SecAlerts
n

npm

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 60 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 8, 2021 to present

60
Total CVEs
14
Critical+High
5
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
40/100
medium
⚠️ 5 Active Exploits🆕 2Fresh (<7d)📈 2 in Last 30 Days

Severity Distribution

Critical
1
High
13
Medium
6
Low
2

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
SSRF
3
2
Input Validation
2
3
XSS
2
4
Command Injection
1

Most Affected Products

1. npm package6
2. npm/brace-expansion4
3. juliangruber Brace-expansion Node.js4
4. npm registry4
5. npm eslint-config-prettier4

Recent Vulnerabilities

See more →
CVE-2026-71429
CVSS 6.2medium

stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)

Sep 3, 2026
CVE-2026-82417
CVSS 6.3medium

qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property

Aug 29, 2026
CVE-2026-69192
CVSS 7.7high

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

Aug 3, 2026
CVE-2026-14257
CVSS 7.5high

brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash

Jul 23, 2026
CVE-2026-13149
CVSS 7.7high
Jun 30, 2026
https://www.theregister.com/2025/12/22/whatsapp_npm_package_message_steal/
unknown

Poisoned WhatsApp API package steals messages and accounts

Dec 22, 2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/shai-hulud-20-npm-malware-attack-exposed-up-to-400-000-dev-secrets/
unknown

Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets

Dec 2, 2025🔧 No Patch
CVE-2025-13466
CVSS 5.5medium

body-parser vulnerable to denial of service when url encoding is used

Nov 24, 2025
https://www.bleepingcomputer.com/news/security/shai-hulud-malware-infects-500-npm-packages-leaks-secrets-on-github/
unknown

Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub

Nov 24, 2025🔧 No Patch
https://www.theregister.com/2025/11/24/shai_hulud_npm_worm/
unknown

Shai-Hulud worm returns, belches secrets to 25K GitHub repos

Nov 24, 2025🔧 No Patch

Monitor npm in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

npm Security Vulnerabilities & Risk Score | 60 CVEs | SecAlerts - SecAlerts