Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
713658
AlmaLinux
5081
Alpaquita
10222
Alpine
4283
Android
3402
Azure Linux
12016
BellSoft Hardened Containers
521
Bitnami
8141
Chainguard
7157
CleanStart
1497
CRAN
14
crates.io
2487
Debian
58273
Echo
5488
GHC
3
GIT
81697
GitHub Actions
54
Go
7191
Hackage
32
Hex
142
Julia
950
Linux
15361
Mageia
6001
Maven
6597
MinimOS
74018
npm
220840
NuGet
1731
opam
18
openEuler
7054
openSUSE
13117
OSS-Fuzz
3934
Packagist
6502
Pub
11
PyPI
20274
Red Hat
20752
Rocky Linux
3468
Root
16014
RubyGems
2000
SUSE
20874
SwiftURL
58
TuxCare
5651
Ubuntu
56031
VSCode
20
Wolfi
4681
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7c78-jf6q-g5cm
npm/tmp
tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
15 Jun
Fix available
Severity - 8.2 (High)
GHSA-ph9p-34f9-6g65
npm/tmp
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
27 May
Fix available
Severity - 7.7 (High)
MAL-2025-48005
npm/tmp-npmsnha
Malicious code in tmp-npmsnha (npm)
07 Oct 2025
No fix available
MAL-2025-36995
npm/tmp-tmp3
Malicious code in tmp-tmp3 (npm)
14 Aug 2025
No fix available
GHSA-52f5-9888-hmc6
npm/tmp
tmp allows arbitrary temporary file / directory write via symbolic link
`
dir
`
parameter
06 Aug 2025
Fix available
Severity - 2.5 (Low)
MAL-2022-60
npm/@adam_baldwin/tag-tmp
Malicious code in @adam_baldwin/tag-tmp (npm)
01 Jun 2022
No fix available
npm - OSV