Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-86082Medium· 6.5n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…
CVE-2026-86081High· 7.1n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The p…
CVE-2026-86080Medium· 5.3n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow sta…
CVE-2026-86079Medium· 6.5n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An i…
CVE-2026-86078Medium· 6.5n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API…
CVE-2026-86077Medium· 6.5n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous f…
CVE-2026-86076High· 8.8n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __s…
CVE-2026-86075High· 7.5n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated re…
GHSA-rgj7-g3m4-5g8cHighsharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
GHSA-j95f-988m-3j2fHighTiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
GHSA-8m3c-c648-2xjjMedium· 5.9Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
GHSA-2xp9-vwfh-vxw4CriticalNext.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
GHSA-26w7-cxv4-gfx2Critical· 9.8Astro: Remote code execution through AVIF image optimization
Astro: Remote code execution through AVIF image optimization
CVE-2026-15603Medium· 5.3morgan vulnerable to Log Forging via unescaped Unicode line separators
morgan vulnerable to Log Forging via unescaped Unicode line separators
GHSA-wmmp-3585-3rmpMedium· 6.5Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
GHSA-cc9r-2j5m-2m83Medium· 6.5Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
GHSA-2x7j-588g-ccc2High· 7.5Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
GHSA-2q42-4q24-7rgvHigh· 7.1OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
CVE-2026-86996Medium· 5.4n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a too…
CVE-2026-82333High· 7.5multer vulnerable to Denial of Service via oversized array index in field names
multer vulnerable to Denial of Service via oversized array index in field names
CVE-2026-77078High· 7.5PoCmulter vulnerable to Denial of Service via crafted multipart field names
multer vulnerable to Denial of Service via crafted multipart field names
CVE-2026-77063Low· 3.7multer vulnerable to file size limit bypass via async fileFilter race condition
multer vulnerable to file size limit bypass via async fileFilter race condition
CVE-2026-77037High· 7.5multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
CVE-2026-86073High· 7.6n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked on…
CVE-2026-86074High· 7.1n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-co…
CVE-2026-76969Critical· 9.4@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive …
CVE-2026-86439High· 8.8knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory…
GHSA-7q9c-hpx7-9cwmHigh· 7.5TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
GHSA-6hxq-p678-4hr2LowSimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
CVE-2026-85062Medium· 6.9Colord is a tiny yet powerful tool for high-performance color manipulations and conversions
Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.t…