Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host High
CVE-2026-54304 was published for n8n (npm) Jun 16, 2026
34selen Credited to 34selen
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint Moderate
GHSA-hv7x-3x78-gx53 was published for n8n (npm) Jun 16, 2026
34selen Credited to 34selen
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution Moderate
CVE-2026-42228 was published for n8n (npm) Apr 29, 2026
34selen Credited to 34selen, Aikido-Security, JorianWoltjer, reindaelman, grumpinout1, and vbCrLf Aikido-Security Aikido-Security
JorianWoltjer JorianWoltjer reindaelman reindaelman grumpinout1 grumpinout1 vbCrLf vbCrLf
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover High
CVE-2026-33665 was published for n8n (npm) Mar 25, 2026
weblover12 Credited to weblover12, 34selen, B0RI, and jh-hack 34selen 34selen
B0RI B0RI jh-hack jh-hack
Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion High
CVE-2026-6409 was published for google/protobuf (Composer) Mar 25, 2026
34selen Credited to 34selen
ProTip! Advisories are also available from the GraphQL API