Package ecosystem
npm package vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 5,362 vulnerabilities in npm packages: 23 in the last 7 days and 606 in the last 90 days, 197 of them critical and 3 exploited in the wild. The most recent, CVE-2026-61788, was published on 24 September 2026. 392 packages have a page of their own.
- Last 7 days
- 23
- Last 90 days
- 606
- Critical, all time
- 197
- Exploited in the wild
- 3
About npm
npm is a package manager and registry for JavaScript and Node.js packages.
npm packages
- flowise (npm)156
- vm2 (npm)82
- @budibase/server (npm)61
- directus (npm)60
- nocodb (npm)55
- hono (npm)54
- parse-server (npm)42
- dompurify (npm)39
- ghost (npm)39
- flowise-components (npm)35
- astro (npm)30
- @anthropic-ai/claude-code (npm)28
- 9router (npm)26
- better-auth (npm)24
- fuxa-server (npm)24
- renovate (npm)24
- tinymce (npm)23
- @xmldom/xmldom (npm)22
- electron (npm)21
- @openzeppelin/contracts-upgradeable (npm)20
- electerm (npm)19
- sequelize (npm)19
- @sveltejs/kit (npm)19
- xmldom (npm)19
- liquidjs (npm)18
- @openzeppelin/contracts (npm)18
- shescape (npm)18
- apostrophe (npm)17
- @haxtheweb/haxcms-nodejs (npm)16
- jspdf (npm)16
- mermaid (npm)16
- angular (npm)15
- ckeditor4 (npm)15
- node-forge (npm)15
- svelte (npm)15
- jsrsasign (npm)14
- @nyariv/sandboxjs (npm)14
- @paperclipai/server (npm)14
- pnpm (npm)14
- signalk-server (npm)14
- swagger-ui (npm)14
- systeminformation (npm)14
- @directus/api (npm)13
- js-yaml (npm)13
- sanitize-html (npm)13
- strapi (npm)13
- @asymmetric-effort/specifyjs (npm)12
- bootstrap (npm)12
- clawdbot (npm)12
- @evershop/evershop (npm)12
- matrix-js-sdk (npm)12
- n8n-mcp (npm)12
- npm (npm)12
- orval (npm)12
- undici (npm)12
- uptime-kuma (npm)12
- fastify (npm)11
- @hulumi/policies (npm)11
- @lobehub/chat (npm)11
- mongoose (npm)11
- nuxt (npm)11
- @oneuptime/common (npm)11
- payload (npm)11
- sillytavern (npm)11
- @strapi/strapi (npm)11
- devalue (npm)10
- h3 (npm)10
- aws-cdk-lib (npm)9
- elliptic (npm)9
- matrix-appservice-irc (npm)9
- mysql2 (npm)9
- serve (npm)9
- trix (npm)9
- @vitejs/plugin-rsc (npm)9
- ws (npm)9
- @actual-app/sync-server (npm)8
- budibase (npm)8
- @builder.io/qwik-city (npm)8
- @dynatrace-oss/dynatrace-mcp-server (npm)8
- editor.md (npm)8
- express-cart (npm)8
- fast-jwt (npm)8
- fast-xml-parser (npm)8
- hapi (npm)8
- jquery-ui (npm)8
- @keystone-6/core (npm)8
- locutus (npm)8
- lodash (npm)8
- matrix-react-sdk (npm)8
- mcp-searxng (npm)8
- next-auth (npm)8
- steal (npm)8
- @strapi/plugin-users-permissions (npm)8
- tarteaucitronjs (npm)8
- @tinacms/cli (npm)8
- typeorm (npm)8
- urijs (npm)8
- url-parse (npm)8
- @astrojs/node (npm)7
- @backstage/plugin-scaffolder-backend (npm)7
- bootstrap-sass (npm)7
- brace-expansion (npm)7
- ep_etherpad-lite (npm)7
- hermes-engine (npm)7
- @hono/node-server (npm)7
- jodit (npm)7
- lunary (npm)7
- simple-git (npm)7
- snyk-broker (npm)7
- studiocms (npm)7
- @sync-in/server (npm)7
- total.js (npm)7
- ua-parser-js (npm)7
- webpack-dev-server (npm)7
- aaptjs (npm)6
- @aborruso/ckan-mcp-server (npm)6
- @auth0/nextjs-auth0 (npm)6
- basic-ftp (npm)6
- @budibase/backend-core (npm)6
- @evomap/evolver (npm)6
- @fastify/static (npm)6
- follow-redirects (npm)6
- @frangoteam/fuxa (npm)6
- lodash-es (npm)6
- mcp-server-kubernetes (npm)6
- muhammara (npm)6
- node-opcua (npm)6
- openpgp (npm)6
- parse-url (npm)6
- passport-wsfed-saml2 (npm)6
- prismjs (npm)6
- quill (npm)6
- rsshub (npm)6
- safe-eval (npm)6
- @saltcorn/server (npm)6
- @samanhappy/mcphub (npm)6
- seroval (npm)6
- @steipete/summarize (npm)6
- swagger-typescript-api (npm)6
- unleash-server (npm)6
- vega (npm)6
- @vendure/core (npm)6
- vite-plus (npm)6
- adm-zip (npm)5
- apollo-server (npm)5
- auth0-js (npm)5
- @backstage/plugin-auth-backend (npm)5
- convict (npm)5
- dns-sync (npm)5
- ecstatic (npm)5
- ejs (npm)5
- engine.io (npm)5
- esbuild (npm)5
- exceljs (npm)5
- froala-editor (npm)5
- generator-jhipster (npm)5
- glance (npm)5
- @grackle-ai/server (npm)5
- happy-dom (npm)5
- http-proxy-middleware (npm)5
- jsonwebtoken (npm)5
- katex (npm)5
- mathjs (npm)5
- minimatch (npm)5
- nanoid (npm)5
- @nestjs/platform-fastify (npm)5
- nuxt-og-image (npm)5
- @perfood/couch-auth (npm)5
- postcss (npm)5
- public (npm)5
- rendertron (npm)5
- safer-eval (npm)5
- @sequelize/core (npm)5
- serialize-javascript (npm)5
- sm-crypto (npm)5
- @strapi/admin (npm)5
- sweetalert2 (npm)5
- @tinacms/graphql (npm)5
- total4 (npm)5
- unhead (npm)5
- vditor (npm)5
- vega-functions (npm)5
- xlsx (npm)5
- yarn (npm)5
- @zereight/mcp-gitlab (npm)5
- @apollo/gateway (npm)4
- apollo-server-core (npm)4
- @asymmetric-effort/nogginlessdom (npm)4
- auth0-lock (npm)4
- aws-iot-device-sdk-v2 (npm)4
- bestzip (npm)4
- @better-auth/oauth-provider (npm)4
- @better-auth/scim (npm)4
- @bitbonsai/mcpvault (npm)4
- @builder.io/qwik (npm)4
- @cloudflare/workers-oauth-provider (npm)4
- code-server (npm)4
- convert-svg-core (npm)4
- @cyclonedx/cdxgen (npm)4
- dojo (npm)4
- @earendil-works/pi-coding-agent (npm)4
- erxes (npm)4
- @excalidraw/excalidraw (npm)4
- express-xss-sanitizer (npm)4
- @fastify/middie (npm)4
- @fastify/reply-from (npm)4
- @feathersjs/authentication-oauth (npm)4
- @finos/git-proxy (npm)4
- @frontmcp/adapters (npm)4
- highcharts (npm)4
- @hulumi/baseline (npm)4
- hummus (npm)4
- i18next-http-middleware (npm)4
- @intlify/vue-i18n-core (npm)4
- ip-address (npm)4
- is-my-json-valid (npm)4
- jquery-validation (npm)4
- kysely (npm)4
- LangSmith (npm)4
- libxmljs (npm)4
- markdown-it (npm)4
- materialize-css (npm)4
- mercurius (npm)4
- mongosh (npm)4
- node-saml (npm)4
- @node-saml/node-saml (npm)4
- @novu/api (npm)4
- openclaude (npm)4
- @openclaw/feishu (npm)4
- parse-dashboard (npm)4
- path-to-regexp (npm)4
- petite-vue-i18n (npm)4
- psitransfer (npm)4
- realms-shim (npm)4
- remarkable (npm)4
- repomix (npm)4
- sails (npm)4
- @sap/approuter (npm)4
- ses (npm)4
- shell-quote (npm)4
- showdown (npm)4
- simple-markdown (npm)4
- simplehttpserver (npm)4
- snyk (npm)4
- @strapi/plugin-content-manager (npm)4
- @sveltia/cms (npm)4
- tar-fs (npm)4
- tinacms (npm)4
- @tiptap/core (npm)4
- @uppy/companion (npm)4
- valine (npm)4
- vue-i18n (npm)4
- webpack (npm)4
- xdlocalstorage (npm)4
- xml-crypto (npm)4
- yapi-vendor (npm)4
- actual (npm)3
- aedes (npm)3
- @agenticmail/api (npm)3
- @agenticmail/core (npm)3
- agnai (npm)3
- @aiondadotcom/mcp-ssh (npm)3
- @astrojs/netlify (npm)3
- @astrojs/vercel (npm)3
- auth-fetch-mcp (npm)3
- @backstage/techdocs-common (npm)3
- bin-links (npm)3
- blamer (npm)3
- braces (npm)3
- browserify-shim (npm)3
- browserslist (npm)3
- bson (npm)3
- buttle (npm)3
- ckeditor5 (npm)3
- codecov (npm)3
- @commercial/subtext (npm)3
- crypto-js (npm)3
- @cubejs-backend/api-gateway (npm)3
- docsify (npm)3
- dojox (npm)3
- dot (npm)3
- dset (npm)3
- express-fileupload (npm)3
- @fastify/express (npm)3
- feathers-sequelize (npm)3
- file-type (npm)3
- find-my-way (npm)3
- ftp-srv (npm)3
- gemini-mcp-tool (npm)3
- gnuplot (npm)3
- @grackle-ai/mcp (npm)3
- @grackle-ai/powerline (npm)3
- grunt (npm)3
- @hapi/content (npm)3
- harp (npm)3
- hekto (npm)3
- http-live-simulator (npm)3
- https-proxy-agent (npm)3
- @hulumi/drift (npm)3
- ids-enterprise (npm)3
- image-size (npm)3
- immer (npm)3
- @intlify/core (npm)3
- @intlify/core-base (npm)3
- @janhq/core (npm)3
- @jmondi/url-to-png (npm)3
- jointjs (npm)3
- jose-node-cjs-runtime (npm)3
- jose-node-esm-runtime (npm)3
- jquery-file-upload (npm)3
- json-ptr (npm)3
- jsondiffpatch (npm)3
- jwt-simple (npm)3
- keycloak-connect (npm)3
- knex (npm)3
- @langchain/community (npm)3
- layui (npm)3
- @libp2p/gossipsub (npm)3
- llhttp (npm)3
- @lobehub/lobehub (npm)3
- localhost-now (npm)3
- lodash.defaultsdeep (npm)3
- m-server (npm)3
- mailgen (npm)3
- @mariozechner/pi-coding-agent (npm)3
- @materializecss/materialize (npm)3
- mathlive (npm)3
- mcp-markdownify-server (npm)3
- minimist (npm)3
- @modelcontextprotocol/sdk (npm)3
- mxgraph (npm)3
- nadesiko3 (npm)3
- neotoma (npm)3
- next-intl (npm)3
- node-fetch (npm)3
- node-ipc (npm)3
- node-jose (npm)3
- node-red-dashboard (npm)3
- notevil (npm)3
- @nuxt/devtools (npm)3
- @nuxtjs/mdc (npm)3
- object-path (npm)3
- opencc (npm)3
- openmct (npm)3
- @openzeppelin/wizard (npm)3
- paperclipai (npm)3
- parse (npm)3
- parsel (npm)3
- passport-saml (npm)3
- @payloadcms/graphql (npm)3
- @payloadcms/next (npm)3
- pdf-image (npm)3
- @pdfme/schemas (npm)3
- protobufjs (npm)3
- raneto (npm)3
- @remix-run/server-runtime (npm)3
- request (npm)3
- rollbar (npm)3
- samlify (npm)3
- @sentry/astro (npm)3
- @sentry/nextjs (npm)3
- serialize-to-js (npm)3
- set-in (npm)3
- slp-validate (npm)3
- slpjs (npm)3
- smol-toml (npm)3
- snowflake-sdk (npm)3
- socket.io (npm)3
- socket.io-file (npm)3
- @soketi/soketi (npm)3
- static-eval (npm)3
- statics-server (npm)3
- stimulsoft-dashboards-js (npm)3
- @strapi/core (npm)3
- @strapi/utils (npm)3
- @theia/ai-chat (npm)3
- @theia/ai-chat-ui (npm)3
- @theia/ai-claude-code (npm)3
- @theia/ai-code-completion (npm)3
- @theia/ai-core (npm)3
- @theia/ai-editor (npm)3
- tmp (npm)3
- tough-cookie (npm)3
- tree-kill (npm)3
- @typebot.io/js (npm)3
- uap-core (npm)3
- uglify-js (npm)3
- uri-js (npm)3
- @vrite/sdk (npm)3
- vuetify (npm)3
- @workos-inc/authkit-nextjs (npm)3
- wrangler (npm)3
Latest npm package vulnerabilities
- CVE-2026-61788: DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting…highCVSS 7.4EPSS 0.3%
- CVE-2026-61784: xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML…mediumCVSS 6.1EPSS 0.2%
- CVE-2026-61782: Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report…highCVSS 7.5EPSS 0.4%
- CVE-2026-61742: DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose…criticalCVSS 4EPSS 0.2%
- CVE-2026-56744: `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and…highCVSS 4EPSS 0.3%
- CVE-2026-77394: OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems…highCVSS 7.6EPSS 0.4%
- CVE-2026-59167: SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the…criticalCVSS 10EPSS 0.4%
- CVE-2026-61685: ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build…highCVSS 7.5EPSS 0.5%
- CVE-2026-77426: Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization…highCVSS 4EPSS 0.5%
- CVE-2026-77425: Unleash is an open-source feature management platform. Prior to 8.0.3, POST…mediumCVSS 4.3EPSS 0.2%
- CVE-2026-76910: Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST…mediumCVSS 4EPSS 0.3%
- CVE-2026-76909: Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at…mediumCVSS 4EPSS 0.3%
- CVE-2026-62985: request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to…highCVSS 7.5EPSS 0.5%
- CVE-2026-56682: 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without…mediumCVSS 5.3EPSS 0.5%
- CVE-2026-75510: Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox…mediumCVSS 4EPSS 0.4%
- CVE-2026-56681: 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without…highCVSS 7.3EPSS 1.0%
- CVE-2026-61647: NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to…highCVSS 4EPSS 0.3%
- CVE-2026-58272: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-58270: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-58271: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0…mediumCVSS 6.8EPSS 0.2%
- CVE-2026-58269: Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0…highCVSS 8.1EPSS 0.2%
- CVE-2026-61612: CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard…mediumCVSS 5.7EPSS 0.2%
- CVE-2026-63116: deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From…highCVSS 8.8EPSS 0.5%
- CVE-2026-91127: File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web…highCVSS 8.2EPSS 0.4%
- CVE-2026-84992: md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()…mediumCVSS 6.1EPSS 0.3%
Most severe npm package vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2022-4135: Google Chrome heap buffer overflow in GPUcriticalexploited in the wildCVSS 3.1EPSS 31.9%
- CVE-2021-21315: System Information Library for Node.JS Command Injectioncriticalexploited in the wildCVSS 3.1
- CVE-2019-5786: Google Puppeteer use-after-free in Chromium FileReadercriticalexploited in the wildCVSS 3EPSS 62.3%
- CVE-2026-41679: paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization BypasscriticalCVSS 10EPSS 7.4%
- CVE-2026-47668: DbGate remote code execution in JSON script runnercriticalCVSS 10EPSS 3.9%
- CVE-2026-46339: decolua 9router unauthenticated RCE via MCP custom pluginscriticalCVSS 10EPSS 3.4%
- CVE-2025-71338: Flowise path traversal and arbitrary file write in document-store APIcriticalCVSS 10EPSS 1.2%
- CVE-2026-27597: agentfront @enclave-vm/core sandbox escape leading to RCEcriticalCVSS 10EPSS 1.0%
- CVE-2026-52887: NocoBase SQL injection in in-app notification channel filtercriticalCVSS 10EPSS 0.9%
- CVE-2026-47208: patriksimek vm2 sandbox breakout via Promise species hijackcriticalCVSS 10EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 46 | 2 | |
| 6 Jul 2026 | 45 | 4 | |
| 13 Jul 2026 | 64 | 13 | |
| 20 Jul 2026 | 91 | 8 | |
| 27 Jul 2026 | 44 | 2 | |
| 3 Aug 2026 | 57 | 14 | |
| 10 Aug 2026 | 36 | 1 | |
| 17 Aug 2026 | 56 | 15 | |
| 24 Aug 2026 | 16 | 1 | |
| 31 Aug 2026 | 58 | 5 | |
| 7 Sep 2026 | 15 | 2 | |
| 14 Sep 2026 | 55 | 7 | |
| 21 Sep 2026 | 23 | 2 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/npm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "npm package vulnerabilities", https://junglewise.ai/threats/vendors/npm, 26 September 2026.