IndexedVerified
Node.js Security
Node.js, Express, and Electron SAST rules aggregated across verified providers.
Fetch pack
greprules pack fetch nodejs-security --engine opengrepcurl https://api.greprules.io/api/packs/nodejs-security.tar.gz -o nodejs-security.tar.gzIncluded rules
CVE-2026-49357: Insecure Hardcoded Bind To All Interfaces
cve-2026-49357-insecure-hardcoded-bind-to-all-interfacesCVE-2026-47140: Node Module Denylist Bypasscve-2026-47140-node-module-denylist-bypassCVE-2026-47139: Bypass Node Internal Modules Filtercve-2026-47139-bypass-node-internal-modules-filterCVE-2026-44695: Archive Manifest Path Traversalcve-2026-44695-archive-manifest-path-traversalCVE-2026-44313: Ssrf Scheme Only Url Guard Before Server Fetchcve-2026-44313-ssrf-scheme-only-url-guard-before-server-fetchCVE-2026-43940: Ai Schema Authtype Missing Profile Constraintcve-2026-43940-ai-schema-authtype-missing-profile-constraintCVE-2026-41885: Custom Regex Interpolation Unvalidatedcve-2026-41885-custom-regex-interpolation-unvalidatedCVE-2026-41500: Command Injection Exec Unsanitized Jsoncve-2026-41500-command-injection-exec-unsanitized-jsonCVE-2026-41242: Protobufjs Type Constructor Unsanitized Name Code Injectioncve-2026-41242-protobufjs-type-constructor-unsanitized-name-code-injectionCVE-2026-41167: Js Node Postgres Template Literal Sql Injectioncve-2026-41167-js-node-postgres-template-literal-sql-injectionCVE-2026-40073: Unvalidated Content Length Limit Bypasscve-2026-40073-unvalidated-content-length-limit-bypassCVE-2026-33994: Js Prototype Pollution Regex Test Guardcve-2026-33994-js-prototype-pollution-regex-test-guardCVE-2026-33979: Sanitizer Config Ignored Empty Arraycve-2026-33979-sanitizer-config-ignored-empty-arrayCVE-2026-33890: Ts Admin Auth Gated On Loginrequired Config Flagcve-2026-33890-ts-admin-auth-gated-on-loginrequired-config-flagCVE-2026-33877: Password Reset Timing Side Channel User Enumerationcve-2026-33877-password-reset-timing-side-channel-user-enumerationCVE-2026-32774: Mongoose Unsanitized Html Stored Xsscve-2026-32774-mongoose-unsanitized-html-stored-xssCVE-2026-32304: Js Function Constructor Non Literal Bodycve-2026-32304-js-function-constructor-non-literal-bodyCVE-2026-32094: Shescape Missing Bracket Glob Escapecve-2026-32094-shescape-missing-bracket-glob-escapeCVE-2026-31975: Shell Command Injection Via Cd Template Literalcve-2026-31975-shell-command-injection-via-cd-template-literalCVE-2026-28360: Generic Idor Presigned Urlcve-2026-28360-generic-idor-presigned-urlCVE-2026-27971: Js Require Dynamic Module And Symbol From Inputcve-2026-27971-js-require-dynamic-module-and-symbol-from-inputCVE-2026-26974: Fast Glob Unanchored Recursive Glob Rcecve-2026-26974-fast-glob-unanchored-recursive-glob-rceCVE-2026-26833: Nodejs Child Process Exec String Concatcve-2026-26833-nodejs-child-process-exec-string-concatCVE-2026-26831: Textract Cve 2026 26831 Shell Injection Incomplete Path Escapecve-2026-26831-textract-cve-2026-26831-shell-injection-incomplete-path-escape24 of 67 loaded