Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17636
  • npm/hardhat-init
Malicious code in hardhat-init (npm) 2 hours ago
  • No fix available
MAL-2026-17341
  • npm/@badzz88/baileys
Malicious code in @badzz88/baileys (npm) 2 hours ago
  • No fix available
MAL-2026-17632
  • npm/internallib_v23
Malicious code in internallib_v23 (npm) 2 hours ago
  • No fix available
MAL-2026-17631
  • npm/@pinecone-experience/messages
Malicious code in @pinecone-experience/messages (npm) 2 hours ago
  • No fix available
MAL-2026-17633
  • npm/internallib_v30
Malicious code in internallib_v30 (npm) 2 hours ago
  • No fix available
MAL-2026-17634
  • npm/internallib_v86
Malicious code in internallib_v86 (npm) 2 hours ago
  • No fix available
MAL-2026-17635
  • npm/internallib_v875
Malicious code in internallib_v875 (npm) 2 hours ago
  • No fix available
GHSA-v5rq-49vh-5v5c
  • npm/@simple-git/argv-parser
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection 6 hours ago
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-x6jw-m9v5-85vh
  • npm/simple-git
simple-git unsafe-operation guard does not block trailer command configuration 6 hours ago
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-g4wm-2vf7-vfgr
  • npm/simple-git
simple-git allows command execution through unblocked Git configuration includes 6 hours ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-858h-whjf-mvg5
  • npm/simple-git
simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291) 6 hours ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-wfpm-5gcm-94cg
  • npm/@socket.io/cluster-engine
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup 6 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-6688-9rhm-gjv2
  • npm/dompurify
DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes 6 hours ago
  • Fix available
GHSA-r4xh-jqrq-34v2
  • npm/smol-toml
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line 6 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-238p-pmpm-9mq7
  • npm/katex
KaTeX: Existing prototype pollution can bypass trust restrictions 6 hours ago
  • Fix available
  • Severity - 2.1 (Low)
GHSA-p6vx-979v-rg4c
  • npm/seroval
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw) 6 hours ago
  • Fix available
  • Severity - 9.8 (Critical)