npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-65589Mediumn8n: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution DataCVE-2026-65014Mediumn8n: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test WebhookCVE-2026-65596Mediumn8n: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" RestrictionCVE-2026-65594Mediumn8n: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization CheckCVE-2026-65590Mediumn8n: n8n: computer-use Shell Sandbox Not Enforced on Linux and WindowsCVE-2026-58661Mediumn8n: n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File UploadsCVE-2026-59253Mediumn8n: n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other ProjectsCVE-2026-59254Mediumn8n: n8n: External Secrets Accessible via Workflow Expressions Outside CredentialsCVE-2026-59257Mediumn8n: n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression InterpolationCVE-2026-59259Mediumn8n: n8n: External Secrets Permission Bypass via Expression Parser MismatchGHSA-PF2Q-PXHF-HGMWMediumn8n: n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base DirectoryGHSA-HX4H-VR3M-45VHMediumn8n: n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of ServiceGHSA-XWX6-JJHV-84P8Highn8n: n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of ServiceGHSA-XMC9-4F2H-JF9CHighn8n: n8n: Edit Image Node Format Injection Allows Arbitrary File WriteGHSA-CJ9H-QX8G-PQ2GHighn8n: n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSONGHSA-6QC9-MQVW-JG7XHighn8n: n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`GHSA-GV7G-JM28-CR3MHighn8n: n8n: Expression sandbox escape via arrow-function bodies enabling command executionGHSA-2X35-3FW4-9JR4Highn8n: n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type ConfusionGHSA-RCV6-PVRJ-4XCGHighn8n: n8n: Authenticated code execution in the n8n Git nodeGHSA-VHF8-CG2H-CG3PMediumn8n: n8n: SSRF Protection Bypass via MCP Client NodeGHSA-GF29-4F56-R2JFHighn8n: n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path RestrictionGHSA-64XH-79J6-R5V8Highn8n: n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM NodesGHSA-8342-988Q-86CRHighn8n: n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed LoginCVE-2026-65016Highn8n: n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance OwnerCVE-2026-65591Highn8n: n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

Stop the waste.
Protect your environment with Kodem.