Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g74q-6g2f-874x
  • npm/@tinacms/auth
  • npm/next-tinacms-azure
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site 5 days ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-2xp9-vwfh-vxw4
  • npm/next
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used 08 Sep
  • Fix available
  • Severity - 9.5 (Critical)
GHSA-p293-qw3h-jr36
  • npm/next
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers 08 Sep
  • Fix available
  • Severity - 9.0 (Critical)
MAL-2026-14346
  • npm/@next-fonts/font
Malicious code in @next-fonts/font (npm) 21 Aug
  • No fix available
GHSA-2p39-2jf3-fv2q
  • npm/next-video
next-video: Unauthenticated arbitrary file read via /api/video request handler 20 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-8mq9-5fw2-5rm4
  • npm/next-tinacms-azure
  • npm/next-tinacms-cloudinary
  • npm/next-tinacms-dos
  • npm/next-tinacms-s3
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters) 19 Aug
  • Fix available
  • Severity - 5.4 (Medium)
MAL-2026-13995
  • npm/@dsp-next-gen-ui/needs-review
Malicious code in @dsp-next-gen-ui/needs-review (npm) 13 Aug
  • No fix available
MAL-2026-11609
  • npm/@onereach/or-browser-next
Malicious code in @onereach/or-browser-next (npm) 04 Aug
  • No fix available
MAL-2026-11965
  • npm/conv-context-next
Malicious code in conv-context-next (npm) 04 Aug
  • No fix available
MAL-2026-11611
  • npm/@onereach/or-file-uploader-next
Malicious code in @onereach/or-file-uploader-next (npm) 04 Aug
  • No fix available
MAL-2026-11069
  • npm/clerk-next-fix-auth-protection
Malicious code in clerk-next-fix-auth-protection (npm) 24 Jul
  • No fix available
GHSA-8fpg-xm3f-6cx3
  • npm/next-auth
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-xmf8-cvqr-rfgj
  • npm/@auth/core
  • npm/next-auth
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers 23 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-7rqj-j65f-68wh
  • npm/@auth/core
  • npm/next-auth
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-x445-f3h2-j279
  • npm/@auth/core
  • npm/next-auth
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them 23 Jul
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-89xv-2m56-2m9x
  • npm/next
Next.js: Server-Side Request Forgery in Server Actions on custom servers 22 Jul
  • Fix available
  • Severity - 8.3 (High)