Home/Product/npmjs npm
Product

npmjs npm

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-29244
>= 7.9.0 and < 8.11.0
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (
7.5HIGH
CVE-2021-43616
>= 7.0.0 and <= 7.24.2
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.j
9.0CRITICAL
CVE-2021-26700
< 0.3.15
Visual Studio Code npm-script Extension Remote Code Execution Vulnerability
7.8HIGH
CVE-2020-7754
< 1.0.1
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process
7.5HIGH
CVE-2020-15095
< 6.14.6
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI support
4.4MEDIUM
CVE-2019-16777
< 6.13.4
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-insta
7.7HIGH
CVE-2019-16776
< 6.13.3
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside o
7.7HIGH
CVE-2019-16775
< 6.13.3
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks
7.7HIGH
CVE-2018-7408
all versions
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by a
7.8HIGH
CVE-2016-3956
< 2.15.1
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, an
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin