Package impact

npm npm / n8n

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-42233 critical 9.8 9.8 23d ago n8n has SQL Injection in Oracle Database Node via Limit Field npm
CVE-2026-42235 critical 9.6 9.6 23d ago n8n Vulnerable to XSS via MCP OAuth client npm
CVE-2026-44791 critical 9.5 13d ago n8n Has an XML Node Prototype Pollution Patch Bypass npm
CVE-2026-44790 critical 9.5 13d ago n8n Has an Arbitrary File Read via Git Node npm
CVE-2026-44789 critical 9.5 13d ago n8n: HTTP Request Node Pagination Prototype Pollution to RCE npm
CVE-2026-42237 high 8.8 8.8 23d ago n8n has SQL Injection in Snowflake and MySQL Nodes npm
CVE-2026-42234 high 8.8 8.8 23d ago n8n has a Python Task Runner Sandbox Escape Vulnerability npm
CVE-2026-42232 high 8.8 8.8 23d ago n8n has XML Node Prototype Pollution that to RCE npm
CVE-2026-42231 high 8.8 8.8 23d ago n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE npm
CVE-2026-42229 high 8.8 8.8 23d ago n8n has SQL Injection in SeaTable Node npm
CVE-2026-45732 high 8.0 13d ago n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints npm
CVE-2026-44792 high 8.0 13d ago n8n Has a Source Control Pull SQL Injection npm
CVE-2026-42236 high 7.5 7.5 23d ago n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration npm
CVE-2026-42226 high 7.5 7.5 23d ago n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay npm