Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: nodejs Clear
ID Title
CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
CVE-2026-58043 Vulnerability in nodejs (CVE-2026-58043)
vulnerability in nodejs (CVE-2026-58043). Confidential information can be exposed externally.
CVE-2026-56847 Vulnerability in nodejs (CVE-2026-56847)
vulnerability in nodejs (CVE-2026-56847). Confidential information can be exposed externally.
CVE-2026-56850 Authentication Bypass in nodejs (CVE-2026-56850)
authentication bypass in nodejs (CVE-2026-56850). Data can be tampered with by attackers.
CVE-2026-15157 Vulnerability in undici (CVE-2026-15157)
vulnerability in undici (CVE-2026-15157). Risk of unauthorized operations or information disclosure. Exploitable via ``body.type``. Mitigation: upgrade to `6.24.0` or later.
CVE-2026-14643 Vulnerability in undici (CVE-2026-14643)
vulnerability in undici (CVE-2026-14643). Confidential information can be exposed externally. Exploitable via ``private``. Mitigation: upgrade to `8.9.0` or later.
CVE-2026-16728 Vulnerability in undici (CVE-2026-16728)
vulnerability in undici (CVE-2026-16728). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.9.0` or later.
CVE-2026-16729 Vulnerability in undici (CVE-2026-16729)
vulnerability in undici (CVE-2026-16729). Risk of unauthorized operations or information disclosure. Exploitable via ``setCookie``. Mitigation: upgrade to `8.9.0` or later.
CVE-2026-13697 Information Disclosure in undici (CVE-2026-13697)
vulnerability in undici (CVE-2026-13697). Confidential information can be exposed externally. Exploitable via ``private``. Mitigation: upgrade to `8.9.0` or later.
CVE-2026-15074 @fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
CVE-2026-16158 Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
CVE-2026-48934 Vulnerability in node (CVE-2026-48934)
vulnerability in node (CVE-2026-48934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48935 Vulnerability in node (CVE-2026-48935)
vulnerability in node (CVE-2026-48935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48936 Vulnerability in node (CVE-2026-48936)
vulnerability in node (CVE-2026-48936). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.3.1` or later.
CVE-2026-48619 Vulnerability in node (CVE-2026-48619)
vulnerability in node (CVE-2026-48619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48933 Vulnerability in nodejs (CVE-2026-48933)
vulnerability in nodejs (CVE-2026-48933). Risk of unauthorized operations or information disclosure.
CVE-2026-48615 Vulnerability in node (CVE-2026-48615)
vulnerability in node (CVE-2026-48615). Confidential information can be exposed externally. Exploitable via ``ERR_PROXY_TUNNEL``. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48930 Vulnerability in node (CVE-2026-48930)
vulnerability in node (CVE-2026-48930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48928 Vulnerability in node (CVE-2026-48928)
vulnerability in node (CVE-2026-48928). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48618 Vulnerability in nodejs (CVE-2026-48618)
vulnerability in nodejs (CVE-2026-48618). Confidential information can be exposed externally.
CVE-2026-54639 Style Dictionary - Prototype Pollution in convertTokenData utility function
Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-48931 Vulnerability in node (CVE-2026-48931)
vulnerability in node (CVE-2026-48931). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48937 Vulnerability in nodejs (CVE-2026-48937)
vulnerability in nodejs (CVE-2026-48937). Risk of unauthorized operations or information disclosure. Exploitable via ``GOAWAY``.
CVE-2026-48617 Vulnerability in nodejs (CVE-2026-48617)
vulnerability in nodejs (CVE-2026-48617). Confidential information can be exposed externally.
CVE-2026-9697 Vulnerability in undici (CVE-2026-9697)
vulnerability in undici (CVE-2026-9697). Confidential information can be exposed externally. Exploitable via ``ProxyAgent``. Mitigation: upgrade to `8.5.0` or later.
CVE-2026-9679 Vulnerability in undici (CVE-2026-9679)
vulnerability in undici (CVE-2026-9679). Data can be tampered with by attackers. Exploitable via ``parseSetCookie``. Mitigation: upgrade to `8.5.0` or later.
CVE-2026-9678 Vulnerability in undici (CVE-2026-9678)
vulnerability in undici (CVE-2026-9678). Confidential information can be exposed externally. Exploitable via ``private``. Mitigation: upgrade to `8.5.0` or later.
CVE-2026-6733 Vulnerability in undici (CVE-2026-6733)
vulnerability in undici (CVE-2026-6733). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5.0` or later.
CVE-2026-6734 Vulnerability in undici (CVE-2026-6734)
vulnerability in undici (CVE-2026-6734). Successful exploitation can lead to full system takeover. Exploitable via ``Socks5ProxyAgent``. Mitigation: upgrade to `8.2.0` or later.
CVE-2026-11525 Vulnerability in undici (CVE-2026-11525)
vulnerability in undici (CVE-2026-11525). Risk of unauthorized operations or information disclosure. Exploitable via ``SameSite``. Mitigation: upgrade to `8.5.0` or later.
CVE-2026-9675 Vulnerability in undici (CVE-2026-9675)
vulnerability in undici (CVE-2026-9675). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
CVE-2026-12151 Vulnerability in undici (CVE-2026-12151)
vulnerability in undici (CVE-2026-12151). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
CVE-2026-53864 OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
CVE-2026-44313 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44313)
SSRF in ssrf (CVE-2026-44313). Confidential information can be exposed externally. Exploitable via `GET /api/v1/archives/{linkId}`.
CVE-2026-41512 Code Injection in gem (CVE-2026-41512)
code injection in gem (CVE-2026-41512). Successful exploitation can lead to full system takeover. Exploitable via `POST /targets/auto_detect_selectors`.
CVE-2026-43944 Vulnerability in electerm (CVE-2026-43944)
vulnerability in electerm (CVE-2026-43944). Successful exploitation can lead to full system takeover. Exploitable via ``opts``. Mitigation: upgrade to `> 3.8.8` or later.
CVE-2025-63706 Code Injection in npm (CVE-2025-63706)
code injection in npm (CVE-2025-63706). Successful exploitation can lead to full system takeover.
CVE-2026-26956 Vulnerability in vm2-project (CVE-2026-26956)
vulnerability in vm2-project (CVE-2026-26956). Successful exploitation can lead to full system takeover. Exploitable via ``catch``.
CVE-2026-24118 Code Injection in vm2-project (CVE-2026-24118)
code injection in vm2-project (CVE-2026-24118). Successful exploitation can lead to full system takeover. Exploitable via ``__lookupGetter__``.
CVE-2026-24120 Code Injection in vm2-project (CVE-2026-24120)
code injection in vm2-project (CVE-2026-24120). Successful exploitation can lead to full system takeover. Exploitable via ``resetPromiseSpecies``.
CVE-2026-24781 Code Injection in vm2-project (CVE-2026-24781)
code injection in vm2-project (CVE-2026-24781). Successful exploitation can lead to full system takeover. Exploitable via ``inspect``.
CVE-2026-21710 Vulnerability in node (CVE-2026-21710)
vulnerability in node (CVE-2026-21710). Risk of unauthorized operations or information disclosure. Exploitable via ``TypeError``. Mitigation: upgrade to `20.20.2, 22.22.2, 24.14.1, 25.8.2` or later.
CVE-2026-21717 Vulnerability in nodejs (CVE-2026-21717)
vulnerability in nodejs (CVE-2026-21717). Risk of unauthorized operations or information disclosure.
CVE-2026-21716 Vulnerability in nodejs (CVE-2026-21716)
vulnerability in nodejs (CVE-2026-21716). Risk of unauthorized operations or information disclosure. Exploitable via ``FileHandle``.
CVE-2026-21715 Vulnerability in nodejs (CVE-2026-21715)
vulnerability in nodejs (CVE-2026-21715). Risk of unauthorized operations or information disclosure.
CVE-2026-21714 Vulnerability in nodejs (CVE-2026-21714)
vulnerability in nodejs (CVE-2026-21714). Risk of unauthorized operations or information disclosure.
CVE-2026-21711 Vulnerability in nodejs (CVE-2026-21711)
vulnerability in nodejs (CVE-2026-21711). Risk of unauthorized operations or information disclosure.
CVE-2026-21713 Vulnerability in nodejs (CVE-2026-21713)
vulnerability in nodejs (CVE-2026-21713). Confidential information can be exposed externally.
CVE-2026-21712 Vulnerability in nodejs (CVE-2026-21712)
vulnerability in nodejs (CVE-2026-21712). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →