{"source":"ghsa-npm","note":"Free 5-item preview. The full feed is $0.05/call at GET /v1/ghsa-npm/changes.","question":"Which new security vulnerabilities / CVEs affecting npm packages were published since T, and how severe (CVSS) are they?","sample":[{"source":"ghsa-npm","entityId":"ghsa:GHSA-xcpc-8h2w-3j85","type":"advisory","title":"GHSA-xcpc-8h2w-3j85 / CVE-2026-39244: adm-zip: Crafted ZIP file triggers 4GB memory allocation","summary":"HIGH severity. Affected: adm-zip.","significance":8,"detectedAt":"2026-07-18T23:42:07.968Z","effectiveDate":"2026-07-10T18:32:19Z","sourceUrl":"https://github.com/advisories/GHSA-xcpc-8h2w-3j85","detail":{"severity":"high","cve":"CVE-2026-39244","packages":"adm-zip","cvss":7.5}},{"source":"ghsa-npm","entityId":"ghsa:GHSA-vqrw-qphh-p34v","type":"advisory","title":"GHSA-vqrw-qphh-p34v / CVE-2026-54546: TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard","summary":"MEDIUM severity. Affected: @tak-ps/cloudtak.","significance":5,"detectedAt":"2026-07-18T23:42:07.968Z","effectiveDate":"2026-07-17T19:02:37Z","sourceUrl":"https://github.com/advisories/GHSA-vqrw-qphh-p34v","detail":{"severity":"medium","cve":"CVE-2026-54546","packages":"@tak-ps/cloudtak","cvss":5}},{"source":"ghsa-npm","entityId":"ghsa:GHSA-f7wf-v2vw-mpcx","type":"advisory","title":"GHSA-f7wf-v2vw-mpcx / CVE-2026-54561: mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath","summary":"MEDIUM severity. Affected: mcp-memory-keeper.","significance":6,"detectedAt":"2026-07-18T23:42:07.968Z","effectiveDate":"2026-07-17T19:23:07Z","sourceUrl":"https://github.com/advisories/GHSA-f7wf-v2vw-mpcx","detail":{"severity":"medium","cve":"CVE-2026-54561","packages":"mcp-memory-keeper","cvss":6.2}},{"source":"ghsa-npm","entityId":"ghsa:GHSA-wxhm-2mq7-7697","type":"advisory","title":"GHSA-wxhm-2mq7-7697 / CVE-2026-53598: Prompty: Arbitrary file read via file reference expansion","summary":"HIGH severity. Affected: prompty, @prompty/core, prompty, Prompty.Core.","significance":8,"detectedAt":"2026-07-18T23:42:07.968Z","effectiveDate":"2026-07-17T19:46:05Z","sourceUrl":"https://github.com/advisories/GHSA-wxhm-2mq7-7697","detail":{"severity":"high","cve":"CVE-2026-53598","packages":"prompty, @prompty/core, prompty, Prompty.Core","cvss":7.5}},{"source":"ghsa-npm","entityId":"ghsa:GHSA-c4gh-rv8h-q9vw","type":"advisory","title":"GHSA-c4gh-rv8h-q9vw / CVE-2026-53597: Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader","summary":"HIGH severity. Affected: @prompty/core.","significance":7,"detectedAt":"2026-07-18T23:42:07.968Z","effectiveDate":"2026-07-17T19:53:34Z","sourceUrl":"https://github.com/advisories/GHSA-c4gh-rv8h-q9vw","detail":{"severity":"high","cve":"CVE-2026-53597","packages":"@prompty/core","cvss":null}}]}