VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

GHSA-7rqj-j65f-68whCritical
2mo ago

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

▾ Midnightauth · @auth/corevia GHSA
GHSA-xmf8-cvqr-rfgjHigh· 7.5
2mo ago

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

▾ Twilightauth · @auth/corevia GHSA
GHSA-8fpg-xm3f-6cx3Critical
2mo ago

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

▾ Midnightnext-auth · next-authvia GHSA
CVE-2026-64648Medium
2mo ago

Next.js: Cache confusion of response bodies for requests with bodies

Next.js: Cache confusion of response bodies for requests with bodies

▾ Sunlitnext · nextEPSS 0.34%via GHSA
CVE-2026-64649High
2mo ago

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Next.js: Server-Side Request Forgery in Server Actions on custom servers

▾ Twilightnext · nextEPSS 0.46%via GHSA
GHSA-9cmh-xcqm-5hqrMedium
2mo ago

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

▾ Sunlitn8n · n8nvia GHSA
GHSA-jqwr-vx3p-r266Medium
2mo ago

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

▾ Sunlitn8n · n8nvia GHSA
GHSA-652q-gvq3-74qvMedium
2mo ago

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

▾ Sunlitn8n · n8nvia GHSA
GHSA-fmvg-vhqq-r2mjMedium
2mo ago

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

▾ Sunlitn8n · n8nvia GHSA
GHSA-5vfw-jc4p-fj39Medium
2mo ago

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

▾ Sunlitn8n · n8nvia GHSA
GHSA-h9fm-xcv2-qfw3Medium
2mo ago

Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

▾ Sunlitn8n · n8nvia GHSA
GHSA-4v35-78jc-648rMedium
2mo ago

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

▾ Sunlitn8n · @n8n/computer-usevia GHSA
GHSA-88c4-pcqm-3r9pMedium
2mo ago

Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction

▾ Sunlitn8n · n8nvia GHSA
GHSA-gf29-4f56-r2jfHigh
2mo ago

n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

▾ Twilightn8n · n8nvia GHSA
GHSA-vhf8-cg2h-cg3pMedium
2mo ago

n8n: SSRF Protection Bypass via MCP Client Node

n8n: SSRF Protection Bypass via MCP Client Node

▾ Sunlitn8n · n8nvia GHSA
GHSA-rcv6-pvrj-4xcgHigh
2mo ago

n8n: Authenticated code execution in the n8n Git node

n8n: Authenticated code execution in the n8n Git node

▾ Twilightn8n · n8nvia GHSA
GHSA-2x35-3fw4-9jr4High
2mo ago

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

▾ Twilightn8n · n8nvia GHSA
GHSA-gv7g-jm28-cr3mHigh
2mo ago

n8n: Expression sandbox escape via arrow-function bodies enabling command execution

n8n: Expression sandbox escape via arrow-function bodies enabling command execution

▾ Twilightn8n · n8nvia GHSA
GHSA-6qc9-mqvw-jg7xHigh
2mo ago

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

▾ Twilightn8n · n8nvia GHSA
GHSA-cj9h-qx8g-pq2gHigh
2mo ago

n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

▾ Twilightn8n · n8nvia GHSA
GHSA-xmc9-4f2h-jf9cHigh
2mo ago

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

n8n: Edit Image Node Format Injection Allows Arbitrary File Write

▾ Twilightn8n · n8nvia GHSA
GHSA-xwx6-jjhv-84p8High
2mo ago

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

▾ Twilightn8n · n8nvia GHSA
GHSA-hx4h-vr3m-45vhMedium
2mo ago

n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service

n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service

▾ Sunlitn8n · n8nvia GHSA
GHSA-pf2q-pxhf-hgmwMedium
2mo ago

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-59259Medium
2mo ago

n8n: External Secrets Permission Bypass via Expression Parser Mismatch

n8n: External Secrets Permission Bypass via Expression Parser Mismatch

▾ Sunlitn8n · n8nEPSS 0.44%via GHSA
CVE-2026-59257Medium
2mo ago

n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

▾ Sunlitn8n · n8nEPSS 0.57%via GHSA
CVE-2026-59254Medium
2mo ago

n8n: External Secrets Accessible via Workflow Expressions Outside Credentials

n8n: External Secrets Accessible via Workflow Expressions Outside Credentials

▾ Sunlitn8n · n8nEPSS 0.36%via GHSA
CVE-2026-59253Medium
2mo ago

n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

▾ Sunlitn8n · n8nEPSS 0.28%via GHSA
CVE-2026-58661Medium
2mo ago

n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

▾ Sunlitn8n · n8nEPSS 0.39%via GHSA
CVE-2026-65590Medium
2mo ago

n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows

n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows

▾ Sunlitn8n · n8nEPSS 0.58%via GHSA
CVEs tagged “npm” — page 17 · VulnSea