Native Node.js bindings for liblzma (XZ/LZMA2). Streaming, buffer and async APIs with browser support via WebAssembly. zlib-like API, TypeScript-first, prebuilt binaries for Linux/macOS/Windows.
93%
Total Score
67
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10783 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. node-liblzma is vulnerable to Denial of Service in versions 3.0.0 - 5.0.0. | 3.0.0 - 5.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
node-addon-api Version ^8.6.0 | — | — |
node-gyp-build Version ^4.8.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant