Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-f67j-2jqw-jpq7
  • npm/@angular/platform-server
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE 28 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-j3r3-mxqp-r2p4
  • npm/@angular/platform-server
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements 28 Sep
  • Fix available
  • Severity - 8.6 (High)
GHSA-72h8-wp98-7hch
  • npm/unleash-server
Unleash: Missing await on permission check + cross-project IDOR in admin API 22 Sep
  • Fix available
  • Severity - 7.1 (High)
GHSA-5ffh-6f9q-5hhr
  • npm/unleash-server
Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log 22 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-8xcj-9hfr-fh9j
  • npm/unleash-server
Unleash: Clone-feature lets a user copy a feature from a project they cannot read 22 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7hvx-28gp-mf6j
  • npm/unleash-server
Unleash: CR-approval email renders user-controlled raw HTML 22 Sep
  • Fix available
  • Severity - 2.1 (Low)
GHSA-89vx-jh4q-vg3w
  • npm/@deepstream/server
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes 22 Sep
  • Fix available
  • Severity - 8.8 (High)
GHSA-798p-78g2-v556
  • npm/@aborruso/ckan-mcp-server
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509 22 Sep
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-29hq-23m2-2j47
  • npm/@sync-in/server
Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory) 22 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-jx63-h26r-8cph
  • npm/@sync-in/server
Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` 22 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-92cr-jxw4-5wjg
  • npm/@sync-in/server
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` 22 Sep
  • Fix available
  • Severity - 8.1 (High)
GHSA-274f-6w77-8qm9
  • npm/@sync-in/server
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` 22 Sep
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-j9v4-rhgr-4m5f
  • npm/@orpc/server
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass 17 Sep
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-rqx4-3f6q-3x2v
  • npm/@mockoon/cli
  • npm/@mockoon/commons-server
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft 11 Sep
  • Fix available
  • Severity - 8.8 (High)
GHSA-8wqc-v2q8-vff2
  • npm/@mockoon/cli
  • npm/@mockoon/commons-server
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check) 11 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-v3p8-whq6-r5jg
  • npm/@angular/platform-server
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements 10 Sep
  • Fix available
  • Severity - 8.6 (High)