npm package report

Is node-cube safe?

1 known vulnerability, worst severity LOW.

cvss
6.5

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
1.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-8v65-5fw5-23wj, the advisory selected below

// advisories

GHSA-8v65-5fw5-23wj

LOWCVE-2025-57348

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties into the prototype of built-in objects. This issue, categorized under CWE-1321, arises from improper validation of user-supplied input in the package's resource initialization process. Successful exploitation may lead to denia

Affected
<= 5.0.0-beta.19
Fixed in
not stated
Weakness
CWE-1321
Published
2025-09-24
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:31 UTC. The most recent advisory here was published 2025-09-24. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is node-cube safe? npm package security report | CyberXYZ