Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-v5rq-49vh-5v5c
  • npm/@simple-git/argv-parser
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection 4 hours ago
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-x6jw-m9v5-85vh
  • npm/simple-git
simple-git unsafe-operation guard does not block trailer command configuration 4 hours ago
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-g4wm-2vf7-vfgr
  • npm/simple-git
simple-git allows command execution through unblocked Git configuration includes 4 hours ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-858h-whjf-mvg5
  • npm/simple-git
simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291) 4 hours ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-wfpm-5gcm-94cg
  • npm/@socket.io/cluster-engine
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup 4 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-6688-9rhm-gjv2
  • npm/dompurify
DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes 4 hours ago
  • Fix available
GHSA-r4xh-jqrq-34v2
  • npm/smol-toml
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line 4 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-238p-pmpm-9mq7
  • npm/katex
KaTeX: Existing prototype pollution can bypass trust restrictions 4 hours ago
  • Fix available
  • Severity - 2.1 (Low)
GHSA-p6vx-979v-rg4c
  • npm/seroval
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw) 4 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-jp82-f5mq-hwhp
  • npm/seroval
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization 4 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jqcg-44mw-7w3h
  • npm/proxy-addr
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 4 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-6vc5-vf29-ffr2
  • npm/@nx/docker
@nx/docker: OS command injection in the @nx/docker release pipeline 4 hours ago
  • Fix available
  • Severity - 7.3 (High)
GHSA-w2vw-w76x-qr89
  • npm/nx
Nx: OS command injection via git revisions and remote refs 4 hours ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-w3vv-58gj-gw77
  • npm/nx
Nx daemon and plugin worker sockets are accessible to other local users 4 hours ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-hrvq-x7jp-36xv
  • npm/nx
Nx: Path traversal in nx migrate package-migrations extraction 4 hours ago
  • Fix available
  • Severity - 5.8 (Medium)
GHSA-vc2v-76pw-4v95
  • npm/compression
compression vulnerable to Denial of Service via memory leak on premature response close 4 hours ago
  • Fix available
  • Severity - 7.5 (High)