Articles tagged npm
-
Vulnerability@appium/base-driver Cross-Site Scripting (CVE-2026-58191)
CVE-2026-58191 lets an attacker execute arbitrary JavaScript on an Appium server via unauthenticated, unescaped test routes mounted on every server by default.
-
Vulnerabilitybrowserslist Denial of Service (CVE-2026-73089)
CVE-2026-73089 lets an attacker exhaust memory in any long-running process calling Browserslist by sending many distinct queries with no cache eviction, fixed in 4.28.7.
-
MalwareMini Shai-Hulud
Self-replicating supply-chain worm and credential stealer, per MITRE ATT&CK, derived from Shai-Hulud and used by TeamPCP to target CI/CD workflows since at least 2026 via stolen npm and GitHub OIDC tokens.
-
Vulnerabilitybrowserslist Prototype Pollution (CVE-2026-73088)
CVE-2026-73088 lets an untrusted browserslist-stats.json file crash or pollute the prototype of any Node.js process calling Browserslist, fixed in 4.28.7.