
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
@celestial-community/baileys is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Malicious Package
shortneer is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Cross-site Scripting (XSS)
org.webjars.npm:dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in _sanitizeElements and _sanitizeAttributes in src/purify.ts, which invoke _handleHookDetachedNode only after the beforeSanitizeElements and uponSanitizeElement hooks, so a non-root node removed by an afterSanitizeElements or afterSanitizeAttributes hook keeps its descendants' event handlers armed, and the post-walk neutralization pass covers only entries in DOMPurify.removed, which excludes hook-detached nodes. An attacker can execute script in the page origin under the victim's session by supplying markup with a non-root wrapper whose descendants carry on* handlers, such as an <img onerror>, so a queued resource event fires on the detached subtree after the synchronous sanitize() call has returned. This requires the application to call sanitize() with IN_PLACE: true on a live node and to register a node-removing afterSanitizeElements or afterSanitizeAttributes hook, so callers using the default returning mode or no such hooks are unaffected.
Note: This is a bypass of the fix for the vulnerability described in CVE-2026-75838.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




