Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
GHSA-7rqj-j65f-68whCriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-xmf8-cvqr-rfgjHigh· 7.5Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
GHSA-8fpg-xm3f-6cx3CriticalAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
CVE-2026-64648MediumNext.js: Cache confusion of response bodies for requests with bodies
Next.js: Cache confusion of response bodies for requests with bodies
CVE-2026-64649HighNext.js: Server-Side Request Forgery in Server Actions on custom servers
Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-9cmh-xcqm-5hqrMediumn8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
GHSA-jqwr-vx3p-r266Mediumn8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
GHSA-652q-gvq3-74qvMediumn8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-fmvg-vhqq-r2mjMediumDuplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
GHSA-5vfw-jc4p-fj39MediumDuplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
GHSA-h9fm-xcv2-qfw3MediumDuplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
GHSA-4v35-78jc-648rMediumDuplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows
Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows
GHSA-88c4-pcqm-3r9pMediumDuplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
GHSA-gf29-4f56-r2jfHighn8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-vhf8-cg2h-cg3pMediumn8n: SSRF Protection Bypass via MCP Client Node
n8n: SSRF Protection Bypass via MCP Client Node
GHSA-rcv6-pvrj-4xcgHighn8n: Authenticated code execution in the n8n Git node
n8n: Authenticated code execution in the n8n Git node
GHSA-2x35-3fw4-9jr4Highn8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-gv7g-jm28-cr3mHighn8n: Expression sandbox escape via arrow-function bodies enabling command execution
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GHSA-6qc9-mqvw-jg7xHighn8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-cj9h-qx8g-pq2gHighn8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
GHSA-xmc9-4f2h-jf9cHighn8n: Edit Image Node Format Injection Allows Arbitrary File Write
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GHSA-xwx6-jjhv-84p8Highn8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GHSA-hx4h-vr3m-45vhMediumn8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
GHSA-pf2q-pxhf-hgmwMediumn8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
CVE-2026-59259Mediumn8n: External Secrets Permission Bypass via Expression Parser Mismatch
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
CVE-2026-59257Mediumn8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
CVE-2026-59254Mediumn8n: External Secrets Accessible via Workflow Expressions Outside Credentials
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
CVE-2026-59253Mediumn8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
CVE-2026-58661Mediumn8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
CVE-2026-65590Mediumn8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows