Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17176
  • npm/n8n-nodes-moonlet-helpers
Malicious code in n8n-nodes-moonlet-helpers (npm) 2 days ago
  • No fix available
MAL-2026-17177
  • npm/n8n-nodes-moonlet-utils
Malicious code in n8n-nodes-moonlet-utils (npm) 2 days ago
  • No fix available
MAL-2026-17175
  • npm/n8n-nodes-flowstats
Malicious code in n8n-nodes-flowstats (npm) 2 days ago
  • No fix available
MAL-2026-16444
  • npm/n8n-nodes-healthmon
Malicious code in n8n-nodes-healthmon (npm) 4 days ago
  • No fix available
MAL-2026-16445
  • npm/n8n-nodes-metricsagent
Malicious code in n8n-nodes-metricsagent (npm) 4 days ago
  • No fix available
MAL-2026-16418
  • npm/n8n-nodes-data-transformer-utils
Malicious code in n8n-nodes-data-transformer-utils (npm) 4 days ago
  • No fix available
MAL-2026-16177
  • npm/n8n-nodes-buildcheck
Malicious code in n8n-nodes-buildcheck (npm) 15 Sep
  • No fix available
MAL-2026-16162
  • npm/n8n-nodes-sysdiag2
Malicious code in n8n-nodes-sysdiag2 (npm) 14 Sep
  • No fix available
MAL-2026-16147
  • npm/n8n-nodes-sysdiag
Malicious code in n8n-nodes-sysdiag (npm) 14 Sep
  • No fix available
GHSA-cw9w-vv67-hf73
  • npm/n8n
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution 10 Sep
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-q5wm-mgqx-fv2f
  • npm/n8n
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content 10 Sep
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-qgpw-8g46-w95v
  • npm/n8n
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read 10 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-cqr2-h44g-v75v
  • npm/n8n
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints 10 Sep
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-pq6c-vh67-xpm3
  • npm/n8n
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check 10 Sep
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-pf83-w3f9-8m37
  • npm/n8n
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions 10 Sep
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-5m98-cgcr-xx3q
  • npm/n8n
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open 10 Sep
  • Fix available
  • Severity - 6.3 (Medium)