Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Npmjs

First CVE: Jul 2, 2016Active for: 10 yearsTotal CVEs: 16
41.1
VTI Score
High

NPM's vulnerability profile centers on its package manager toolchain—the npm client, the tar extraction utility, the package dependency resolver (Arborist), and related Git integration libraries—which collectively form a critical node in the JavaScript supply chain. The recurring weakness classes cluster around file-system safety: path traversal, symlink-following, and improper pathname restrictions that arise when processing untrusted package archives and repository metadata, paired with information-disclosure flaws. A meaningful share of the vendor's disclosures reach serious severity, reflecting the consequences of archive-extraction and dependency-resolution flaws in build and deployment automation. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Npmjs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2016
10 years ago
Most Recent CVE
Jun 21, 2023
1,129 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-43616CRITICAL
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is in
Nov 13, 20219.833NONO
CVE-2021-37713HIGH
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to
Aug 31, 20218.628NONO
CVE-2021-37712HIGH
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to
Aug 31, 20218.628NONO
CVE-2021-37701HIGH
The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to
Aug 31, 20218.628NONO
CVE-2022-29244HIGH
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone
Jun 13, 20227.527NONO
CVE-2019-16776HIGH
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin
Dec 13, 20198.127NONO
CVE-2016-3956HIGH
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arb
Jul 2, 20167.527NONO
CVE-2021-39135HIGH
`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package de
Aug 31, 20217.826NONO
CVE-2021-39134HIGH
`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package
Aug 31, 20217.825NONO
CVE-2018-7408HIGH
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced
Feb 22, 20187.825NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
25%
69%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (43.8%)
Network9 (56.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None10 (62.5%)
Unknown0 (0.0%)
Required6 (37.5%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None11 (68.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Npmjs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Npmjs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Npmjs's Products

View all 3 CNAs →

Top CWEs