VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-86082Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…

▾ Sunlitn8n · n8nEPSS 0.41%via NVD
CVE-2026-86081High· 7.1
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The p…

▾ Twilightn8n-io · n8nEPSS 0.56%via NVD
CVE-2026-86080Medium· 5.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow sta…

▾ Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86079Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An i…

▾ Sunlitn8n · n8nEPSS 0.49%via NVD
CVE-2026-86078Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API…

▾ Sunlitn8n · n8nEPSS 0.59%via NVD
CVE-2026-86077Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous f…

▾ Sunlitn8n · n8nEPSS 0.43%via NVD
CVE-2026-86076High· 8.8
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __s…

▾ Twilightn8n · n8nEPSS 0.79%via NVD
CVE-2026-86075High· 7.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated re…

▾ Twilightn8n · n8nEPSS 0.61%via NVD
GHSA-rgj7-g3m4-5g8cHigh
2w ago

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

▾ Twilightsharp · sharpvia GHSA
GHSA-j95f-988m-3j2fHigh
2w ago

Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing

Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing

▾ Twilighttiptap · @tiptap/corevia GHSA
GHSA-8m3c-c648-2xjjMedium· 5.9
2w ago

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-2xp9-vwfh-vxw4Critical
2w ago

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

▾ Midnightnext · nextvia GHSA
GHSA-26w7-cxv4-gfx2Critical· 9.8
2w ago

Astro: Remote code execution through AVIF image optimization

Astro: Remote code execution through AVIF image optimization

▾ Midnightastro · astrovia GHSA
CVE-2026-15603Medium· 5.3
2w ago

morgan vulnerable to Log Forging via unescaped Unicode line separators

morgan vulnerable to Log Forging via unescaped Unicode line separators

▾ Sunlitmorgan · morganEPSS 0.29%via GHSA
GHSA-wmmp-3585-3rmpMedium· 6.5
2w ago

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-cc9r-2j5m-2m83Medium· 6.5
2w ago

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-2x7j-588g-ccc2High· 7.5
2w ago

Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

▾ Twilightnodemailer · nodemailervia GHSA
GHSA-2q42-4q24-7rgvHigh· 7.1
2w ago

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

▾ Twilighttypespec · @typespec/openapi3via GHSA
CVE-2026-86996Medium· 5.4
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a too…

▾ Sunlitn8n · n8nEPSS 0.29%via NVD
CVE-2026-82333High· 7.5
2w ago

multer vulnerable to Denial of Service via oversized array index in field names

multer vulnerable to Denial of Service via oversized array index in field names

▾ Twilightmulter · multerEPSS 0.49%via GHSA
CVE-2026-77078High· 7.5PoC
2w ago

multer vulnerable to Denial of Service via crafted multipart field names

multer vulnerable to Denial of Service via crafted multipart field names

▾ Midnightmulter · multerEPSS 0.49%via GHSA
CVE-2026-77063Low· 3.7
2w ago

multer vulnerable to file size limit bypass via async fileFilter race condition

multer vulnerable to file size limit bypass via async fileFilter race condition

▾ Sunlitmulter · multerEPSS 0.23%via GHSA
CVE-2026-77037High· 7.5
2w ago

multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

▾ Twilightmulter · multerEPSS 0.58%via GHSA
CVE-2026-86073High· 7.6
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked on…

▾ Twilightn8n · n8nEPSS 0.39%via NVD
CVE-2026-86074High· 7.1
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-co…

▾ Twilightn8n · n8nEPSS 0.38%via NVD
CVE-2026-76969Critical· 9.4
2w ago

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive …

▾ MidnightSAP_SE · SAP Cloud Application Programming Model (CAP)EPSS 0.44%via NVD
CVE-2026-86439High· 8.8
2w ago

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory…

▾ Twilightknowns-dev · knownsEPSS 1.1%via NVD
GHSA-7q9c-hpx7-9cwmHigh· 7.5
3w ago

TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

▾ Twilighttypespec · @typespec/spectorvia GHSA
GHSA-6hxq-p678-4hr2Low
3w ago

SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor

SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor

▾ Sunlitsimplewebauthn · @simplewebauthn/servervia GHSA
CVE-2026-85062Medium· 6.9
3w ago

Colord is a tiny yet powerful tool for high-performance color manipulations and conversions

Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.t…

▾ Sunlitomgovich · colordEPSS 0.51%via NVD
CVEs tagged “npm” — page 4 · VulnSea