WhisperX tag archive

#npm

This page collects WhisperX intelligence signals tagged #npm. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (20)

The Lab · 2026-03-25 09:27:15 · GitHub Issues

1. Security Alert: `flatted` <=3.4.1 Exposes High-Severity DoS & Prototype Pollution Vulnerabilities

A critical security report reveals two high-severity vulnerabilities in the widely used `flatted` npm package, versions 3.4.1 and below. The flaws expose countless development projects to potential Denial of Service (DoS) attacks and prototype pollution, posing a direct risk to application stability and security. The ...

The Lab · 2026-03-25 10:27:13 · GitHub Issues

2. GitHub Security Alert: High/Critical Vulnerabilities Detected in Automated Trivy Scan

A GitHub repository's automated security scan has flagged high or critical vulnerabilities, triggering a formal security alert. The scan, conducted by the Trivy tool, specifically identified a security flaw within the project's `package-lock.json` file, a critical dependency manifest for Node.js applications. This auto...

The Lab · 2026-03-25 16:27:19 · GitHub Issues

3. Valibot v1.2.0 Patches Critical ReDoS Vulnerability in Emoji Regex (CVE-2025-66020)

A critical security vulnerability in the popular TypeScript-first schema validation library, Valibot, has been patched in its latest release. The flaw, tracked as CVE-2025-66020, resides in the `emoji` action's `EMOJI_REGEX`. This regular expression is vulnerable to a Regular Expression Denial of Service (ReDoS) attack...

The Lab · 2026-03-25 22:27:22 · GitHub Issues

4. Critical Security Patch: picomatch v4.0.4 Fixes High-Severity Vulnerability (CVE-2026-33672)

A critical security vulnerability, tracked as CVE-2026-33672, has been disclosed in the widely used `picomatch` library, prompting an urgent patch to version 4.0.4. The flaw, detailed in a GitHub Security Advisory, represents a high-severity risk that could be exploited in applications relying on the library for glob p...

The Lab · 2026-03-26 01:27:31 · GitHub Issues

5. Security Alert: 'flatted' Dependency Requires Urgent Upgrade to 3.4.2 to Mitigate Prototype Pollution Risk

A critical security vulnerability has been flagged within the widely-used `flatted` npm package, necessitating an immediate upgrade to version 3.4.2. The issue centers on a potential prototype pollution flaw in older versions, a class of vulnerability that can allow attackers to modify an application's object prototype...

The Lab · 2026-03-26 02:27:06 · GitHub Issues

6. Commitizen 4.3.1 Package Exposes Multiple Projects to 8 Vulnerabilities, Including High-Severity Flaw

A critical security alert has been triggered for the widely used `commitizen` tool, version 4.3.1. The npm package, a staple for standardizing commit messages, contains eight distinct vulnerabilities, with the highest severity rated at 7.5. This exposes any project relying on this specific version to potential exploita...

The Lab · 2026-03-26 04:27:03 · GitHub Issues

8. Security Alert: High/Critical Vulnerability Detected in 'develop' Branch Package-lock.json

An automated security scan has flagged a high or critical-severity vulnerability within the `develop` branch of the `trivy-actions-with-issue-creation` repository. The scan, triggered by user @veenoise, specifically identified the issue within the `package-lock.json` file, a core dependency manifest for Node.js project...

The Lab · 2026-03-26 05:27:02 · GitHub Issues

9. YAML 2.8.3 Security Update Patches Critical Stack Overflow Vulnerability (CVE-2026-33532)

A critical security vulnerability in the widely-used `yaml` npm package has been patched, exposing countless Node.js applications to denial-of-service attacks. The flaw, tracked as CVE-2026-33532, allows an attacker to crash a process by supplying a maliciously crafted YAML document. The issue stems from a recursive fu...

The Lab · 2026-03-26 06:27:05 · GitHub Issues

10. Critical YAML Parser Vulnerability (CVE-2026-33532) Exposes Projects to Stack Overflow Attacks

A critical security flaw in the widely-used `yaml` npm package, tracked as CVE-2026-33532, exposes countless software projects to denial-of-service attacks. The vulnerability, a stack overflow in the parser's composition phase, allows an attacker to crash a Node.js application by feeding it a maliciously crafted YAML d...

The Lab · 2026-03-26 08:27:07 · GitHub Issues

11. Order-Service Exposed: 6 Critical npm Vulnerabilities Open Door to DoS, File Overwrite, and Data Breach

An automated security audit has exposed six high and critical vulnerabilities in the order-service, creating a direct path for denial-of-service attacks, arbitrary file overwrites, and potential data breaches. The findings, flagged by npm audit, reveal a dangerously outdated dependency chain that could allow attackers ...

The Lab · 2026-03-26 14:27:38 · GitHub Issues

12. Security Alert: High-Severity RCE Vulnerability in serialize-javascript Build Dependency

A high-severity Remote Code Execution (RCE) vulnerability has been identified in the `serialize-javascript` package, a transitive dependency for projects using `copy-webpack-plugin`. The vulnerability, tracked as GHSA-5c6j-r48x-rmvq, affects `serialize-javascript` versions 7.0.2 and earlier. While classified as a build...

The Lab · 2026-03-26 19:27:38 · GitHub Issues

13. Security Alert: High-Severity ReDoS Vulnerability in picomatch Library (GHSA-c2c7-rcm5-vvqj)

A high-severity security vulnerability has been identified in the widely used `picomatch` library, posing a direct risk of Regular Expression Denial of Service (ReDoS) attacks. The flaw, tracked as GHSA-c2c7-rcm5-vvqj and rated with a CVSS score of 7.5, resides in versions below 2.3.2. An attacker can exploit this weak...

The Lab · 2026-03-26 22:27:17 · GitHub Issues

14. YAML Parser Vulnerability CVE-2026-33532: Stack Overflow Risk in `yaml` Dependency Update

A critical security flaw in the widely used `yaml` JavaScript library exposes countless projects to denial-of-service attacks. The vulnerability, tracked as CVE-2026-33532, stems from an unbounded recursion flaw during document parsing. An attacker can craft a malicious YAML payload as small as 2–10 KB to trigger a sta...

The Lab · 2026-03-26 22:27:30 · GitHub Issues

15. Critical DoS Flaw in node-forge 1.3.1 Prompts Urgent Update to 1.4.0

A high-severity Denial of Service (DoS) vulnerability in the widely used `node-forge` cryptography library has triggered an urgent update. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function inherited from the bundled jsbn library. When called with a zero value as input, the function'...

The Lab · 2026-03-26 23:27:29 · GitHub Issues

16. Critical Node-Forge Flaw (CVE-2025-12816): ASN.1 Bug Threatens Cryptographic Verification Bypass

A critical security vulnerability in the widely-used `node-forge` cryptography library has been patched, exposing a high-risk path for attackers to bypass downstream cryptographic verifications. The flaw, tracked as CVE-2025-12816 and rated HIGH severity, is an Interpretation Conflict (CWE-436) that exists in versions ...

The Lab · 2026-03-26 23:27:30 · GitHub Issues

17. Node-Forge 1.4.0 Patches Critical DoS Flaw (CVE-2026-33891) in `BigInteger.modInverse()`

A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function. When this function is called with a zero value as input, the internal Extended Euclidean...

The Lab · 2026-03-26 23:27:36 · GitHub Issues

18. Node-Forge 1.4.0 Patches Critical DoS Flaw in `BigInteger.modInverse()` (CVE-2026-33891)

A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...

The Lab · 2026-03-27 00:27:16 · GitHub Issues

19. axios-0.21.4.tgz 发现 6 个可被利用漏洞,最高严重性达 7.5

在 DimaMend/V-Achilles 项目的代码库中,一个广泛使用的 HTTP 客户端库 axios 的过时版本被标记为存在严重安全风险。自动化安全扫描在提交 `11d21c5fccd238699f5c2bd3370cb76b77ce750a` 中检测到 `axios-0.21.4.tgz` 包含六个已知漏洞,其中最高严重性评分为 7.5(CVSS 评分)。关键点在于,这些漏洞被标记为“可被利用”,意味着攻击路径在项目的 `/baak-dataload-sql/package.json` 和 `/achilles-frontend/package.json` 依赖文件中是可达的,显著增加了实际被攻击的风险。 该漏洞影响的是一...

The Lab · 2026-03-27 00:27:21 · GitHub Issues

20. Critical 9.3 CVSS Vulnerability in workbox-webpack-plugin 6.5.3 Exposes DimaMend/V-Achilles Repository

A critical security flaw has been identified within the DimaMend/V-Achilles GitHub repository, stemming from a vulnerable dependency. The `workbox-webpack-plugin-6.5.3.tgz` library, used in both the `achilles-frontend` and `baak-vizualization` projects, contains 18 distinct vulnerabilities. The most severe of these car...