A patch-week for the dependency chain
Vite dev servers are being mass-scanned for exposed `.env` files, Express and Moment.js shipped CVE fixes, Next.js patched a critical RCE — while npm rolled out account-level holds and stage-only tokens for safer publishing.
It was a week to run your updates. The clearest signal in the cut: attackers are now mass-scanning for exposed Vite development servers, because the endpoints can leak .env files straight into the open — patch to Vite 7.3.2 or 8.0.5, and in the meantime never let a dev server listen on a public interface.
Beyond Vite, the Node ecosystem shipped a coordinated wave of dependency fixes. Express 4.22.3 updates path-to-regexp to close CVE-2026-4867. Moment.js disclosed a path-traversal advisory: server-side users before 2.31.0 can be exposed when attacker-controlled non-string input reaches moment.locale(), so update or validate that the input is a string. Next.js pushed a critical security update fixing an RCE in next/og's ImageResponse for v16.2+. And Datasette shipped 1.0a39 and 0.65.4 to close its own reported issues.
The defenses are maturing too. npm extended recovery-code security holds to all accounts, and its new stage-only tokens let automation stage a release for a human maintainer to approve with 2FA — a safer path for projects not yet on trusted publishing. The Node Release WG, meanwhile, says npm 12's hardening (blocked install scripts, publish-time scans, cooldowns) is too disruptive for Node 22/24/26 and is targeting Node 27 instead. The trend across all of it: assume your dependency graph is attackable, and put friction where the blast radius is largest.