VYPR
Vendor

Ljharb

Products
3
CVEs
6
Across products
6
Status
Private

Products

3

Recent CVEs

6
  • CVE-2022-0841CriMar 3, 2022
    risk 0.57cvss 9.8epss 0.03

    OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.

  • CVE-2026-102422HigSep 29, 2026
    risk 0.46cvss 8.1epss —

    shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the…

  • CVE-2026-82417MedAug 30, 2026
    risk 0.27cvss 5.3epss 0.00

    ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is…

  • CVE-2026-8723MedMay 17, 2026
    risk 0.27cvss 5.3epss 0.00

    ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`). …

  • CVE-2026-82562LowAug 30, 2026
    risk 0.17cvss 3.7epss 0.01

    ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`),…

  • CVE-2025-15284LowDec 29, 2025
    risk 0.17cvss 3.7epss 0.00

    Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug;…