Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16086
  • npm/graphql-js-client-transform
Malicious code in graphql-js-client-transform (npm) 09 Sep
  • No fix available
MAL-2026-16063
  • npm/alloy-graphql
Malicious code in alloy-graphql (npm) 09 Sep
  • No fix available
MAL-2026-14210
  • npm/sui-graphql-rpc
Malicious code in sui-graphql-rpc (npm) 19 Aug
  • No fix available
MAL-2026-14121
  • npm/sui-move-graphql
Malicious code in sui-move-graphql (npm) 18 Aug
  • No fix available
MAL-2026-13475
  • npm/sui-graphql-client
Malicious code in sui-graphql-client (npm) 06 Aug
  • No fix available
MAL-2026-11756
  • npm/@ornikar/graphql-config
Malicious code in @ornikar/graphql-config (npm) 04 Aug
  • No fix available
MAL-2026-4590
  • npm/json-to-simple-graphql-schema
Malicious code in json-to-simple-graphql-schema (npm) 25 May
  • No fix available
GHSA-hp5w-3hxx-vmwf
  • npm/@payloadcms/graphql
  • npm/payload
Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery 01 Apr
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-g9c2-gf25-3x67
  • npm/@tinacms/graphql
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions 01 Apr
  • Fix available
  • Severity - 7.1 (High)
GHSA-g87c-r2jp-293w
  • npm/@tinacms/graphql
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions 01 Apr
  • Fix available
  • Severity - 7.1 (High)
GHSA-v9p7-gf3q-h779
  • npm/@tinacms/graphql
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files 30 Mar
  • Fix available
  • Severity - 8.1 (High)
MAL-2026-1444
  • npm/graphql-request-dom
Malicious code in graphql-request-dom (npm) 16 Mar
  • No fix available
MAL-2026-1540
  • npm/typescript-type-graphql
Malicious code in typescript-type-graphql (npm) 16 Mar
  • No fix available
GHSA-2238-xc5r-v9hj
  • npm/@tinacms/graphql
@tinacms/graphql has a Path Traversal issue 12 Mar
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-h3hw-29fv-2x75
  • npm/@envelop/graphql-modules
@envelop/graphql-modules has a Race Condition vulnerability 21 Jan
  • Fix available
  • Severity - 8.7 (High)
GHSA-53wg-r69p-v3r7
  • npm/graphql-modules
GraphQL Modules has a Race Condition issue 16 Jan
  • Fix available
  • Severity - 8.7 (High)