npm Inc.

Security Scorecard

Score

100A

Total CVEs

7

Patch Rate

100%

7 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical1
High6
Medium0
Low0

Patch Status

Patched7 (100%)
Partial/Workaround0 (0%)
Unpatched0 (0%)

CVEs (8)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-0775npm cli Incorrect Permission Assignment Local Privilege Escalation VulnerabilityHigh7.0-Patched
CVE-2021-47837Markdownify XSSHigh7.2-Patched
CVE-2025-61686React Router VulnerabilityCritical9.1-Patched
CVE-2025-14874Nodemailer DoS VulnerabilityHigh7.5-Patched
CVE-2025-65512MCP Server VulnerabilityHigh7.5-Patched
CVE-2025-65513Fetch-MCP SSRFHigh7.5-Patched
CVE-2025-58754Axios DoS via data: URL decodeHigh7.5-Patched
CVE-2025-68154-N/A-2dUnpatched