Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g74q-6g2f-874x
  • npm/@tinacms/auth
  • npm/next-tinacms-azure
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site 17 Sep
  • Fix available
  • Severity - 8.8 (High)
MAL-2026-14438
  • npm/remove-bg-serverless-azure
Malicious code in remove-bg-serverless-azure (npm) 24 Aug
  • No fix available
GHSA-8mq9-5fw2-5rm4
  • npm/next-tinacms-azure
  • npm/next-tinacms-cloudinary
  • npm/next-tinacms-dos
  • npm/next-tinacms-s3
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) 19 Aug
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-vp3h-ghgh-jr7g
  • npm/@nx/azure-cache
  • npm/@nx/gcs-cache
  • npm/@nx/powerpack-azure-cache
  • npm/@nx/powerpack-gcs-cache
  • npm/@nx/powerpack-s3-cache
  • ... 4 more
Nx: Zip-Slip in the self-hosted remote cache 06 Aug
  • Fix available
  • Severity - 8.7 (High)
MAL-2026-12400
  • npm/matlab-azure-devops-extension
Malicious code in matlab-azure-devops-extension (npm) 05 Aug
  • No fix available
MAL-2026-10871
  • npm/@azure-lab-services/ml-ts
Malicious code in @azure-lab-services/ml-ts (npm) 20 Jul
  • No fix available
GHSA-jgg6-4rpr-wfh7
  • npm/@mistralai/mistralai
  • npm/@mistralai/mistralai-azure
  • npm/@mistralai/mistralai-gcp
Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp 18 May
  • No fix available
  • Severity - 0.0 (None)
MAL-2026-3511
  • npm/@mistralai/mistralai-azure
Malicious code in @mistralai/mistralai-azure (npm) 12 May
  • No fix available
GHSA-frq9-7j6g-v74x
  • npm/@payloadcms/storage-azure
  • npm/@payloadcms/storage-gcs
  • npm/@payloadcms/storage-r2
  • npm/@payloadcms/storage-s3
Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints 01 Apr
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hhfx-wfvq-7g9c
  • NuGet/Azure.Mcp
  • PyPI/msmcp-azure
  • npm/@azure/mcp
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network 10 Mar
  • Fix available
  • Severity - 8.8 (High)
MAL-2026-975
  • npm/azure-postgresql-auth
Malicious code in azure-postgresql-auth (npm) 20 Feb
  • No fix available
MAL-2025-192601
  • npm/vscode-azure-mcp-server
Malicious code in vscode-azure-mcp-server (npm) 16 Dec 2025
  • No fix available
MAL-2025-138602
  • npm/bumpy-azure-hawk
Malicious code in bumpy-azure-hawk (npm) 12 Nov 2025
  • No fix available
MAL-2025-138618
  • npm/cold-azure-thrush
Malicious code in cold-azure-thrush (npm) 12 Nov 2025
  • No fix available
MAL-2025-138821
  • npm/junior-azure-lemur
Malicious code in junior-azure-lemur (npm) 12 Nov 2025
  • No fix available
MAL-2025-138887
  • npm/naughty-azure-mink
Malicious code in naughty-azure-mink (npm) 12 Nov 2025
  • No fix available