Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-65594Mediumn8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
CVE-2026-65596Mediumn8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
CVE-2026-65014Mediumn8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
CVE-2026-65589Mediumn8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
CVE-2026-64641HighNext.js: Denial of Service in App Router using Server Actions
Next.js: Denial of Service in App Router using Server Actions
CVE-2026-64642HighNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
CVE-2026-64643MediumNext.js: Unauthenticated disclosure of internal Server Function endpoints
Next.js: Unauthenticated disclosure of internal Server Function endpoints
CVE-2026-64644MediumNext.js: Denial of Service in the Image Optimization API using SVGs
Next.js: Denial of Service in the Image Optimization API using SVGs
CVE-2026-64645HighNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
CVE-2026-64646MediumNext.js: Unbounded Server Action payload in Edge runtime
Next.js: Unbounded Server Action payload in Edge runtime
CVE-2026-64647MediumNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
GHSA-m7jc-p4hf-xhwqHighDuplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-wq64-hcrf-8m56HighDuplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
GHSA-mwq7-vcmc-cm4qHighDuplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-38fj-36m5-783cMediumDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-59209Highn8n: Shared Credential Header Leak via HTTP Request Pagination Expression
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-59206Highn8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVE-2026-59207Highn8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
CVE-2026-59208Highn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVE-2026-65595Highn8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
CVE-2026-65593Mediumn8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65591HighPoCn8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2026-65016Highn8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-8342-988q-86crHighn8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-64xh-79j6-r5v8Highn8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-w46p-w7w2-fr9gHighDuplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-h5xr-fqvj-253pHighDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-vhcw-f978-xjjgHighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GHSA-725q-c4vp-q4cgHighDuplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
GHSA-mhvh-gwhr-76pwMediumDuplicate Advisory: Google Service Account Private Key Exposed in JWT Header
Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header