Index › programming › npm npm 2 tools · 1 release line Node package manager. Every tool here carries the same sandbox boundary. $ boks npm ⧉ $ boks npx ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 12.0.2 stable 2026-08-19 9 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ npm netrw default H3M6 npm Package manager for JavaScript and Node.js ▸ npx netrw default H3M6 npm Execute npm package binaries ▸ showing npm npx from npm@latest → 12.0.2 stable Findings H3M6 identical on arm64, amd64 — one table describes both CVE Sev CVSS Affects Description GHSA-mwp4-54f8-5fhr ↗ H 7.7 ip-address ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mh99-v99m-4gvg ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-rgw5-rvv9-x895 ↗ H 7.5 brace-expansion brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-22jq-vg5j-6vgg ↗ M 6.9 ip-address ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh ↗ M 6.9 ip-address ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-r292-9mhp-454m ↗ M 5.3 tar node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection GHSA-8xcm-r25x-g524 ↗ M 4.8 undici undici vulnerable to downstream response desynchronization via retry interceptor GHSA-v3r7-h72x-cjcm ↗ M 4.8 undici undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-m8rv-5g2x-5cg5 ↗ M 4.2 undici undici vulnerable to CRLF Injection via blob-like body 'type' property These are the findings of npm, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding. Composition default + bash, env runtime node composes bash, env, node Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default + bash, env runtime node composes bash, env, node Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/boks-sh/npm:12.0.2 digest sha256:f2ff…8039 copy platforms arm64 sha256:0913…8d1e copy amd64 sha256:0075…42fa copy size 14 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-19 Sandbox boundary npm capabilities netrw Filled is granted by default; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 0 of 1 Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Sandbox boundary npx capabilities netrw Filled is granted by default; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 0 of 1 Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Provenance sbom arm64 ↗ amd64 ↗ attestation arm64 ↗ amd64 ↗ scan report arm64 ↗ amd64 ↗ grype · 2026-08-19 vex arm64 ↗ amd64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 9 findings across this project at latest. Counted once per advisory across every image the project builds.