Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2241582
AlmaLinux
5967
Alpaquita
16176
Alpine
4655
Android
3677
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9476
Chainguard
1048510
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68963
Echo
7866
GHC
3
GIT
109042
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148513
npm
229196
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25464
Red Hat
23527
Rocky Linux
4343
Root
19638
RubyGems
5331
SUSE
23442
SwiftURL
60
TuxCare
9919
Ubuntu
65977
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17176
npm/n8n-nodes-moonlet-helpers
Malicious code in n8n-nodes-moonlet-helpers (npm)
25 Sep
No fix available
MAL-2026-17177
npm/n8n-nodes-moonlet-utils
Malicious code in n8n-nodes-moonlet-utils (npm)
25 Sep
No fix available
MAL-2026-17175
npm/n8n-nodes-flowstats
Malicious code in n8n-nodes-flowstats (npm)
25 Sep
No fix available
MAL-2026-16444
npm/n8n-nodes-healthmon
Malicious code in n8n-nodes-healthmon (npm)
23 Sep
No fix available
MAL-2026-16445
npm/n8n-nodes-metricsagent
Malicious code in n8n-nodes-metricsagent (npm)
23 Sep
No fix available
MAL-2026-16418
npm/n8n-nodes-data-transformer-utils
Malicious code in n8n-nodes-data-transformer-utils (npm)
22 Sep
No fix available
MAL-2026-16177
npm/n8n-nodes-buildcheck
Malicious code in n8n-nodes-buildcheck (npm)
15 Sep
No fix available
MAL-2026-16162
npm/n8n-nodes-sysdiag2
Malicious code in n8n-nodes-sysdiag2 (npm)
14 Sep
No fix available
MAL-2026-16147
npm/n8n-nodes-sysdiag
Malicious code in n8n-nodes-sysdiag (npm)
14 Sep
No fix available
GHSA-cw9w-vv67-hf73
npm/n8n
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
10 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-q5wm-mgqx-fv2f
npm/n8n
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
10 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-qgpw-8g46-w95v
npm/n8n
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
10 Sep
Fix available
Severity - 5.3 (Medium)
GHSA-cqr2-h44g-v75v
npm/n8n
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
10 Sep
Fix available
Severity - 5.1 (Medium)
GHSA-pq6c-vh67-xpm3
npm/n8n
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
10 Sep
Fix available
Severity - 5.9 (Medium)
GHSA-pf83-w3f9-8m37
npm/n8n
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
10 Sep
Fix available
Severity - 6.0 (Medium)
GHSA-5m98-cgcr-xx3q
npm/n8n
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
10 Sep
Fix available
Severity - 6.3 (Medium)
Load more...
npm - OSV