OsVault/npm/ws
npm12 critical

ws

496 known vulnerabilities · 12 critical · 44 high

CVE-2024-37890HIGH

ws affected by a DoS when handling a request with many HTTP headers

Published Jun 17, 2024
CVE-2016-10542HIGH

DoS due to excessively large websocket message in ws

Published Feb 18, 2019
CVE-2016-10518HIGH

Remote Memory Disclosure in ws

Published Feb 18, 2019
CVE-2021-32640MEDIUM

ReDoS in Sec-Websocket-Protocol header

Published May 28, 2021
CVE-2024-36361MEDIUM

Pug allows JavaScript code execution if an application accepts untrusted input

Published May 24, 2024
GHSA-2qrv-rc5x-2g2h

OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup

Published Apr 7, 2026
CVE-2026-32064

OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 3, 2026
GHSA-3xx2-mqjm-hg9x

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

Published Apr 16, 2026
CVE-2022-41777HIGH

nadesiko3 allows remote attacker to inject invalid value to decodeURIComponent of nako3edit

Published Dec 5, 2022
CVE-2022-41654MEDIUM

ghost vulnerable to unauthorized newsletter modification via improper access controls

Published Nov 28, 2022
GHSA-58q2-7r52-jq62

OpenClaw: Path traversal via inbound channel attachment path in ACP dispatch allows arbitrary file read

Published Apr 3, 2026
MAL-2025-191199

Malicious code in @browserbasehq/stagehand-docs (npm)

Published Nov 25, 2025
CVE-2022-37623CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 31, 2022
CVE-2024-36422MEDIUM

Flowise Cross-site Scripting in api/v1/chatflows/id

Published Aug 5, 2024
CVE-2026-30920

OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding

Published Mar 9, 2026
CVE-2025-8101

Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)

Published Jul 26, 2025
CVE-2026-23889

pnpm has Windows-specific tarball Path Traversal

Published Jan 26, 2026
CVE-2025-5276

Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Published May 29, 2025
CVE-2024-51434

Froala WYSIWYG editor allows cross-site scripting (XSS)

Published Nov 8, 2024
CVE-2025-53889

Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows

Published Jul 15, 2025
CVE-2024-34712MEDIUM

Oceanic allows unsanitized user input to lead to path traversal in URLs

Published May 14, 2024
CVE-2025-48054

radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published May 27, 2025
MAL-2025-192965

Malicious code in awsmcc (npm)

Published Dec 30, 2025
MAL-2025-2017

Malicious code in aws-features-signin-proxy-client (npm)

Published Mar 3, 2025
MAL-2025-2092

Malicious code in aws-ui-component-select (npm)

Published Mar 4, 2025
CVE-2021-46871MEDIUM

phoenix_html allows Cross-site Scripting in HEEx class attributes

Published Jan 10, 2023
CVE-2025-27109

Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)

Published Feb 25, 2025
CVE-2025-61917

n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

Published Feb 4, 2026
CVE-2026-22176

OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 3, 2026
GHSA-vp62-r36r-9xqp

Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace

Published Apr 21, 2026
CVE-2026-34768LOW
Risk: 19.5/100

Electron: Unquoted executable path in app.setLoginItemSettings on Windows

Published Apr 3, 2026
GHSA-jhm7-29pj-4xvf

@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codes

Published Apr 16, 2026
CVE-2017-16078HIGH

Shadowsock is malware

Published Aug 27, 2018
GHSA-m866-6qv5-p2fg

OpenClaw host-env blocklist missing `GIT_TEMPLATE_DIR` and `AWS_CONFIG_FILE` allows code execution via env override

Published Mar 31, 2026
CVE-2025-54798

tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

Published Aug 6, 2025
GHSA-mhr7-2xmv-4c4q

OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode

Published Apr 3, 2026
CVE-2018-1999024MEDIUM

Macro in MathJax running untrusted Javascript within a web browser

Published Jul 27, 2018
CVE-2026-34773MEDIUM
Risk: 23.51/100

Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

Published Apr 3, 2026
CVE-2022-36077HIGH

Exfiltration of hashed SMB credentials on Windows via file:// redirect

Published Nov 10, 2022
CVE-2025-31476

tarteaucitron.js allows url scheme injection via unfiltered inputs

Published Apr 7, 2025
CVE-2024-34708MEDIUM

Directus allows redacted data extraction on the API through "alias"

Published May 13, 2024
CVE-2026-32000

OpenClaw has command injection via Windows shell fallback in Lobster tool execution

Published Mar 3, 2026
CVE-2023-35931LOW

Shescape potential environment variable exposure on Windows with CMD

Published Jun 22, 2023
CVE-2026-26319

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Published Feb 17, 2026
CVE-2026-30921

OneUptime: Synthetic Monitor RCE via exposed Playwright browser object

Published Mar 7, 2026
CVE-2020-7625CRITICAL

Injection in op-browser

Published Feb 10, 2022
CVE-2025-30360

webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser

Published Jun 4, 2025
CVE-2026-32046

OpenClaw: Chrome --no-sandbox disabled OS-level browser sandbox in sandbox browser container

Published Mar 3, 2026
CVE-2022-24709HIGH

Cross site scripting in @awsui/components-react

Published Feb 25, 2022
GHSA-68v4-hmwv-f43h

OpenClaw: Media download follows cross-origin redirects with Authorization headers intact

Published Apr 3, 2026
CVE-2026-22812

OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution

Published Jan 13, 2026
CVE-2016-10612HIGH

dalek-browser-ie-canary downloads Resources over HTTP

Published Feb 18, 2019
CVE-2026-30822

Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint

Published Mar 6, 2026
CVE-2016-10670HIGH

Downloads Resources over HTTP in windows-seleniumjar-mirror

Published Feb 18, 2019
GHSA-458j-xx4x-4375

hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR

Published Apr 16, 2026
CVE-2024-37145MEDIUM

Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id

Published Aug 5, 2024
GHSA-536q-mj95-h29h

OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage

Published Apr 17, 2026
GHSA-53vx-pmqw-863c

OpenClaw: Browser SSRF policy default allowed private-network navigation

Published Apr 17, 2026
CVE-2026-30229

parse-server's endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user

Published Mar 6, 2026
CVE-2022-32213MEDIUM

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

Published Jul 15, 2022
CVE-2024-56198

path-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability

Published Jan 2, 2025
GHSA-5cwg-9f6j-9jvx

Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows

Published Apr 17, 2026
GHSA-qj22-xqjr-v83v

OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection

Published Mar 3, 2026
CVE-2026-33060

SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks

Published Mar 18, 2026
CVE-2026-23888

pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)

Published Jan 26, 2026
CVE-2024-47183

Parse Server's custom object ID allows to acquire role privileges

Published Oct 4, 2024
CVE-2026-32008

OpenClaw browser navigation guard allowed non-network URL schemes, enabling authenticated browser-tool users to access file:// local files

Published Mar 3, 2026
GHSA-wr4h-v87w-p3r7

h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read

Published Mar 18, 2026
CVE-2016-10584HIGH

Downloads Resources over HTTP in dalek-browser-chrome-canary

Published Feb 18, 2019
CVE-2025-30353

Directus's webhook trigger flows can leak sensitive data

Published Mar 26, 2025
CVE-2026-32005

OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows

Published Mar 4, 2026
CVE-2023-41646MEDIUM

Buttercup allows attackers to obtain the hash of the master password

Published Sep 8, 2023
CVE-2024-48913

Hono allows bypass of CSRF Middleware by a request without Content-Type header.

Published Oct 15, 2024
CVE-2024-36423MEDIUM

Flowise Cross-site Scripting in /api/v1/public-chatflows/id

Published Aug 5, 2024
GHSA-g374-mggx-p6xc

OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode

Published Apr 3, 2026
CVE-2025-31475

tarteaucitron.js allows prototype pollution via custom text injection

Published Apr 7, 2025
CVE-2025-55303

Astro allows unauthorized third-party images in _image endpoint

Published Aug 19, 2025
GHSA-xh9j-mpc9-2m9p

Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 21, 2026
MAL-2022-1197

Malicious code in aws-greengrass-provisioner (npm)

Published Jun 20, 2022
CVE-2021-40829MEDIUM

Improper certificate management in AWS IoT Device SDK v2

Published Nov 24, 2021
GHSA-4vcf-q4xf-f48m

Better Auth Passkey Plugin allows passkey deletion through IDOR

Published Nov 25, 2025
CVE-2026-23890

pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

Published Jan 26, 2026
CVE-2019-18954MEDIUM

Pomelo allows external control of critical state data

Published Dec 2, 2019
CVE-2026-1528

Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

Published Mar 13, 2026
MAL-2022-3502

Malicious code in gulp-browserify-thin (npm)

Published May 16, 2022
CVE-2021-29444MEDIUM

Padding Oracle Attack due to Observable Timing Discrepancy in jose-browser-runtime

Published Apr 19, 2021
CVE-2021-40828MEDIUM

Improper certificate management in AWS IoT Device SDK v2

Published Nov 24, 2021
MAL-2023-611

Malicious code in mv-browser-support (npm)

Published May 9, 2023
CVE-2025-30222

Shescape has potential environment variable exposure on Windows with CMD

Published Mar 26, 2025
CVE-2026-3419

Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation

Published Mar 5, 2026
GHSA-57gh-m6rq-54cf

OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration

Published Apr 3, 2026
MAL-2022-1191

Malicious code in aws-amplify-unicorntrivia-workshop (npm)

Published Jun 20, 2022
MAL-2022-1192

Malicious code in aws-centralized-logging (npm)

Published Jun 20, 2022
CVE-2024-33669MEDIUM

Passbolt Browser Extension leaks password information

Published Apr 26, 2024
CVE-2025-57283

BrowserStack Local vulnerable to Command Injection through logfile variable

Published Jan 28, 2026
CVE-2026-32742

Parse Server session creation endpoint allows overwriting server-generated session fields

Published Mar 17, 2026
MAL-2025-192359

Malicious code in ssf-desktop-api-browser (npm)

Published Dec 6, 2025
CVE-2026-21894

n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

Published Jan 7, 2026
CVE-2018-7560HIGH

AWS Lambda parser is vulnerable to Regular Expression Denial of Service

Published Mar 5, 2018
MAL-2026-2730

Malicious code in browserstack-utils (npm)

Published Apr 16, 2026
CVE-2026-33989

@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools

Published Mar 27, 2026
CVE-2018-3787HIGH

simplehttpserver allows directory traversal and file listing

Published Sep 6, 2018
CVE-2018-12457HIGH

express-cart allows any user to create an admin user

Published May 13, 2022
CVE-2020-7597HIGH

codecov NPM module allows remote attackers to execute arbitrary commands

Published Feb 19, 2020
CVE-2019-19596MEDIUM

GitBook allows Cross-site Scripting via a local .md file.

Published May 24, 2022
MAL-2022-1201

Malicious code in aws-perspective (npm)

Published Jun 20, 2022
MAL-2022-1202

Malicious code in aws-simple-cicd (npm)

Published Jun 20, 2022
MAL-2022-1203

Malicious code in aws-solutions-constructs (npm)

Published Jun 20, 2022
CVE-2026-32020

OpenClaw's Control UI Static File Handler Follows Symlinks and Allows Out-of-Root File Read

Published Mar 2, 2026
MAL-2022-1327

Malicious code in azure-event-hubs-browser (npm)

Published Jun 20, 2022
CVE-2025-1302

JSONPath Plus allows Remote Code Execution

Published Feb 15, 2025
GHSA-qf48-qfv4-jjm9

OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image

Published Mar 31, 2026
CVE-2025-9611

Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools

Published Jan 7, 2026
CVE-2025-67419

evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API

Published Jan 5, 2026
GHSA-82gw-wqw6-r2cf

Duplicate Advisory: Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 19, 2026
GHSA-82qx-6vj7-p8m2

OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows

Published Apr 17, 2026
CVE-2026-22168

OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing arguments

Published Mar 2, 2026
CVE-2022-33987MEDIUM

Got allows a redirect to a UNIX socket

Published Jun 19, 2022
CVE-2022-37621CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 29, 2022
CVE-2026-1470

n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution

Published Jan 27, 2026
CVE-2017-1000219CRITICAL

Command Execution in windows-cpu

Published Sep 1, 2020
CVE-2026-31994

OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

Published Mar 3, 2026
CVE-2025-49223

billboard.js allows prototype pollution via the function generate

Published Jun 4, 2025
CVE-2016-10605HIGH

dalek-browser-ie downloads Resources over HTTP

Published Feb 18, 2019
CVE-2026-33151

socket.io allows an unbounded number of binary attachments

Published Mar 18, 2026
GHSA-67mf-f936-ppxf

OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval

Published Apr 9, 2026
CVE-2018-14730HIGH

Missing Origin Validation in browserify-hmr

Published Sep 1, 2020
MAL-2022-1964

Malicious code in cobrowse-common (npm)

Published Jun 20, 2022
CVE-2026-32001

OpenClaw's Node role device-identity bypass allows unauthorized node.event injection

Published Mar 3, 2026
CVE-2026-27638

@actual-app/sync-server: Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode

Published Feb 27, 2026
MAL-2022-2111

Malicious code in com.unity.xr.windowsmr (npm)

Published Jun 20, 2022
MAL-2022-2112

Malicious code in com.unity.xr.windowsmr.metro (npm)

Published Jun 20, 2022
CVE-2023-36472MEDIUM

Strapi may leak sensitive user information, user reset password, tokens via content-manager views

Published Sep 13, 2023
CVE-2025-15284

qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion

Published Dec 30, 2025
GHSA-6v7q-wjvx-w8wg

basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands

Published Apr 10, 2026
CVE-2025-1398

Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection

Published Mar 17, 2025
CVE-2016-10689HIGH

Downloads Resources over HTTP in windows-iedriver

Published Feb 18, 2019
GHSA-7ff8-xjh3-mgh6

OpenClaw's non-default autoAllowSkills setting could bypass on-miss exec prompt

Published Mar 3, 2026
CVE-2022-39230MEDIUM

fhir-works-on-aws-authz-smart handles permissions improperly

Published Sep 21, 2022
CVE-2024-34448HIGH

Ghost allows CSV Injection during member CSV export

Published May 22, 2024
CVE-2024-56332

Next.js Allows a Denial of Service (DoS) with Server Actions

Published Jan 3, 2025
CVE-2024-36287LOW

Mattermost Desktop App allows for bypassing TCC restrictions on macOS

Published Jun 14, 2024
CVE-2025-5273

Markdownify MCP Server allows attackers to read arbitrary files

Published May 29, 2025
CVE-2025-30352

Directus `search` query parameter allows enumeration of non permitted fields

Published Mar 26, 2025
CVE-2026-32029

OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

Published Mar 3, 2026
CVE-2022-37617CRITICAL

thlorenz browserify-shim vulnerable to prototype pollution

Published Oct 12, 2022
CVE-2025-65945

auth0/node-jws Improperly Verifies HMAC Signature

Published Dec 4, 2025
MAL-2022-1200

Malicious code in aws-ms-deploy-assistant (npm)

Published Jun 20, 2022
MAL-2022-5901

Malicious code in sa-kws-demo-web (npm)

Published Aug 22, 2022
MAL-2022-6322

Malicious code in strapi-provider-upload-aws-s3-auth (npm)

Published Jun 20, 2022
GHSA-353c-v8x9-v7c3

MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport

Published Apr 16, 2026
MAL-2022-7057

Malicious code in wdesk_browser_environment (npm)

Published Jun 20, 2022
MAL-2023-196

Malicious code in cms-ui-views (npm)

Published Mar 15, 2023
GHSA-8rh7-6779-cjqq

OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover

Published Apr 1, 2026
MAL-2022-734

Malicious code in @ws-amplify/core (npm)

Published Jun 20, 2022
CVE-2025-62522

vite allows server.fs.deny bypass via backslash on Windows

Published Oct 20, 2025
GHSA-c4qm-58hj-j6pj

OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation

Published Apr 17, 2026
CVE-2026-26317

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

Published Feb 18, 2026
CVE-2022-25898HIGH

JWS and JWT signature validation vulnerability with special characters

Published Jun 25, 2022
CVE-2025-43865

React Router allows pre-render data spoofing on React-Router framework mode

Published Apr 24, 2025
MAL-2024-1562

Malicious code in aws-logs (npm)

Published Jun 10, 2024
CVE-2025-67898

MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827

Published Dec 15, 2025
GHSA-8wj8-cfxr-9374

AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Published Nov 13, 2025
CVE-2019-10777CRITICAL

OS command injection in aws-lambda

Published Feb 14, 2020
MAL-2022-808

Malicious code in abu-news-api (npm)

Published Jun 20, 2022
CVE-2026-4603

jsrsasign: Division by Zero Allows Invalid JWK Modulus to Cause Deterministic Zero Output in RSA Operations

Published Mar 23, 2026
GHSA-98ch-45wp-ch47

OpenClaw: Windows-compatible env override keys could bypass system.run approval binding

Published Apr 7, 2026
GHSA-98hh-7ghg-x6rq

OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals

Published Mar 31, 2026
CVE-2018-1000118HIGH

Electron protocol handler browser vulnerable to Command Injection

Published Mar 26, 2018
MAL-2022-4350

Malicious code in loblaws-mkt-bundle (npm)

Published Jun 20, 2022
MAL-2024-8878

Malicious code in awsspeedtest (npm)

Published Sep 16, 2024
GHSA-527m-976r-jf79

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

Published Apr 17, 2026
CVE-2026-22814

Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State

Published Jan 13, 2026
CVE-2021-37713HIGH

Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization

Published Aug 31, 2021
GHSA-cj63-jhhr-wcxv

DOMPurify USE_PROFILES prototype pollution allows event handlers

Published Apr 3, 2026
MAL-2024-8998

Malicious code in node-jaws (npm)

Published Sep 27, 2024
MAL-2025-191195

Malicious code in @browserbasehq/mcp (npm)

Published Nov 25, 2025
CVE-2026-23522

Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion

Published Jan 20, 2026
GHSA-jccr-rrw2-vc8h

OpenClaw safeBins jq `$ENV` filter bypass allows environment variable disclosure

Published Mar 31, 2026
GHSA-jhpv-5j76-m56h

OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure

Published Apr 17, 2026
GHSA-9q82-xgwf-vj6h

Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention

Published Mar 26, 2026
MAL-2025-190719

Malicious code in @asyncapi/nodejs-ws-template (npm)

Published Nov 24, 2025
CVE-2025-31138

tarteaucitron.js allows UI manipulation via unrestricted CSS injection

Published Apr 7, 2025
GHSA-9r75-g2cr-3h76

Vercel Workflow Allows Webhook Creation with Predictable User-Specified Tokens

Published Mar 6, 2026
GHSA-fv94-qvg8-xqpw

OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host

Published Apr 2, 2026
MAL-2025-190746

Malicious code in @kvytech/medusa-plugin-product-reviews (npm)

Published Nov 24, 2025
MAL-2025-191204

Malicious code in @clausehq/flows-step-sendgridemail (npm)

Published Nov 25, 2025
MAL-2023-93

Malicious code in angra_temple_of_shadows_songbook_pdf_105_kssry (npm)

Published May 9, 2023
MAL-2023-948

Malicious code in vue-gws (npm)

Published Jun 15, 2023
CVE-2021-40830MEDIUM

Improper certificate management in AWS IoT Device SDK v2

Published Nov 24, 2021
CVE-2022-23505MEDIUM

Authentication Bypass for passport-wsfed-saml2

Published Dec 13, 2022
CVE-2026-24737

jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution

Published Feb 2, 2026
MAL-2024-1563

Malicious code in aws-check (npm)

Published Jun 10, 2024
MAL-2024-1608

Malicious code in legacyreact-aws-s3-typescript (npm)

Published Jun 13, 2024
MAL-2024-9387

Malicious code in new-al-bum-av-ailable-2014-15374-tourniquets-hacksaws-and-graves-53p3g-eabxqr (npm)

Published Oct 16, 2024
GHSA-cjq8-m7wj-xmq9

Duplicate Advisory: OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 21, 2026
CVE-2022-39353CRITICAL

xmldom allows multiple root nodes in a DOM

Published Nov 1, 2022
MAL-2022-736

Malicious code in @wso-utils/json-mapper (npm)

Published Jun 20, 2022
GHSA-qmwg-qprg-3j38

OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads

Published Apr 17, 2026
MAL-2022-810

Malicious code in abunews-components (npm)

Published Jun 20, 2022
GHSA-f3pv-wv63-48x8

Electron: Named window.open targets not scoped to the opener's browsing context

Published Apr 7, 2026
GHSA-rj2p-j66c-mgqh

OpenClaw: Browser tabs action select and close routes bypassed SSRF policy

Published Apr 17, 2026
CVE-2023-35165MEDIUM

AWS CDK EKS overly permissive trust policies

Published Jun 19, 2023
CVE-2025-32014

estree-util-value-to-estree allows prototype pollution in generated ESTree

Published Apr 7, 2025
CVE-2025-67427

evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API

Published Jan 5, 2026
CVE-2025-59288

Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate

Published Oct 14, 2025
CVE-2025-69206

hemmelig allows SSRF Filter bypass via Secret Request functionality

Published Dec 29, 2025
GHSA-ffr4-mrhv-vfr2

Duplicate Advisory: OpenClaw has browser trace/download path symlink escape in temp output handling

Published Mar 21, 2026
CVE-2026-28393

OpenClaw's hook transform module path allows traversal and arbitrary JavaScript module loading

Published Mar 3, 2026
CVE-2022-32214MEDIUM

llhttp allows HTTP Request Smuggling via Improper Delimiting of Header Fields

Published Jul 15, 2022
MAL-2025-173

Malicious code in com.unity.assetbundlebrowser (npm)

Published Jan 20, 2025
CVE-2026-30848

Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory

Published Mar 9, 2026
CVE-2025-31486

Vite allows server.fs.deny to be bypassed with .svg or relative paths

Published Apr 4, 2025
MAL-2025-191201

Malicious code in @clausehq/flows-step-httprequest (npm)

Published Nov 25, 2025
MAL-2025-191202

Malicious code in @clausehq/flows-step-jsontoxml (npm)

Published Nov 25, 2025
MAL-2025-191203

Malicious code in @clausehq/flows-step-mqtt (npm)

Published Nov 25, 2025
GHSA-8h8f-7cxm-m38j

Duplicate Advisory: OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation

Published Apr 2, 2026
MAL-2025-190776

Malicious code in medusa-plugin-product-reviews-kvy (npm)

Published Nov 24, 2025
MAL-2022-1193

Malicious code in aws-centralized-waf-and-vpc-security-group-management (npm)

Published Jun 20, 2022
MAL-2022-1194

Malicious code in aws-data-api-ux (npm)

Published Jun 20, 2022
MAL-2022-1195

Malicious code in aws-data-replication-hub (npm)

Published Jun 20, 2022
MAL-2022-1196

Malicious code in aws-delivlib-sample (npm)

Published Jun 20, 2022
GHSA-g8xp-qx39-9jq9

OpenClaw: Incomplete host-env-security-policy allows untrusted model to substitute compiler binaries via env overrides

Published Apr 3, 2026
CVE-2016-10618HIGH

node-browser downloads Resources over HTTP

Published Feb 18, 2019
MAL-2025-48744

Malicious code in node-js-playwright-browserstack (npm)

Published Oct 22, 2025
CVE-2026-25223

Fastify's Content-Type header tab character allows body validation bypass

Published Feb 2, 2026
GHSA-92jp-89mq-4374

OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials

Published Apr 17, 2026
MAL-2024-1550

Malicious code in vue2-webviews (npm)

Published Jun 7, 2024
CVE-2024-6833

Zowe CLI allows storage of previously entered secure credentials in a plaintext file

Published Jul 17, 2024
MAL-2022-1696

Malicious code in browsersilst (npm)

Published Aug 19, 2022
MAL-2022-1697

Malicious code in browserslist-config-freight-trust (npm)

Published Jun 20, 2022
CVE-2025-32997

http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed

Published Apr 15, 2025
CVE-2026-28462

OpenClaw has a path traversal in browser trace/download output paths may allow arbitrary file writes

Published Feb 18, 2026
MAL-2025-192433

Malicious code in mws-common-ui (npm)

Published Dec 10, 2025
CVE-2019-0219CRITICAL

Privilege Escalation in cordova-plugin-inappbrowser

Published Sep 4, 2020
MAL-2022-1963

Malicious code in co-browsing (npm)

Published Jun 20, 2022
MAL-2026-1578

Malicious code in browser-gaming-client (npm)

Published Mar 19, 2026
CVE-2026-26329

OpenClaw has a path traversal in browser upload allows local file read

Published Feb 18, 2026
MAL-2025-190762

Malicious code in @zapier/browserslist-config-zapier (npm)

Published Nov 24, 2025
CVE-2024-39896HIGH

Directus Allows Single Sign-On User Enumeration

Published Jul 8, 2024
CVE-2026-31995

OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path

Published Mar 3, 2026
GHSA-m6rx-7pvw-2f73

OpenClaude: Sandbox Bypass via Early-Exit Logic Flaw Allows Path Traversal

Published Apr 21, 2026
CVE-2026-34770HIGH
Risk: 35/100

Electron: Use-after-free in PowerMonitor on Windows and macOS

Published Apr 3, 2026
CVE-2025-55746

Directus allows unauthenticated file upload and file modification due to lacking input sanitization

Published Aug 20, 2025
MAL-2025-2682

Malicious code in kagi_browser_ext (npm)

Published Mar 25, 2025
CVE-2026-32058

OpenClaw Node system.run approval context-binding weakness in approval-enabled host=node flows

Published Mar 2, 2026
GHSA-h3x4-hc5v-v2gm

OpenClaw: Windows media loaders accepted remote-host file URLs before local path validation

Published Mar 26, 2026
GHSA-h5hg-h7rr-gpf3

OpenClaw: Node browser proxy `allowProfiles` bypass through persistent profile mutation and runtime profile selection

Published Apr 3, 2026
MAL-2024-7976

Malicious code in new-relic-browser (npm)

Published Aug 7, 2024
CVE-2016-10544MEDIUM

Denial of Service in uws

Published Sep 1, 2020
MAL-2025-3628

Malicious code in jade-browserify (npm)

Published May 6, 2025
MAL-2024-11115

Malicious code in windowscleaner (npm)

Published Nov 27, 2024
CVE-2016-10687HIGH

windows-selenium-chromedriver downloads Resources over HTTP

Published Sep 1, 2020
CVE-2023-40185MEDIUM

Shescape on Windows escaping may be bypassed in threaded context

Published Aug 22, 2023
MAL-2025-3693

Malicious code in outline-shadowsocksconfig (npm)

Published May 7, 2025
CVE-2026-33527

Parse Server's Session Update endpoint allows overwriting server-generated session fields

Published Mar 24, 2026
MAL-2022-424

Malicious code in @mcd-gws/fetlife-assets (npm)

Published Jun 20, 2022
MAL-2026-280

Malicious code in dws-dx (npm)

Published Jan 16, 2026
CVE-2026-32025

OpenClaw's browser-origin WebSocket auth hardening gap could enable loopback password brute-force chains

Published Mar 3, 2026
CVE-2026-24398

Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing

Published Jan 27, 2026
CVE-2026-26327

OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning

Published Feb 18, 2026
MAL-2022-4686

Malicious code in mongodb-stitch-browser-testutils (npm)

Published Jul 26, 2022
CVE-2026-27574

OneUptime:: node:vm sandbox escape in probe allows any project member to achieve RCE

Published Feb 24, 2026
GHSA-vp58-j275-797x

Better Auth allows bypassing the trustedOrigins Protection which leads to ATO

Published Feb 24, 2025
MAL-2026-1042

Malicious code in trae-browser-inspect (npm)

Published Feb 25, 2026
MAL-2024-7751

Malicious code in img-aws-s3-object-multipart-copy (npm)

Published Jul 15, 2024
CVE-2026-32057

OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

Published Mar 3, 2026
CVE-2016-10691HIGH

windows-seleniumjar downloads Resources over HTTP

Published Jul 31, 2018
CVE-2026-31999

CpenClaw's ACPX Windows wrapper shell fallback allowed cwd injection in specific paths

Published Mar 2, 2026
CVE-2020-7646CRITICAL

curlrequest allows execution of arbitrary commands

Published May 13, 2020
GHSA-vffh-c9pq-4crh

Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read

Published Oct 20, 2025
CVE-2024-8372

AngularJS allows attackers to bypass common image source restrictions

Published Sep 9, 2024
CVE-2026-24052

Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains

Published Feb 3, 2026
GHSA-83f3-hh45-vfw9

OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://

Published Apr 7, 2026
GHSA-vr5g-mmx7-h897

OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation

Published Apr 9, 2026
CVE-2017-16149HIGH

Directory Traversal in zwserver

Published Sep 1, 2020
MAL-2025-1068

Malicious code in browser-sign-in (npm)

Published Feb 3, 2025
CVE-2026-32701

Qwik City has array method pollution in FormData processing allows type confusion and DoS

Published Mar 20, 2026
CVE-2022-29623HIGH

Connect-Multiparty allows arbitrary file upload

Published May 17, 2022
CVE-2017-16003HIGH

windows-build-tools downloads Resources over HTTP

Published Nov 9, 2018
GHSA-wmjr-v86c-m9jj

Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions

Published Nov 26, 2025
CVE-2026-26833

thumbler allows OS Command Injection

Published Mar 25, 2026
CVE-2026-32106

StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts

Published Mar 12, 2026
GHSA-pfv7-rr5m-qmv6

OpenClaw has auth inconsistency on local Browser Extension Relay /extension endpoint

Published Mar 3, 2026
GHSA-xmv6-r34m-62p4

OpenClaw: Sandbox media fallback tmp symlink alias bypass allows host file reads outside sandboxRoot

Published Mar 3, 2026
GHSA-h36m-2vh5-x699

Duplicate Advisory: ACPX Windows wrapper shell fallback allowed cwd injection in specific paths

Published Mar 19, 2026
CVE-2026-24053

Claude Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes

Published Feb 3, 2026
GHSA-5h3f-885m-v22w

OpenClaw: Existing WS sessions survive shared gateway token rotation

Published Apr 9, 2026
MAL-2025-191220

Malicious code in @fishingbooker/browser-sync-plugin (npm)

Published Nov 24, 2025
MAL-2024-1565

Malicious code in aws-public (npm)

Published Jun 11, 2024
MAL-2025-191484

Malicious code in browser-client-neptune (npm)

Published Nov 28, 2025
GHSA-vjx8-8p7h-82gr

OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection

Published Apr 7, 2026
MAL-2024-9400

Malicious code in zip-mp3-a-lbum-do-wnload-new-gift-of-screws-q2h3s-xswcix (npm)

Published Oct 16, 2024
CVE-2016-1000249

fury-adapter-swagger allows arbitrary file read from system

Published Sep 1, 2020
GHSA-xq94-r468-qwgj

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

Published Apr 17, 2026
GHSA-cmfr-9m2r-xwhq

OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard

Published Apr 9, 2026
GHSA-525j-hqq2-66r4

OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0

Published Apr 17, 2026
MAL-2022-2578

Malicious code in dowsersync (npm)

Published Aug 19, 2022
CVE-2025-0868

DocsGPT Allows Remote Code Execution

Published Feb 20, 2025
MAL-2022-1694

Malicious code in browser-warning-ui (npm)

Published Jun 20, 2022
MAL-2022-1695

Malicious code in browser-wurfl (npm)

Published Jun 20, 2022
CVE-2026-34451
Risk: 0.02/100

Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories

Published Apr 1, 2026
MAL-2025-3090

Malicious code in adult-content-detection-aws (npm)

Published Apr 3, 2025
CVE-2016-10696HIGH

Downloads Resources over HTTP in windows-latestchromedriver

Published Sep 1, 2020
CVE-2024-45801HIGH

DOMPurify allows tampering by prototype pollution

Published Sep 16, 2024
MAL-2022-5089

Malicious code in opbox-web-browser (npm)

Published Jun 20, 2022
MAL-2025-3407

Malicious code in my-rei-browser-shim (npm)

Published Apr 26, 2025
MAL-2022-5090

Malicious code in open-data-registry-browser (npm)

Published Jun 20, 2022
CVE-2026-34523MEDIUM
Risk: 26.52/100

SillyTavern: Path Traversal allows file existence oracle

Published Apr 1, 2026
MAL-2022-1496

Malicious code in belzqadykjcpmwsk (npm)

Published Jul 11, 2022
CVE-2017-16897HIGH

passport-wsfed-saml2 vulnerable to Signature Bypass in SAML2 token

Published Jun 21, 2023
MAL-2022-4349

Malicious code in loblaws-mkt (npm)

Published Jun 20, 2022
GHSA-6475-r3vj-m8vf

AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value

Published Jan 8, 2026
MAL-2024-11819

Malicious code in lana-ws (npm)

Published Dec 13, 2024
CVE-2026-26118

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Published Mar 10, 2026
GHSA-8px5-2gfr-7ph6

Duplicate Advisory: OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path

Published Mar 19, 2026
CVE-2016-1000223

Forgeable Public/Private Tokens in jws

Published Sep 1, 2020
CVE-2026-33665

n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover

Published Mar 25, 2026
CVE-2024-26135HIGH

MeshCentral cross-site websocket hijacking (CSWSH) vulnerability

Published Feb 21, 2024
CVE-2026-22817

Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass

Published Jan 13, 2026
MAL-2025-3566

Malicious code in lezer-snowsql (npm)

Published May 1, 2025
CVE-2025-29049

MathLive's Lack of Escaping of HTML allows for XSS

Published Jan 21, 2025
MAL-2025-191193

Malicious code in @browserbasehq/bb9 (npm)

Published Nov 25, 2025
MAL-2025-191194

Malicious code in @browserbasehq/director-ai (npm)

Published Nov 25, 2025
CVE-2024-34449MEDIUM

Vditor allows Cross-site Scripting via an attribute of an `A` element

Published May 3, 2024
CVE-2026-30887

OneUpTime's Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE

Published Mar 7, 2026
CVE-2026-34524HIGH
Risk: 41.51/100

SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root

Published Apr 1, 2026
CVE-2021-40831MEDIUM

Improper certificate management in AWS IoT Device SDK v2

Published Nov 24, 2021
GHSA-j7p2-qcwm-94v4

OpenClaw's incomplete host env sanitization blocklist allows supply-chain redirection via package-manager env overrides

Published Mar 31, 2026
MAL-2022-6325

Malicious code in string_decoder-browserify (npm)

Published Jun 20, 2022
GHSA-jvff-x2qm-6286

mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes

Published Apr 10, 2026
CVE-2026-30957

OneUptime has Synthetic Monitor RCE via exposed Playwright browser object

Published Mar 10, 2026
MAL-2022-737

Malicious code in @wso-utils/localization (npm)

Published Jun 20, 2022
MAL-2025-4471

Malicious code in athira-windows-arm64 (npm)

Published May 27, 2025
MAL-2022-735

Malicious code in @wso-utils/form-utils (npm)

Published Jun 20, 2022
CVE-2024-8373

AngularJS allows attackers to bypass common image source restrictions

Published Sep 9, 2024
CVE-2026-28458

OpenClaw's Browser Relay /cdp websocket is missing auth which could allow cross-tab cookie access

Published Feb 17, 2026
CVE-2026-22171

OpenClaw vulnerable to path traversal in Feishu media temp-file naming allows writes outside os.tmpdir()

Published Mar 3, 2026
CVE-2026-32041

OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failure

Published Mar 2, 2026
MAL-2025-4417

Malicious code in wsticket (npm)

Published May 23, 2025
MAL-2025-4472

Malicious code in athira-windows-x64 (npm)

Published May 27, 2025
CVE-2025-66401

MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL

Published Dec 2, 2025
MAL-2023-8213

Malicious code in sentrybrowser5 (npm)

Published Sep 21, 2023
CVE-2026-32054

OpenClaw has browser trace/download path symlink escape in temp output handling

Published Mar 2, 2026
CVE-2018-25110HIGH

Marked allows Regular Expression Denial of Service (ReDoS) attacks

Published May 23, 2025
CVE-2020-7758HIGH

Path Traversal in browserless-chrome

Published May 10, 2021
MAL-2022-3454

Malicious code in grenache-browser-http (npm)

Published Jun 20, 2022
MAL-2022-6950

Malicious code in vkchtoewspkjrfld (npm)

Published Jul 11, 2022
CVE-2020-28472HIGH

Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader

Published Nov 16, 2021
GHSA-5gqg-mqh5-2v39

Duplicate Advisory: OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

Published Mar 19, 2026
CVE-2025-69983

FUXA allows Remote Code Execution (RCE) via the project import functionality.

Published Feb 3, 2026
GHSA-w8g9-x8gx-crmm

OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable

Published Apr 9, 2026
MAL-2022-7212

Malicious code in woo-better-reviews (npm)

Published Jun 20, 2022
CVE-2025-26791

DOMPurify allows Cross-site Scripting (XSS)

Published Feb 14, 2025
CVE-2026-34601HIGH
Risk: 37.51/100

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

Published Apr 1, 2026
CVE-2026-32104

StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settings

Published Mar 12, 2026
MAL-2026-129

Malicious code in aws-target-mediator (npm)

Published Jan 7, 2026
CVE-2026-28391

OpenClaw's Windows cmd.exe parsing may bypass exec allowlist/approval gating

Published Feb 17, 2026
GHSA-cxcw-jm67-3wwp

Duplicate Advisory: OpenClaw's andbox browser noVNC observer lacked VNC authentication

Published Mar 21, 2026
MAL-2022-1693

Malicious code in browser-timings (npm)

Published Jun 20, 2022
CVE-2025-66032

Claude Code Command Validation Bypass Allows Arbitrary Code Execution

Published Dec 3, 2025
CVE-2016-10625HIGH

headless-browser-lite downloads Resources over HTTP

Published Feb 18, 2019
CVE-2023-37899HIGH

Feathers socket handler allows abusing implicit toString

Published Jul 20, 2023
MAL-2022-749

Malicious code in @xvideos/aws (npm)

Published Jun 20, 2022
MAL-2025-1022

Malicious code in awsume (npm)

Published Feb 3, 2025
CVE-2026-25940

jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)

Published Feb 19, 2026
MAL-2022-4695

Malicious code in moralis-web3-providers-ws (npm)

Published Jun 20, 2022
MAL-2022-2687

Malicious code in elasticagent-windows-arm (npm)

Published Jun 20, 2022
MAL-2026-2776

Malicious code in int-browsing-gateway (npm)

Published Apr 16, 2026
MAL-2026-2785

Malicious code in nemo-jaws (npm)

Published Apr 16, 2026
CVE-2026-2391

qs's arrayLimit bypass in comma parsing allows denial of service

Published Feb 12, 2026
CVE-2021-23364MEDIUM

Regular Expression Denial of Service in browserslist

Published May 24, 2021
CVE-2025-68154

systeminformation has a Command Injection vulnerability in fsSize() function on Windows

Published Dec 16, 2025
CVE-2024-49770

Path traversal in oak allows transfer of hidden files within the served root directory

Published Nov 1, 2024
MAL-2022-907

Malicious code in ainruohkpglvwsmj (npm)

Published Jul 11, 2022
MAL-2025-1367

Malicious code in jbrowse (npm)

Published Feb 13, 2025
MAL-2025-190816

Malicious code in @kvytech/medusa-plugin-newsletter (npm)

Published Nov 24, 2025
GHSA-rchv-x836-w7xp

OpenClaw's dashboard leaked gateway auth material via browser URL/query and localStorage

Published Mar 9, 2026
GHSA-xp9r-prpg-373r

OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface

Published Mar 30, 2026
GHSA-vmhq-cqm9-6p7q

OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes

Published Mar 13, 2026
MAL-2024-9238

Malicious code in ig-release-aws (npm)

Published Oct 10, 2024
MAL-2025-4568

Malicious code in mergify-browser-extension (npm)

Published May 24, 2025
MAL-2022-1198

Malicious code in aws-instance-scheduler (npm)

Published Jun 20, 2022
MAL-2022-1199

Malicious code in aws-iot-greengrass-accelerators (npm)

Published Jun 20, 2022
MAL-2022-1204

Malicious code in aws-track-and-trace (npm)

Published Jun 20, 2022
MAL-2022-1205

Malicious code in aws-video-transcriber (npm)

Published Jun 20, 2022
CVE-2026-27484

OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows

Published Feb 20, 2026
GHSA-xf4j-xp2r-rqqx

Hono: Path traversal in toSSG() allows writing files outside the output directory

Published Apr 8, 2026
CVE-2026-27700

Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo

Published Feb 25, 2026
CVE-2025-66420

Tryton sao allows XSS via an HTML attachment

Published Nov 30, 2025
MAL-2023-1038

Malicious code in sentrybrowser7 (npm)

Published Aug 1, 2023
CVE-2026-26972

OpenClaw has a Path Traversal in Browser Download Functionality

Published Feb 18, 2026
MAL-2026-2015

Malicious code in lingewindows (npm)

Published Mar 21, 2026
MAL-2022-1557

Malicious code in bfx-ws2-api-audit (npm)

Published Jun 20, 2022
MAL-2025-217

Malicious code in platform-browser-dynamic (npm)

Published Jan 20, 2025
MAL-2026-488

Malicious code in ntwsx (npm)

Published Jan 23, 2026
MAL-2024-1549

Malicious code in vue-webviews (npm)

Published Jun 7, 2024
MAL-2022-2725

Malicious code in ember-views (npm)

Published Jun 20, 2022
MAL-2023-216

Malicious code in crooked-kingdom-six-of-crows-2-by-leigh-bardugo-on-mac-full-format- (npm)

Published May 10, 2023
MAL-2022-2903

Malicious code in evycfpkhwsoqljrg (npm)

Published Jul 11, 2022
MAL-2023-677

Malicious code in pdf-reading-the-signs-by-keira-andrews-on-textbook-new-chapters- (npm)

Published May 10, 2023
MAL-2025-190847

Malicious code in jan-browser (npm)

Published Nov 24, 2025
MAL-2026-1665

Malicious code in browser-compat-data (npm)

Published Mar 18, 2026
MAL-2022-4867

Malicious code in nnabla-browser (npm)

Published Jun 20, 2022
MAL-2023-7938

Malicious code in node-hide-console-windows (npm)

Published Aug 28, 2023
MAL-2022-4351

Malicious code in loblaws-product-listing (npm)

Published Jun 20, 2022
MAL-2022-4352

Malicious code in loblawsdigitalflyer (npm)

Published Jun 20, 2022
MAL-2025-3127

Malicious code in windowsreveal (npm)

Published Apr 3, 2025
MAL-2025-4144

Malicious code in whatsapp-flows-endpoint (npm)

Published May 21, 2025
MAL-2024-7460

Malicious code in newsda (npm)

Published Jul 11, 2024
MAL-2023-8086

Malicious code in web3tool-providers-ws (npm)

Published Sep 11, 2023
MAL-2022-4704

Malicious code in mqttoverwsprovider (npm)

Published Jun 20, 2022
MAL-2026-131

Malicious code in awsm-core (npm)

Published Jan 7, 2026
MAL-2022-4830

Malicious code in nextcloud-news (npm)

Published Jun 20, 2022
MAL-2022-4842

Malicious code in ng-browser-info (npm)

Published Jun 20, 2022
MAL-2026-1971

Malicious code in trex-proxy-browser-extension-sdk (npm)

Published Mar 20, 2026
CVE-2018-6342CRITICAL

react-dev-utils on Windows vulnerable to Remote Code Execution

Published Jan 4, 2019
MAL-2026-716

Malicious code in si-wsl (npm)

Published Feb 4, 2026
MAL-2022-898

Malicious code in ai-aws-manager (npm)

Published Jun 8, 2022
CVE-2026-35412HIGH
Risk: 41.18/100

Directus: TUS Upload Authorization Bypass Allows Arbitrary File Overwrite

Published Apr 4, 2026
MAL-2024-12129

Malicious code in aws-iot-samples-util (npm)

Published Dec 26, 2024
CVE-2026-34526MEDIUM
Risk: 25.01/100

SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6

Published Apr 1, 2026
MAL-2022-1220

Malicious code in azure-accessplatform-windows-gpu (npm)

Published Jun 20, 2022
MAL-2025-1601

Malicious code in jaws-node (npm)

Published Feb 28, 2025
MAL-2025-5489

Malicious code in axios-browseragent (npm)

Published Jul 1, 2025
MAL-2025-17

Malicious code in facetec-browser-sdk (npm)

Published Jan 2, 2025
MAL-2023-1512

Malicious code in browserslist-config-usaa (npm)

Published Aug 21, 2023
MAL-2026-3307

Malicious code in browserslist-db (npm)

Published May 1, 2026
MAL-2022-3767

Malicious code in identity-browser-manual-tests (npm)

Published Jun 20, 2022
MAL-2026-3314

Malicious code in update-browserslist (npm)

Published May 1, 2026
MAL-2025-190906

Malicious code in @postman/pm-bin-windows-x64 (npm)

Published Nov 24, 2025
MAL-2022-5503

Malicious code in ps-request-ws (npm)

Published Jun 20, 2022
MAL-2022-3209

Malicious code in freekws-devportal-api-client-angular (npm)

Published Aug 22, 2022
MAL-2022-3210

Malicious code in freekws-devportal-api-client-nestjs (npm)

Published Aug 22, 2022
MAL-2022-5595

Malicious code in rawspec (npm)

Published Jun 20, 2022
MAL-2025-191205

Malicious code in @clausehq/flows-step-taskscreateurl (npm)

Published Nov 25, 2025
MAL-2022-5648

Malicious code in react-hackernews-bootcamp-one-v2 (npm)

Published Jun 20, 2022
MAL-2026-643

Malicious code in @hemanshu_patil/xcode-windows-x64 (npm)

Published Feb 2, 2026
CVE-2021-45459CRITICAL

Command Injection in node-windows

Published Jan 5, 2022
MAL-2023-8462

Malicious code in print-vault-browser (npm)

Published Nov 6, 2023
MAL-2024-11069

Malicious code in proton-vpn-browser-extension (npm)

Published Nov 27, 2024
CVE-2016-10604HIGH

dalek-browser-chrome Downloads Resources over HTTP

Published Feb 18, 2019
MAL-2022-5773

Malicious code in reviewstack (npm)

Published Oct 31, 2022
MAL-2025-1663

Malicious code in react-native-windows-repo (npm)

Published Mar 2, 2025
CVE-2025-50538

Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel

Published Oct 3, 2025
MAL-2024-11907

Malicious code in windows-confirm (npm)

Published Dec 17, 2024
MAL-2022-4129

Malicious code in kbxozjiervwstgyp (npm)

Published Jul 11, 2022
MAL-2025-191035

Malicious code in @ntnx/passport-wso2 (npm)

Published Nov 24, 2025
MAL-2024-11908

Malicious code in windows-version-check (npm)

Published Dec 17, 2024
MAL-2025-191196

Malicious code in @browserbasehq/mcp-server-browserbase (npm)

Published Nov 25, 2025
MAL-2025-191197

Malicious code in @browserbasehq/sdk-functions (npm)

Published Nov 25, 2025
MAL-2025-191198

Malicious code in @browserbasehq/stagehand (npm)

Published Nov 25, 2025
MAL-2025-191448

Malicious code in vue-browserupdate-nuxt (npm)

Published Nov 24, 2025
MAL-2022-6033

Malicious code in service-workbench-on-aws (npm)

Published Jun 20, 2022
MAL-2024-7872

Malicious code in @adidas-data-mesh/common-aws (npm)

Published Aug 1, 2024
MAL-2022-3399

Malicious code in gme-loblawsinc (npm)

Published Jun 20, 2022
GHSA-2hm8-rqrm-xfjq

OpenClaw's owner-only gateway tool access checks were incomplete in specific authenticated DM flows

Published Mar 3, 2026
CVE-2026-33577HIGH
Risk: 40.5/100

OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes

Published Apr 1, 2026
MAL-2022-4821

Malicious code in newspack-blocks (npm)

Published Jun 20, 2022
MAL-2025-313

Malicious code in social-previews (npm)

Published Jan 21, 2025
CVE-2026-22180

OpenClaw: Unified root-bound write hardening for browser output and related path-boundary flows

Published Mar 3, 2026
MAL-2025-4915

Malicious code in @velorum/browser-authenticator (npm)

Published Jun 6, 2025
MAL-2022-6303

Malicious code in steamdb-browser-extension (npm)

Published Jun 20, 2022
CVE-2026-4599

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

Published Mar 23, 2026
CVE-2018-3718MEDIUM

vercel/serve allows access to restricted files if filename is URL encoded.

Published Aug 9, 2021
GHSA-65w6-pf7x-5g85

@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections

Published Apr 8, 2026
CVE-2025-66421

Tryton sao allows XSS because it does not escape completion values

Published Nov 30, 2025
CVE-2019-18818CRITICAL

Strapi allows unauthenticated attacker to reset admin password without valid reset token

Published Dec 2, 2019
MAL-2023-8677

Malicious code in sentrybrowser (npm)

Published Dec 8, 2023
CVE-2025-69263

pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies

Published Jan 7, 2026
GHSA-8847-338w-5hcj

i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite

Published Apr 22, 2026
MAL-2025-4485

Malicious code in ideals-views (npm)

Published May 26, 2025
MAL-2025-4507

Malicious code in skinnyvans-windows-arm64 (npm)

Published May 27, 2025
MAL-2025-4508

Malicious code in skinnyvans-windows-x64 (npm)

Published May 27, 2025
MAL-2022-7240

Malicious code in ws-gp-security-action (npm)

Published Jun 20, 2022
MAL-2022-7241

Malicious code in wso-core (npm)

Published Jun 20, 2022
GHSA-j5w5-568x-rq53

Evolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code Execution

Published Apr 22, 2026
MAL-2023-197

Malicious code in codeceptjs-browserstack (npm)

Published Feb 2, 2023
MAL-2025-4099

Malicious code in lolnews (npm)

Published May 21, 2025
CVE-2026-34522HIGH
Risk: 40.52/100

SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory

Published Apr 1, 2026
GHSA-r466-rxw4-3j9j

Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write

Published Apr 22, 2026
MAL-2025-86

Malicious code in efergvthdaadgfhrgewsfqwf (npm)

Published Jan 14, 2025
MAL-2025-4813

Malicious code in axios-browserify (npm)

Published Jun 10, 2025
MAL-2026-630

Malicious code in cowsay-allcaps (npm)

Published Feb 2, 2026
MAL-2026-631

Malicious code in cowsay-caps (npm)

Published Feb 2, 2026
MAL-2026-632

Malicious code in cowsay-deluxe (npm)

Published Feb 2, 2026
MAL-2026-633

Malicious code in cowsay-fancy (npm)

Published Feb 2, 2026
MAL-2026-487

Malicious code in ntwsc (npm)

Published Jan 23, 2026
MAL-2026-130

Malicious code in awsm-acslibs (npm)

Published Jan 7, 2026
MAL-2025-701

Malicious code in browser-nextjs (npm)

Published Jan 31, 2025
MAL-2026-214

Malicious code in analytics-browser (npm)

Published Jan 12, 2026
MAL-2026-2243

Malicious code in browserstack-electron-forge-include-package-plugin (npm)

Published Mar 26, 2026
MAL-2025-3658

Malicious code in windows-api-codec-pack (npm)

Published May 6, 2025
MAL-2026-406

Malicious code in aws-crt-nodejs (npm)

Published Jan 21, 2026
MAL-2026-1057

Malicious code in windowston (npm)

Published Feb 26, 2026
MAL-2025-4333

Malicious code in dev.voltstro.unitywebbrowser (npm)

Published May 23, 2025
Check your entire dependency tree at onceRun dependency scan →