Security Risk Category

npm Security Risks — Page 2

Published vulnerability pages connected to npm. Each page keeps one canonical URL and focused remediation guidance.

44 published npm risks

npm risks

Showing 37–44 of 44 published risks.

low

body-parser Invalid Limit Denial of Service Vulnerability

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-parser 1.20.6 and 2.3.0. After the fix, invalid limit values throw a clear error at parser construction time instead of silently disabling enforcement, while null and undefined continue to fall back to the default limit of 100kb. Workarounds: Validate the limit value before passing it to body-parser. For example, parse the value at startup and reject any configuration where the result is null or a non-finite number.

CVE-2026-12590node-jsnpmdenial-of-service

Updated Jul 10, 2026

low

enquirer Public Package API Prototype Pollution Vulnerability

A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report.

CVE-2026-15187npmapi-securityremote-code-executioninput-validation

Updated Jul 9, 2026

high

n8n Workflow API Prototype Pollution Privilege Bypass Vulnerability

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via the workflow API, allowing unauthenticated requests to be treated as a privileged user and exposing user and project listing endpoints. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.

CVE-2026-59206npmapi-securityinput-validation

Updated Jul 9, 2026

high

n8n AI Agents Credential Domain Restriction Bypass Vulnerability

n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external server they control. This issue is fixed in versions 2.27.4 and 2.28.1.

CVE-2026-59207npm

Updated Jul 9, 2026

high

n8n Token Exchange Issuer Authentication Bypass Vulnerability

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1.

CVE-2026-59208npmauthentication-bypass

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.023

TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

CVE-2026-45321npm

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.018

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

CVE-2025-48700npmxssinformation-disclosure

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.056

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

CVE-2026-42897npmbrowsermicrosoftxss

Updated Jul 9, 2026