CVEs we hold for Npm
Records whose assigning authority named Npm as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-0775npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm cli
CVE-2021-37713Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitizationnpm node-tar
CVE-2021-37712Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic…npm node-tar
CVE-2021-37701Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic…npm node-tar
CVE-2021-32804Arbitrary File Creation/Overwrite due to insufficient absolute path sanitizationnpm node-tar
CVE-2021-32803Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoningnpm node-tar
31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.