Package impact
NPM / n8n
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2026-42233 | critical | 9.8 | 9.8 | 24d ago | n8n has SQL Injection in Oracle Database Node via Limit Field | |
| CVE-2026-42235 | critical | 9.6 | 9.6 | 24d ago | n8n Vulnerable to XSS via MCP OAuth client | |
| CVE-2026-44791 | critical | — | 9.5 | 14d ago | n8n Has an XML Node Prototype Pollution Patch Bypass | |
| CVE-2026-44790 | critical | — | 9.5 | 14d ago | n8n Has an Arbitrary File Read via Git Node | |
| CVE-2026-44789 | critical | — | 9.5 | 14d ago | n8n: HTTP Request Node Pagination Prototype Pollution to RCE |