Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-53950High· 7.5XSS in Ghost's ActivityPub client
XSS in Ghost's ActivityPub client
CVE-2026-53947Medium· 5.3Ghost: Member existence leak via magic link sign-in response
Ghost: Member existence leak via magic link sign-in response
CVE-2026-59817Medium· 5.3Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
CVE-2026-70588Medium· 5.0Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
CVE-2026-53948Medium· 5.4Ghost: File Upload Content-Type Spoofing
Ghost: File Upload Content-Type Spoofing
CVE-2026-70589Medium· 4.8Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
CVE-2026-53944Medium· 5.8Ghost: Private IP filtering bypass to make server-side requests to internal services
Ghost: Private IP filtering bypass to make server-side requests to internal services
CVE-2026-53945Medium· 4.0Ghost: Server-side request forgery via DNS rebinding in external request handling
Ghost: Server-side request forgery via DNS rebinding in external request handling
CVE-2026-53946Medium· 5.4Ghost: Mobiledoc image-size fetch SSRF
Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-70590Medium· 4.8Ghost is a Node.js content management system
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead…
CVE-2026-70591Medium· 4.1Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was re…
CVE-2026-70592Medium· 5.5Ghost is a Node.js content management system
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issu…
CVE-2026-70475Medium· 6.5Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware …
GHSA-8gj2-2cvc-6xx7MediumFlowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
CVE-2026-70476High· 8.2Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterp…
CVE-2026-70477Critical· 9.8Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypass…
CVE-2026-70478Critical· 10.0Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The …
CVE-2026-70471Medium· 6.5Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protecte…
GHSA-88pr-878c-24wfHighFlowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
CVE-2026-69264Critical· 9.8Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide
Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to gl…
CVE-2026-70472High· 8.8Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without …
CVE-2026-70473High· 8.5Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requestin…
GHSA-rwrp-9823-p2xqMedium· 6.5Flowise: Incomplete Credential Redaction Exposes Secrets via API
Flowise: Incomplete Credential Redaction Exposes Secrets via API
CVE-2026-70474High· 8.1Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The author…
CVE-2026-69262High· 8.1Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of e…
CVE-2026-69263Critical· 9.8PoCFlowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH…
CVE-2026-70470Critical· 9.8Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph iden…
CVE-2026-69255High· 8.8Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').po…
CVE-2026-69256High· 8.8Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Pytho…
CVE-2026-69257High· 8.6Flowise is a drag & drop user interface to build a customized large language model flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.…