OsVault/npm/string
npm2 critical

string

71 known vulnerabilities · 2 critical · 5 high

CVE-2017-16116HIGH

Regular Expression Denial of Service in string package

Published Jul 24, 2018
GHSA-4948-f92q-f432

@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading

Published Apr 22, 2026
CVE-2025-45143

string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)

Published Jun 30, 2025
CVE-2024-27088

es5-ext vulnerable to Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
CVE-2026-33468

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

Published Mar 20, 2026
MAL-2025-4134

Malicious code in string-multiutils (npm)

Published May 21, 2025
CVE-2025-59142

color-string@2.1.1 contains malware after npm account takeover

Published Sep 15, 2025
CVE-2025-62410

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

Published Oct 15, 2025
CVE-2018-15494CRITICAL

dojox vulnerable to unescaped string injection

Published Oct 15, 2018
CVE-2026-28461

OpenClaw has unbounded memory growth in Zalo webhook via query-string key churn (unauthenticated DoS)

Published Mar 2, 2026
CVE-2021-23346MEDIUM

html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)

Published Mar 18, 2021
CVE-2025-47828

@lumieducation/h5p-server Fails to Sanitize Plain Text Strings

Published May 11, 2025
GHSA-5c6j-r48x-rmvq

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Published Feb 28, 2026
GHSA-j8j5-7r4h-vj2g

DbGate has cross site scripting via the SVG Icon String Handler component

Published Apr 13, 2026
CVE-2021-4299MEDIUM

string-kit Inefficient Regular Expression Complexity vulnerability

Published Jan 2, 2023
CVE-2019-16303CRITICAL

JHipster Kotlin using insecure source of randomness `RandomStringUtils` before v1.2.0

Published Jun 26, 2020
MAL-2022-1639

Malicious code in body-string-rest (npm)

Published Jun 20, 2022
CVE-2022-22138HIGH

Uncontrolled Resource Consumption in fast-string-search

Published Jun 18, 2022
CVE-2026-33331

oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify

Published Mar 20, 2026
GHSA-7q9x-8g6p-3x75

@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template

Published Mar 25, 2026
MAL-2022-6215

Malicious code in son-stringiy-safe (npm)

Published Aug 19, 2022
MAL-2023-662

Malicious code in owa-strings (npm)

Published Mar 6, 2023
MAL-2022-4356

Malicious code in lodaschisstring (npm)

Published Aug 19, 2022
MAL-2022-5564

Malicious code in quewynstring (npm)

Published Aug 19, 2022
MAL-2022-3441

Malicious code in gradient-stringss (npm)

Published Jun 20, 2022
MAL-2022-6326

Malicious code in stringjs_lib (npm)

Published Jul 26, 2022
MAL-2025-1500

Malicious code in string-width-aliased (npm)

Published Feb 19, 2025
CVE-2020-5243MEDIUM

Denial of Service in uap-core when processing crafted User-Agent strings

Published Feb 20, 2020
CVE-2026-30837

Elysia has a string URL format ReDoS

Published Mar 10, 2026
MAL-2023-1046

Malicious code in json2stringfy (npm)

Published May 12, 2023
MAL-2025-192253

Malicious code in remark-stringify10 (npm)

Published Dec 3, 2025
CVE-2024-21524HIGH

node-stringbuilder vulnerable to Out-of-bounds Read

Published Jul 10, 2024
CVE-2025-68949

n8n: Webhook Node IP Whitelist Bypass via Partial String Matching

Published Jan 13, 2026
MAL-2022-3013

Malicious code in fetch-string (npm)

Published Aug 16, 2022
CVE-2022-25872MEDIUM

Out-of-bounds Read in fast-string-search

Published Jun 18, 2022
GHSA-p6x5-p4xf-cc4r

Remote Code Execution (RCE) via String Literal Injection into math-codegen

Published Apr 17, 2026
MAL-2026-2003

Malicious code in shakti-strings (npm)

Published Mar 20, 2026
CVE-2018-21270MEDIUM

Out-of-bounds Read in stringstream

Published Jun 20, 2019
CVE-2024-57072

module-from-string prototype pollution

Published Feb 6, 2025
MAL-2025-46973

Malicious code in color-string (npm)

Published Sep 8, 2025
CVE-2022-37259HIGH

steal Inefficient Regular Expression Complexity vulnerability via string variable

Published Sep 21, 2022
MAL-2026-1569

Malicious code in transform-json-strings (npm)

Published Mar 16, 2026
MAL-2024-11764

Malicious code in plugin-proposal-json-strings (npm)

Published Dec 11, 2024
MAL-2025-3055

Malicious code in @hongfangze/string (npm)

Published Apr 2, 2025
MAL-2022-6531

Malicious code in testring-build (npm)

Published Jun 20, 2022
MAL-2022-6325

Malicious code in string_decoder-browserify (npm)

Published Jun 20, 2022
CVE-2016-1000232MEDIUM

ReDoS via long string of semicolons in tough-cookie

Published Oct 10, 2018
GHSA-qx2v-qp2m-jg93

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Published Apr 24, 2026
CVE-2026-30830

defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag

Published Mar 6, 2026
CVE-2023-37899HIGH

Feathers socket handler allows abusing implicit toString

Published Jul 20, 2023
MAL-2022-1638

Malicious code in body-string (npm)

Published Jun 20, 2022
MAL-2022-38

Malicious code in 5string (npm)

Published Aug 19, 2022
MAL-2026-62

Malicious code in oj-sp-common-strings (npm)

Published Jan 6, 2026
MAL-2022-3439

Malicious code in gradient-stringnnnn (npm)

Published Jun 20, 2022
MAL-2022-3440

Malicious code in gradient-strings (npm)

Published Jun 20, 2022
MAL-2025-21

Malicious code in tree-sitter-strings (npm)

Published Jan 6, 2025
MAL-2022-3438

Malicious code in gradient-stringn (npm)

Published Jun 20, 2022
MAL-2026-213

Malicious code in @maxcointech/simple-string-utils (npm)

Published Jan 12, 2026
MAL-2026-233

Malicious code in simple-string-utils3 (npm)

Published Jan 12, 2026
MAL-2024-11010

Malicious code in string-process-mate (npm)

Published Nov 27, 2024
MAL-2023-8707

Malicious code in arrays-string (npm)

Published Dec 18, 2023
MAL-2025-191588

Malicious code in stringify-coder (npm)

Published Dec 1, 2025
MAL-2022-5986

Malicious code in seacpe-string-regexp (npm)

Published Aug 19, 2022
MAL-2025-162

Malicious code in atlaspack-transformer-string (npm)

Published Jan 20, 2025
CVE-2021-32696LOW

Passing in a non-string 'html' argument can lead to unsanitized output

Published Jun 18, 2021
MAL-2022-4916

Malicious code in non-string-num (npm)

Published Jun 20, 2022
MAL-2022-4075

Malicious code in jsostablestringilfy (npm)

Published Aug 19, 2022
MAL-2025-3935

Malicious code in eslint-plugin-i18n-strings (npm)

Published May 18, 2025
MAL-2024-8917

Malicious code in ibm-strings (npm)

Published Sep 19, 2024
MAL-2025-5958

Malicious code in string-parser-utils (npm)

Published Jul 15, 2025
MAL-2025-47206

Malicious code in string-setup-helper (npm)

Published Sep 15, 2025
Check your entire dependency tree at onceRun dependency scan →