npm
5,579 CVEs tracked since 2010. Since Sep 2021, 8 of them reached CISA KEV.
npm CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 47 | 0 |
| 2021-10 | 24 | 0 |
| 2021-11 | 44 | 0 |
| 2021-12 | 26 | 0 |
| 2022-01 | 41 | 0 |
| 2022-02 | 30 | 0 |
| 2022-03 | 48 | 0 |
| 2022-04 | 29 | 0 |
| 2022-05 | 44 | 0 |
| 2022-06 | 55 | 0 |
| 2022-07 | 49 | 0 |
| 2022-08 | 53 | 0 |
| 2022-09 | 43 | 0 |
| 2022-10 | 33 | 0 |
| 2022-11 | 35 | 1 |
| 2022-12 | 48 | 0 |
| 2023-01 | 47 | 0 |
| 2023-02 | 45 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 37 | 0 |
| 2023-05 | 27 | 0 |
| 2023-06 | 30 | 0 |
| 2023-07 | 28 | 0 |
| 2023-08 | 36 | 0 |
| 2023-09 | 29 | 2 |
| 2023-10 | 27 | 0 |
| 2023-11 | 23 | 0 |
| 2023-12 | 37 | 0 |
| 2024-01 | 33 | 0 |
| 2024-02 | 29 | 0 |
| 2024-03 | 43 | 0 |
| 2024-04 | 32 | 0 |
| 2024-05 | 40 | 0 |
| 2024-06 | 33 | 0 |
| 2024-07 | 47 | 0 |
| 2024-08 | 32 | 0 |
| 2024-09 | 47 | 0 |
| 2024-10 | 53 | 0 |
| 2024-11 | 22 | 0 |
| 2024-12 | 22 | 0 |
| 2025-01 | 23 | 0 |
| 2025-02 | 47 | 0 |
| 2025-03 | 52 | 1 |
| 2025-04 | 47 | 0 |
| 2025-05 | 32 | 0 |
| 2025-06 | 34 | 0 |
| 2025-07 | 59 | 1 |
| 2025-08 | 51 | 0 |
| 2025-09 | 100 | 0 |
| 2025-10 | 55 | 0 |
| 2025-11 | 57 | 1 |
| 2025-12 | 75 | 2 |
| 2026-01 | 142 | 0 |
| 2026-02 | 227 | 0 |
| 2026-03 | 562 | 0 |
| 2026-04 | 309 | 0 |
| 2026-05 | 86 | 0 |
| 2026-06 | 89 | 0 |
| 2026-07 | 158 | 0 |
| 2026-08 | 33 | 0 |
| 2026-09 | 20 | 0 |
Products
The products that kept showing up in npm's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting npm.
- GHSA-29h2-jr22-frmhOpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract private data from the vesting wallet—
- GHSA-5648-rgj9-v224@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS—
- GHSA-x7m8-jrm8-hpvx@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name—
- GHSA-wmmp-3585-3rmpNodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain—
- GHSA-2x7j-588g-ccc2Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list—
- GHSA-cc9r-2j5m-2m83Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain—
- GHSA-2q42-4q24-7rgvOpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree—
- GHSA-26w7-cxv4-gfx2Astro: Remote code execution through AVIF image optimization—
- GHSA-rgj7-g3m4-5g8csharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545—
- GHSA-j95f-988m-3j2fTiptap: Quadratic ReDoS in block and inline Markdown attribute parsing—
- GHSA-2xp9-vwfh-vxw4Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used—
- GHSA-8m3c-c648-2xjjNodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature—
- GHSA-7q9c-hpx7-9cwmTypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop—
- GHSA-6hxq-p678-4hr2SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor—
- GHSA-w8wf-3qvj-6xqfOpenClaw Feishu permission tools could ignore per-account disablement—
The record
- Peak rank
- #1 in Mar 2026
- Busiest month shown
- Mar 2026, 562 CVEs
- Months with a KEV entry
- 6 since Sep 2021
- Monthly snapshots
- 124 since 2010