CRITICAL9.8CVE-2021-43616The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json diffe…
from 0
HIGH7.7CVE-2019-16777npm Vulnerable to Global node_modules Binary Overwrite
from 0, < 6.13.4+ds-2
HIGH7.7CVE-2019-16776npm symlink reference outside of node_modules
from 0, < 6.13.4+ds-2
HIGH7.5npm Token Leak in npm
from 0, < 5.8.0+ds-2
HIGH7.0Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
from 0
—Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function.