
MAL-2022-1329

Malicious code in azure-eventhubs-checkpointstore-blob (npm)

Published Jun 20, 2022
CVE-2026-33624

Parse Server: MFA recovery code single-use bypass via concurrent requests

Published Mar 24, 2026
MAL-2025-191988

Malicious code in elf-stats-aurora-candy-291 (npm)

Published Dec 3, 2025
MAL-2025-191989

Malicious code in elf-stats-aurora-garland-513 (npm)

Published Dec 3, 2025
CVE-2026-32308

OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")

Published Mar 13, 2026
MAL-2022-1132

Malicious code in ashion-ingest (npm)

Published Jun 20, 2022
MAL-2024-8917

Malicious code in ibm-strings (npm)

Published Sep 19, 2024
MAL-2025-190881

Malicious code in @posthog/gitub-star-sync-plugin (npm)

Published Nov 24, 2025
GHSA-7rx3-28cr-v5wh

Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry

Published Mar 29, 2026
CVE-2017-16084HIGH

Directory Traversal in list-n-stream

Published Jul 24, 2018
MAL-2025-191495

Malicious code in @bingads-webui-clientcenter/instrumentation (npm)

Published Dec 1, 2025
MAL-2026-1966

Malicious code in restaking-apy-module (npm)

Published Mar 20, 2026
MAL-2025-5014

Malicious code in test.reativity.package (npm)

Published Jun 17, 2025
MAL-2026-3365

Malicious code in @b2bneo-rest/api-csf (npm)

Published May 7, 2026
GHSA-2f7j-rp58-mr42

OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients

Published Apr 7, 2026
CVE-2017-16029HIGH

Directory Traversal in hostr

Published Nov 9, 2018
MAL-2025-191990

Malicious code in elf-stats-aurora-workbench-513 (npm)

Published Dec 3, 2025
MAL-2025-192160

Malicious code in elf-stats-sprucey-train-471 (npm)

Published Dec 3, 2025
MAL-2025-192204

Malicious code in elf-stats-caroling-mailbag-397 (npm)

Published Dec 3, 2025
MAL-2022-1369

Malicious code in azure-schema-registry (npm)

Published Jun 20, 2022
MAL-2025-47463

Malicious code in fast-httpx (npm)

Published Sep 19, 2025
CVE-2021-39134HIGH

@npmcli/arborist vulnerable to UNIX Symbolic Link (Symlink) Following

Published Aug 31, 2021
CVE-2017-16026MEDIUM

Remote Memory Exposure in request

Published Nov 9, 2018
MAL-2022-6311

Malicious code in storage-file-datalake (npm)

Published Jun 20, 2022
MAL-2022-6057

Malicious code in sfdc-stream (npm)

Published Jun 20, 2022
CVE-2023-22621HIGH

Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin

Published Apr 19, 2023
MAL-2022-6327

Malicious code in strip-json-combmentd (npm)

Published Aug 19, 2022
MAL-2025-47919

Malicious code in @winstan/binston (npm)

Published Oct 7, 2025
MAL-2025-5958

Malicious code in string-parser-utils (npm)

Published Jul 15, 2025
MAL-2022-1433

Malicious code in babelpreset4stag3 (npm)

Published Aug 19, 2022
MAL-2025-48028

Malicious code in func-analyst (npm)

Published Oct 8, 2025
MAL-2022-4663

Malicious code in modernizr-custom (npm)

Published Jun 20, 2022
GHSA-2mc2-g238-722j

OpenClaw affected by iMessage remote attachment SCP hardening (strict host-key checks and remoteHost validation)

Published Mar 3, 2026
CVE-2025-25289

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
MAL-2022-163

Malicious code in @calcalist/fetlife-assets (npm)

Published Jun 20, 2022
CVE-2026-32029

OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

Published Mar 3, 2026
CVE-2026-33864

Convict has Prototype Pollution via startsWith() function

Published Mar 26, 2026
MAL-2022-1595

Malicious code in bitpay-rest-client (npm)

Published Jun 20, 2022
MAL-2022-6529

Malicious code in testpkgabc (npm)

Published Jun 20, 2022
MAL-2026-3125

Malicious code in transform-regexp-constructors (npm)

Published Mar 16, 2026
MAL-2022-1714

Malicious code in buffer-auth-test (npm)

Published Jun 20, 2022
MAL-2022-6492

Malicious code in test-rule-package (npm)

Published Jun 20, 2022
MAL-2022-6493

Malicious code in test-task-react-client (npm)

Published Jun 20, 2022
MAL-2022-105

Malicious code in @azure-tests/perf-keyvault-keys (npm)

Published Jun 20, 2022
MAL-2022-6524

Malicious code in testingx (npm)

Published May 16, 2022
MAL-2022-1077

Malicious code in apth-exists (npm)

Published Aug 19, 2022
MAL-2022-1085

Malicious code in argo-hosting-api (npm)

Published May 31, 2022
CVE-2026-25631

n8n's domain allowlist bypass enables credential exfiltration

Published Feb 4, 2026
MAL-2022-5075

Malicious code in one-question-survey (npm)

Published Jun 20, 2022
MAL-2022-6996

Malicious code in vue-test-utils-mic (npm)

Published Jul 26, 2022
CVE-2020-26291MEDIUM

Hostname spoofing via backslashes in URL

Published Dec 30, 2020
MAL-2022-1928

Malicious code in clientlib-manifests (npm)

Published Jun 20, 2022
MAL-2022-1733

Malicious code in buy-button-storefront (npm)

Published Jun 20, 2022
MAL-2022-1295

Malicious code in azure-arm-visualstudio-samples-js-beta (npm)

Published Jun 20, 2022
MAL-2022-1990

Malicious code in coldstone-helpers (npm)

Published May 16, 2022
MAL-2022-612

Malicious code in @status-waku-voting/contracts (npm)

Published Jun 20, 2022
MAL-2022-1381

Malicious code in azure-storage-file-datalake-samples-ts (npm)

Published Jun 20, 2022
MAL-2022-1382

Malicious code in azure-storage-file-share (npm)

Published Jun 20, 2022
MAL-2022-2213

Malicious code in country-nationality-list (npm)

Published Jun 20, 2022
GHSA-86jj-29wc-7q2w

Duplicate Advisory: OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks

Published Mar 21, 2026
MAL-2022-6322

Malicious code in strapi-provider-upload-aws-s3-auth (npm)

Published Jun 20, 2022
GHSA-39pp-xp36-q6mg

OpenClaw has Inconsistent Host Exec Environment Override Sanitization

Published Mar 26, 2026
MAL-2022-2091

Malicious code in com.unity.modules.unitywebrequesttexture (npm)

Published Jun 20, 2022
MAL-2022-2933

Malicious code in ext-iconv-test (npm)

Published Jun 20, 2022
MAL-2022-2961

Malicious code in facebook-nodejs-business-sdk-tests (npm)

Published Jun 20, 2022
MAL-2022-6913

Malicious code in vhustlcfimgkwyzq (npm)

Published Jul 11, 2022
CVE-2023-32325MEDIUM

Potential for cross-site scripting in PostHog-js

Published May 22, 2023
MAL-2022-1899

Malicious code in chnifdwmostgqvyp (npm)

Published Jul 11, 2022
MAL-2022-6496

Malicious code in test2_11931193 (npm)

Published Jun 20, 2022
MAL-2022-6490

Malicious code in test-proj-for-myself (npm)

Published Jun 20, 2022
MAL-2022-2169

Malicious code in container-registry (npm)

Published Jun 20, 2022
MAL-2022-6516

Malicious code in testfromauro (npm)

Published Jun 20, 2022
MAL-2022-6522

Malicious code in testingpp (npm)

Published Jun 20, 2022
CVE-2025-32395

Vite has an `server.fs.deny` bypass with an invalid `request-target`

Published Apr 11, 2025
MAL-2022-2724

Malicious code in ember-tracked-local-storag (npm)

Published Jun 20, 2022
MAL-2022-2800

Malicious code in eslint-config-mattermost (npm)

Published Jun 20, 2022
CVE-2025-25288

@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
MAL-2022-882

Malicious code in af-test (npm)

Published Jun 20, 2022
CVE-2021-29489HIGH

Options structure open to Cross-site Scripting if passed unfiltered

Published May 6, 2021
MAL-2022-2867

Malicious code in ethereumjstox (npm)

Published Aug 19, 2022
MAL-2022-7128

Malicious code in wfs-admin-test (npm)

Published Jun 20, 2022
MAL-2022-3055

Malicious code in firstloadedvideopriorityadjuster (npm)

Published Jun 20, 2022
MAL-2022-3228

Malicious code in frontend-restclient (npm)

Published Jun 20, 2022
MAL-2022-7120

Malicious code in wf-kyt-starter (npm)

Published Jun 20, 2022
MAL-2022-7121

Malicious code in wf-kyt-starter-universal (npm)

Published Jun 20, 2022
CVE-2021-3647MEDIUM

URIjs Vulnerable to Hostname spoofing via backslashes in URL

Published Jul 19, 2021
MAL-2022-3855

Malicious code in instanthangouts (npm)

Published Jun 20, 2022
CVE-2020-26256MEDIUM

Denial of service in fast-csv

Published Dec 8, 2020
MAL-2023-1352

Malicious code in zsbpwebsdktest (npm)

Published Apr 30, 2023
MAL-2023-662

Malicious code in owa-strings (npm)

Published Mar 6, 2023
CVE-2026-29184

@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass

Published Mar 5, 2026
GHSA-8rh7-6779-cjqq

OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover

Published Apr 1, 2026
CVE-2017-16177HIGH

Directory Traversal in chatbyvista

Published Sep 1, 2020
MAL-2022-2813

Malicious code in eslint-plugin-elastic-charts (npm)

Published Jun 20, 2022
GHSA-xrgv-34cc-q765

Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution

Published Mar 19, 2026
MAL-2023-8244

Malicious code in arcotest1 (npm)

Published Sep 26, 2023
MAL-2022-477

Malicious code in @nothingfu/test (npm)

Published Jun 20, 2022
MAL-2023-8410

Malicious code in discordstream (npm)

Published Oct 31, 2023
GHSA-3cw3-5vxw-g2h3

OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials

Published Mar 31, 2026
MAL-2022-4034

Malicious code in jive-styling-toolkit (npm)

Published Jun 20, 2022
MAL-2022-4153

Malicious code in keyvault-mock-attestation (npm)

Published Jun 20, 2022
MAL-2023-694

Malicious code in presto-webui (npm)

Published Jul 14, 2023
MAL-2022-2088

Malicious code in com.unity.modules.unitywebrequest (npm)

Published Jun 20, 2022
MAL-2022-2089

Malicious code in com.unity.modules.unitywebrequestassetbundle (npm)

Published Jun 20, 2022
CVE-2026-31992

OpenClaw has allowlist exec-guard bypass via env -S

Published Mar 3, 2026
MAL-2022-268

Malicious code in @fbsystem/figma-messenger (npm)

Published Jun 20, 2022
CVE-2022-41919MEDIUM

Fastify: Incorrect Content-Type parsing can lead to CSRF attack

Published Nov 21, 2022
MAL-2023-7992

Malicious code in pingserver-test.01 (npm)

Published Sep 3, 2023
MAL-2024-10401

Malicious code in puppeteerrequestinterceptor (npm)

Published Nov 5, 2024
MAL-2023-800

Malicious code in speedtestsolo (npm)

Published Jan 18, 2023
MAL-2023-8009

Malicious code in ajaxmanager-custom (npm)

Published Apr 17, 2023
MAL-2024-10673

Malicious code in lightweight-store (npm)

Published Nov 13, 2024
CVE-2026-22704

HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover

Published Jan 13, 2026
MAL-2022-4305

Malicious code in lido-dao-test-dp (npm)

Published Jul 25, 2022
MAL-2022-4941

Malicious code in npm-test-bravol33 (npm)

Published Jun 20, 2022
MAL-2022-2165

Malicious code in constant-unifi (npm)

Published Jun 20, 2022
CVE-2026-26317

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

Published Feb 18, 2026
MAL-2022-4356

Malicious code in lodaschisstring (npm)

Published Aug 19, 2022
MAL-2023-8097

Malicious code in purplebricks-administration (npm)

Published Sep 13, 2023
MAL-2024-10924

Malicious code in dl-testes (npm)

Published Nov 25, 2024
MAL-2022-5012

Malicious code in oci-console-navigation-registry (npm)

Published Jun 20, 2022
MAL-2023-813

Malicious code in statfacepy (npm)

Published Jan 30, 2023
MAL-2024-10658

Malicious code in eslint-plugin-foody-custom (npm)

Published Nov 13, 2024
CVE-2026-22178

OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction

Published Mar 2, 2026
CVE-2017-16134HIGH

Directory Traversal in http_static_simple

Published Jul 23, 2018
MAL-2023-853

Malicious code in testben (npm)

Published Feb 6, 2023
CVE-2026-26326

OpenClaw skills.status could leak secrets to operator.read clients

Published Feb 17, 2026
MAL-2023-940

Malicious code in visual_studio_1_37_1_crack_top_activation_key_latest_2019_win_mac__2rl (npm)

Published May 9, 2023
MAL-2024-11222

Malicious code in prettier-v3-for-testing (npm)

Published Dec 6, 2024
GHSA-3p2x-hjxj-c7rv

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 21, 2026
MAL-2022-3619

Malicious code in hft-frontend-test (npm)

Published Jul 25, 2022
CVE-2021-41167HIGH

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

Published Oct 21, 2021
MAL-2024-11230

Malicious code in testing-bounty123 (npm)

Published Dec 7, 2024
MAL-2022-3056

Malicious code in firstrunwizard (npm)

Published Jun 20, 2022
MAL-2022-5084

Malicious code in ood-listener (npm)

Published Aug 19, 2022
MAL-2022-467

Malicious code in @nexthink/investigations-components (npm)

Published Oct 19, 2022
MAL-2022-4127

Malicious code in kbrstore (npm)

Published Jun 13, 2022
MAL-2024-3834

Malicious code in vscode-ui5-language-assistant (npm)

Published Jun 25, 2024
MAL-2022-2364

Malicious code in dbabelpreetstage1 (npm)

Published Aug 19, 2022
MAL-2022-5296

Malicious code in perf-storage-file-share (npm)

Published Jun 20, 2022
MAL-2022-2679

Malicious code in eg-clickstream-sdk-js (npm)

Published Jun 8, 2022
MAL-2022-6997

Malicious code in vue2-jest (npm)

Published Jun 20, 2022
MAL-2024-10755

Malicious code in marketing-jest-cli (npm)

Published Nov 14, 2024
MAL-2024-1116

Malicious code in custom-banner-react (npm)

Published Mar 18, 2024
MAL-2022-2934

Malicious code in ext-iconv-test-3 (npm)

Published Jun 20, 2022
MAL-2024-10571

Malicious code in testing-logger-bush1do-c0de (npm)

Published Nov 8, 2024
CVE-2024-48460

Eugeny Tabby Sends Password Despite Host Key Verification Failure

Published Jan 17, 2025
MAL-2023-8415

Malicious code in bonded-stablecoin (npm)

Published Nov 1, 2023
MAL-2023-8420

Malicious code in astar-portal (npm)

Published Nov 2, 2023
MAL-2022-4819

Malicious code in newhistory (npm)

Published Jun 20, 2022
MAL-2023-316

Malicious code in eumetcast-gluing (npm)

Published Jan 30, 2023
MAL-2024-7427

Malicious code in brightspot-styleguide (npm)

Published Jul 8, 2024
GHSA-8wj8-cfxr-9374

AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Published Nov 13, 2025
MAL-2024-1125

Malicious code in sqltest6 (npm)

Published Mar 18, 2024
MAL-2022-2844

Malicious code in eslintpwuginjest (npm)

Published Aug 19, 2022
MAL-2024-11018

Malicious code in web_enhance_sap-stable (npm)

Published Nov 27, 2024
MAL-2024-1393

Malicious code in nespresso-design-system (npm)

Published May 30, 2024
MAL-2024-75

Malicious code in lwc-jest-serializer (npm)

Published Jan 11, 2024
MAL-2022-4949

Malicious code in npmupload_test-xxxxxxxxxxxxx (npm)

Published May 31, 2022
GHSA-42mx-vp8m-j7qh

OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup

Published Apr 7, 2026
MAL-2024-1311

Malicious code in vue2-amis-custom-widget-kk (npm)

Published Apr 30, 2024
MAL-2024-7756

Malicious code in moto-test-int (npm)

Published Jul 15, 2024
MAL-2024-7759

Malicious code in zonduutest (npm)

Published Jul 16, 2024
MAL-2022-3441

Malicious code in gradient-stringss (npm)

Published Jun 20, 2022
CVE-2026-32728

Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries

Published Mar 16, 2026
MAL-2022-3652

Malicious code in hoisting-peer-check-child (npm)

Published Sep 13, 2022
MAL-2023-529

Malicious code in instant_verb_tables_roxanne_burns_pdf___hot___uy4 (npm)

Published May 9, 2023
MAL-2024-1676

Malicious code in world-id-onchain-starter (npm)

Published Jun 27, 2024
CVE-2026-24766

NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS

Published Jan 28, 2026
MAL-2026-4277

Malicious code in dev-env-bootstrapper (npm)

Published May 23, 2026
MAL-2023-549

Malicious code in karma-jasmine-i-request (npm)

Published Jan 30, 2023
MAL-2024-12032

Malicious code in reftest-helper (npm)

Published Dec 19, 2024
MAL-2024-8230

Malicious code in @diotoborg/distinctio-quaerat (npm)

Published Sep 2, 2024
MAL-2024-8283

Malicious code in @diotoborg/eligendi-est-unde (npm)

Published Sep 2, 2024
MAL-2024-8285

Malicious code in @diotoborg/enim-molestias (npm)

Published Sep 2, 2024
MAL-2022-3817

Malicious code in infrastructure_skypefeedback_tools (npm)

Published Jun 20, 2022
GHSA-98ch-45wp-ch47

OpenClaw: Windows-compatible env override keys could bypass system.run approval binding

Published Apr 7, 2026
CVE-2024-23724CRITICAL

Ghost has possible Cross-site Scripting issue

Published Feb 11, 2024
MAL-2024-8307

Malicious code in @diotoborg/eum-nostrum (npm)

Published Sep 2, 2024
MAL-2022-5297

Malicious code in perf-storage-file-share-track-1 (npm)

Published Jun 20, 2022
MAL-2022-7391

Malicious code in zilliqa-testing-library (npm)

Published Jun 20, 2022
GHSA-f7fh-qg34-x2xh

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets

Published Apr 17, 2026
GHSA-f934-5rqf-xx47

OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths

Published Apr 17, 2026
CVE-2025-66400

mdast-util-to-hast has unsanitized class attribute

Published Dec 2, 2025
MAL-2023-211

Malicious code in crack_vialibera_gestione_contabile_free__qls (npm)

Published May 9, 2023
MAL-2023-215

Malicious code in criteo-static-variables-datasource (npm)

Published Jun 24, 2023
MAL-2022-4262

Malicious code in launcher-start-page (npm)

Published Jun 20, 2022
MAL-2024-8466

Malicious code in @diotoborg/nisi-molestiae (npm)

Published Sep 2, 2024
GHSA-4g5x-2jfc-xm98

OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk

Published Apr 7, 2026
MAL-2022-6326

Malicious code in stringjs_lib (npm)

Published Jul 26, 2022
MAL-2023-8077

Malicious code in testingsomethingforscanner (npm)

Published Sep 11, 2023
MAL-2022-4627

Malicious code in mitui-util-bootstrap (npm)

Published Jun 20, 2022
CVE-2020-28168MEDIUM

Axios vulnerable to Server-Side Request Forgery

Published Jan 4, 2021
CVE-2020-26288HIGH

Parse Server stores password in plain text

Published Dec 28, 2020
GHSA-8g75-q649-6pv6

OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 12, 2026
GHSA-fwjq-xwfj-gv75

OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations

Published Apr 7, 2026
GHSA-527m-976r-jf79

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

Published Apr 17, 2026
CVE-2017-16152HIGH

Directory Traversal in static-html-server

Published Jul 23, 2018
MAL-2024-7718

Malicious code in stylesheeet (npm)

Published Jul 11, 2024
MAL-2022-6508

Malicious code in testapp00009 (npm)

Published May 17, 2022
MAL-2022-4769

Malicious code in mynewpkgtest2 (npm)

Published Jun 20, 2022
MAL-2022-6509

Malicious code in testdir12345 (npm)

Published Sep 21, 2022
MAL-2022-4472

Malicious code in manualtestapp (npm)

Published Jun 20, 2022
MAL-2024-7916

Malicious code in @incisive/rvtestmodule (npm)

Published Aug 7, 2024
CVE-2026-22814

Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State

Published Jan 13, 2026
MAL-2024-9458

Malicious code in monday-react-quickstart-app (npm)

Published Oct 22, 2024
CVE-2023-40028MEDIUM

Ghost vulnerable to arbitrary file read via symlinks in content import

Published Aug 15, 2023
MAL-2023-8342

Malicious code in onno-missing-2023-full-movies-at-home-streamnig (npm)

Published Oct 13, 2023
MAL-2024-7962

Malicious code in incisive_testing_stuffasdasdasd (npm)

Published Aug 7, 2024
MAL-2023-8373

Malicious code in @bitsoex/react-design-system (npm)

Published Oct 13, 2023
CVE-2025-13321

Mattermost Desktop App exposes sensitive information in its application logs

Published Dec 17, 2025
MAL-2023-276

Malicious code in dow-load-get-your-sht-together-how-to-stop-worrying-about-what-you-should-do-so-you-can-fi (npm)

Published May 10, 2023
MAL-2023-277

Malicious code in dow-load-pdf-the-daily-stoic-366-meditations-on-wisdom-perseverance-and-the-art-of-living- (npm)

Published May 10, 2023
MAL-2023-319

Malicious code in experimental-entrevista-react-01 (npm)

Published May 9, 2023
MAL-2025-1313

Malicious code in bitfinex-test (npm)

Published Feb 13, 2025
MAL-2025-1500

Malicious code in string-width-aliased (npm)

Published Feb 19, 2025
GHSA-5fc7-f62m-8983

OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix)

Published Apr 9, 2026
MAL-2025-1510

Malicious code in @visma-spcs-registry/react-common-components (npm)

Published Feb 21, 2025
CVE-2026-31990

OpenClaw: stageSandboxMedia destination symlink traversal can overwrite files outside sandbox workspace

Published Mar 3, 2026
MAL-2022-4770

Malicious code in mynewpkgtest3 (npm)

Published Jun 20, 2022
GHSA-gjxx-92w9-8v8f

Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host

Published Mar 27, 2026
MAL-2022-4776

Malicious code in mytestnpmaskedrisec (npm)

Published Jun 20, 2022
MAL-2022-6938

Malicious code in vipps-stitches (npm)

Published Jun 30, 2022
CVE-2025-66402

misskey.js's export data contains private post data

Published Dec 15, 2025
GHSA-9f4w-67g7-mqwv

OpenClaw: Endpoint persists after trust decline, leaking gateway credentials

Published Apr 3, 2026
CVE-2021-39135HIGH

UNIX Symbolic Link (Symlink) Following in @npmcli/arborist

Published Aug 31, 2021
GHSA-8m9v-xpgf-g99m

OpenClaw has an unauthorized sender bypass in its stop triggers and /models command authorization

Published Mar 2, 2026
GHSA-8mf7-vv8w-hjr2

OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode

Published Mar 3, 2026
CVE-2023-29008HIGH

SvelteKit framework has Insufficient CSRF protection for CORS requests

Published Apr 7, 2023
MAL-2022-6610

Malicious code in toosting (npm)

Published Jun 20, 2022
CVE-2025-65099

Claude Code vulnerable to command execution prior to startup trust dialog

Published Nov 19, 2025
MAL-2025-153

Malicious code in ad-shield-essential-test (npm)

Published Jan 20, 2025
CVE-2018-9206CRITICAL

Unrestricted Upload of File with Dangerous Type in blueimp-file-upload

Published Oct 22, 2018
CVE-2020-5243MEDIUM

Denial of Service in uap-core when processing crafted User-Agent strings

Published Feb 20, 2020
MAL-2022-728

Malicious code in @wix-ui/editor-elements-design-systems (npm)

Published Jun 20, 2022
MAL-2023-266

Malicious code in do_not_install_this_is_a_test_package_norwegianwood (npm)

Published Jul 26, 2023
GHSA-247c-9743-5963

Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header

Published Apr 15, 2026
MAL-2024-1084

Malicious code in mastercard-postman-encryption-lib (npm)

Published Mar 12, 2024
MAL-2023-811

Malicious code in startrek-client (npm)

Published Jan 30, 2023
CVE-2025-59142

color-string@2.1.1 contains malware after npm account takeover

Published Sep 15, 2025
MAL-2024-11053

Malicious code in mystock-ui (npm)

Published Nov 27, 2024
GHSA-2cm2-m3w5-gp2f

vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`

Published May 8, 2026
MAL-2023-8525

Malicious code in schibsted-ufo (npm)

Published Nov 17, 2023
MAL-2024-11054

Malicious code in nft-dapp-starter-kit (npm)

Published Nov 27, 2024
MAL-2023-8414

Malicious code in test262-runner (npm)

Published Nov 1, 2023
GHSA-4f8g-77mw-3rxc

OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`

Published Apr 9, 2026
CVE-2023-23636MEDIUM

Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name

Published Feb 3, 2023
MAL-2025-190875

Malicious code in @posthog/customerio-plugin (npm)

Published Nov 24, 2025
CVE-2025-69262

pnpm vulnerable to Command Injection via environment variable substitution

Published Jan 7, 2026
CVE-2018-16462CRITICAL

Command Injection in apex-publish-static-files

Published Nov 1, 2018
MAL-2025-1190

Malicious code in uniform-reliable-broadcast (npm)

Published Feb 3, 2025
MAL-2023-8424

Malicious code in atmos-design-system (npm)

Published Nov 2, 2023
MAL-2025-191072

Malicious code in best_gpio_controller (npm)

Published Nov 24, 2025
CVE-2021-23368MEDIUM

Regular Expression Denial of Service in postcss

Published May 10, 2021
MAL-2024-10751

Malicious code in listing-uss-sdk (npm)

Published Nov 14, 2024
CVE-2025-67438

Sync-in Server has a stored cross-site scripting (XSS) vulnerability

Published Feb 20, 2026
MAL-2024-1538

Malicious code in com.unity.cloud.gltfast (npm)

Published Jun 5, 2024
MAL-2024-11138

Malicious code in distdiscord-v11 (npm)

Published Nov 29, 2024
MAL-2025-191117

Malicious code in kinetix-default-token-list (npm)

Published Nov 24, 2025
MAL-2025-1345

Malicious code in ascendex-test (npm)

Published Feb 13, 2025
MAL-2023-8425

Malicious code in discordstreamings (npm)

Published Nov 1, 2023
MAL-2025-1441

Malicious code in telegram-bot-hoster (npm)

Published Feb 17, 2025
Check your entire dependency tree at onceRun dependency scan →