Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16090
  • npm/sams-run-style
Malicious code in sams-run-style (npm) 09 Sep
  • No fix available
MAL-2026-11654
  • npm/@onereach/step-run-snowflake-query
Malicious code in @onereach/step-run-snowflake-query (npm) 04 Aug
  • No fix available
MAL-2026-10493
  • npm/insomnia-plugin-poc-m4gester-run
Malicious code in insomnia-plugin-poc-m4gester-run (npm) 13 Jul
  • No fix available
GHSA-84g9-w2xq-vcv6
  • npm/@remix-run/server-runtime
  • npm/react-router
React Router: Potential CSRF via PUT/PATCH/DELETE document requests 15 Jun
  • Fix available
  • Severity - 3.1 (Low)
MAL-2026-5641
  • npm/goreleaser-run
Malicious code in goreleaser-run (npm) 11 Jun
  • No fix available
GHSA-8x6r-g9mw-2r78
  • npm/@remix-run/server-runtime
  • npm/react-router
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint 03 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-2j2x-hqr9-3h42
  • npm/@remix-run/router
  • npm/react-router
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation 03 Jun
  • Fix available
  • Severity - 6.6 (Medium)
MAL-2026-4944
  • npm/@cloudplatform-single-spa/ml-inference-comfy-run
Malicious code in @cloudplatform-single-spa/ml-inference-comfy-run (npm) 28 May
  • No fix available
MAL-2026-4945
  • npm/@cloudplatform-single-spa/ml-inference-docker-run
Malicious code in @cloudplatform-single-spa/ml-inference-docker-run (npm) 28 May
  • No fix available
MAL-2026-4947
  • npm/@cloudplatform-single-spa/ml-inference-model-run
Malicious code in @cloudplatform-single-spa/ml-inference-model-run (npm) 28 May
  • No fix available
GHSA-wpqr-6v78-jr5g
  • GitHub Actions/google-github-actions/run-gemini-cli
  • npm/@google/gemini-cli
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses 24 Apr
  • Fix available
  • Severity - 10.0 (Critical)
MAL-2026-2747
  • npm/cloud-run-microservice-template
Malicious code in cloud-run-microservice-template (npm) 16 Apr
  • No fix available
GHSA-h5cw-625j-3rxh
  • npm/@remix-run/server-runtime
  • npm/react-router
React Router has CSRF issue in Action/Server Action Request Processing 08 Jan
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2w69-qvjg-hvjx
  • npm/@remix-run/router
  • npm/react-router
React Router vulnerable to XSS via Open Redirects 08 Jan
  • Fix available
  • Severity - 8.0 (High)
GHSA-8v8x-cx79-35w7
  • npm/@remix-run/react
  • npm/react-router
React Router SSR XSS in ScrollRestoration 08 Jan
  • Fix available
  • Severity - 8.2 (High)
GHSA-9583-h5hc-x8cw
  • npm/@react-router/node
  • npm/@remix-run/deno
  • npm/@remix-run/node
React Router has Path Traversal in File Session Storage 08 Jan
  • Fix available
  • Severity - 9.1 (Critical)