Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Semver HIGH 7.5
CVE-2022-25883

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted…

Fix: 5.7.2 / 6.3.1+
Fix from $1,950 2023-06-21
Npm HIGH 7.5
CVE-2022-29244

npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`,…

Fix: 8.11.0+
Fix from $1,950 2022-06-13
Tar HIGH 8.6
CVE-2021-37713

The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution …

Fix: 1.0.1.1 / 4.4.18+
Fix from $1,950 2021-08-31
Arborist HIGH 7.8
CVE-2021-39134

`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, …

Fix: 1.0.1.1 / 2.8.2+
Fix from $1,950 2021-08-31
Arborist HIGH 7.8
CVE-2021-39135

`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, ai…

Fix: 1.0.1.1 / 2.8.2+
Fix from $1,950 2021-08-31
Hosted Git Info MEDIUM 5.3
CVE-2021-23362

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the f…

Fix: 1.0.1.1 / 2.8.9+
Fix from $1,600 2021-03-23
Npm User Validate HIGH 7.5
CVE-2020-7754

This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings…

Fix: 1.0.1+
Fix from $1,950 2020-10-27
Npm HIGH 7.8
CVE-2018-7408

An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g n…

Patch available
Fix from $1,950 2018-02-22