Traceary

Security advisories

Every advisory the tracked projects have published, newest first, with the release that carries the fix. Severity is the one its publisher assigned. Nothing here is our judgement.

Advisories
640across 21 products
critical
48
high
242
medium
304
low
46
Newest
25 Aug 20262 days ago

An advisory is listed only when its publisher has published it with an identifier. Release notes that use the word security without one are not listed here, because a security page is worth reading only if every line on it can be checked. 545 of these carry a CVE, and 340 are matched to the release in the archive that fixed them.

Next.jscritical

Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

GHSA-2xp9-vwfh-vxw4Fixed in 16.3.3Advisory
vLLMmedium

Unauthenticated audio decompression-bomb DoS in /v1/chat/completions: VLLM_MAX_AUDIO_DECODE_DURATION_S guard not wired into the chat audio path (sibling of CVE-2026-5497)

Difyhigh

IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers

GHSA-ccrj-frp2-c945Fixed in 1.16.0Advisory
n8nmedium

Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across Projects

GHSA-jmmj-93rg-6j39Fixed in 2.35.4Advisory
n8nmedium

Legacy Request Helper SSRF Check Validates uri While Axios Dispatches url

GHSA-jp9j-jr97-w9pjFixed in 2.33.4Advisory
n8nhigh

Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error Data

GHSA-vrv8-j27g-g7crFixed in 2.35.4Advisory
n8nhigh

Gmail and Brevo nodes accept non-string content, enabling local file read and SSRF

GHSA-95ph-833c-4wrpFixed in 2.35.4Advisory
n8nhigh

Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCE

GHSA-9x83-43r8-5hwcFixed in 2.35.4Advisory
n8nhigh

Git Node Remote Code Execution via Incomplete Repository-Local Configuration Neutralization

GHSA-mwp5-2m32-r54hFixed in 2.35.4Advisory
n8nmedium

Query Injection in Elasticsearch and Google Cloud Firestore Nodes via Unescaped Expression Interpolation

GHSA-wxwj-8wv6-vpw2Fixed in 2.35.4Advisory
n8nhigh

Shared-Workflow Editor Can Exfiltrate Credentials via Workflow Tool Node Inline Sub-Workflow

GHSA-4r56-g65c-fm83Fixed in 2.35.4Advisory
n8nhigh

Expression Sandbox SpreadElement Bypass Enables Persistent Cross-Evaluation Native Object Mutation

GHSA-fg85-4wv2-p98jFixed in 2.35.4Advisory
vLLMmedium

SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vLLMmedium

vLLM Unauthenticated Requests Exploit DeepStream Backend Confusion for DoS

GHSA-cqm8-jxg6-fqfqFixed in 0.27.0Advisory
n8nmedium

SSRF Protection Bypass via SearXNG Tool Allows Member Users to Read Internal Service Responses

GHSA-9rp2-wm75-c5fjFixed in 2.33.4Advisory
n8nhigh

Code execution in the n8n Git node via unchecked repository-local git configuration

GHSA-m87g-qr43-ccvcFixed in 2.33.4Advisory
n8nmedium

ReDoS in Filter and Switch Node Regex Matching Allows Worker Denial of Service

GHSA-q3fv-295f-qfpfFixed in 2.33.4Advisory
n8nmedium

GraphQL Node Allowed-Domains Bypass Permits Restricted Credential Exfiltration

GHSA-wcv8-x773-j96rFixed in 2.33.4Advisory
n8nhigh

Custom-role deletion's reassignment path bypasses project-scoped authorization

GHSA-xhmh-8fgr-xqhjFixed in 2.33.4Advisory
n8nhigh

JavaScript Task Runner VM Sandbox Escape via EventEmitter Prototype Pollution Leads to Remote Code Execution

GHSA-m3hg-p5r9-fg9hFixed in 2.33.4Advisory
n8nhigh

GraphQL Node Raw Error Re-throw Leaks Decrypted Credential Headers into Persisted Execution Data

GHSA-9fqj-7wc5-cwhxFixed in 2.33.4Advisory
n8nhigh

Resource Locator Link Preview Expression Injection Allows Cross-User Script Execution

GHSA-fh4c-9rr2-p7qcFixed in 2.33.4Advisory
n8nmedium

MCP create_workflow_from_code Accepts Cross-Project Credentials When Auth Type Is an Expression

GHSA-vfrj-582q-mvcpFixed in 2.33.4Advisory
n8nhigh

Supabase Node PostgREST Filter Injection in Row Get Many, Delete, and Update Operations

GHSA-f4f3-2g67-4vhmFixed in 2.33.4Advisory
n8nhigh

MongoDB Node NoSQL Injection in Find, Delete, and Aggregate Operations via Unescaped Expression Interpolation

GHSA-953p-jm2c-8h5jFixed in 2.33.4Advisory
n8nlow

SSRF Protection Bypass via OAuth2 Credential Token Exchange Reflects Internal Response Body

GHSA-c4f6-59xq-95wwFixed in 2.33.4Advisory
n8nhigh

RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading

GHSA-6h4x-896x-fw5mFixed in 2.33.4Advisory
Open WebUImedium

Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

vLLMlow

Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vLLMmedium

Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vLLMmedium

ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vLLMmedium

Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

n8nmedium

PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

GHSA-jqwr-vx3p-r266Fixed in 2.31.5Advisory
n8nhigh

Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

n8nmedium

Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory

GHSA-pf2q-pxhf-hgmwFixed in 2.31.5Advisory
n8nhigh

Account Takeover via Unverified Email Claim in Token Exchange Embed Login

GHSA-8342-988q-86crFixed in 2.31.5Advisory
n8nhigh

Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

GHSA-64xh-79j6-r5v8Fixed in 2.31.5Advisory
n8nhigh

Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction

GHSA-gf29-4f56-r2jfFixed in 2.31.5Advisory
n8nhigh

Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Code Execution

GHSA-hx4h-vr3m-45vhFixed in 2.31.5Advisory
n8nhigh

Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

GHSA-2x35-3fw4-9jr4Fixed in 2.31.5Advisory
n8nhigh

Expression sandbox escape via arrow-function bodies enabling command execution

GHSA-gv7g-jm28-cr3mFixed in 2.31.5Advisory
n8nhigh

Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON

GHSA-cj9h-qx8g-pq2gFixed in 2.31.5Advisory
n8nmedium

Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

GHSA-652q-gvq3-74qvFixed in 2.31.5Advisory
n8nhigh

Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service

GHSA-xwx6-jjhv-84p8Fixed in 2.35.4Advisory
Next.jsmedium

Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Astrolow

Cross-site scripting via unescaped transition:* directive values on hydrated islands

CVE-2026-59727Fixed in 7.0.4Advisory
Astrolow

XSS via unescaped spread attribute names in custom element rendering

CVE-2026-59729Fixed in 7.0.5Advisory
Astrolow

composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

CVE-2026-73423Fixed in 7.0.5Advisory
Astromedium

Unauthenticated path override in the @astrojs/vercel ISR function

CVE-2026-73424Fixed in 11.0.3Advisory
Astromedium

Reflected XSS via unescaped View Transition animation properties

CVE-2026-73422Fixed in 7.1.0Advisory
Astrolow

Backslash-prefixed paths not recognized as internal by trailing-slash redirect in @astrojs/node

CVE-2026-59730Fixed in 11.0.2Advisory
Astromedium

XML injection in @astrojs/rss via unescaped source and enclosure fields

CVE-2026-59728Fixed in 4.0.19Advisory
Astrolow

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

CVE-2026-73425Fixed in 8.1.2Advisory
n8nhigh

Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

n8nhigh

Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

GHSA-777w-rpr6-c52hFixed in 2.29.8Advisory
n8nmedium

Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check

GHSA-q5xf-xhwf-cwqfFixed in 2.29.8Advisory
n8nmedium

Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

GHSA-9w78-79q7-r4fpFixed in 2.29.8Advisory
n8nhigh

Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

GHSA-pm35-fqvh-cq5gFixed in 2.29.8Advisory
n8nmedium

Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

GHSA-89gh-3pgc-v5h2Fixed in 2.29.8Advisory
n8nhigh

SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

GHSA-35q8-9mj6-wjmfFixed in 2.29.8Advisory
n8nmedium

Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook

GHSA-33q9-f52j-gc75Fixed in 2.27.4Advisory
vLLMmedium

ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

vLLMmedium

DoS caused by sending `/v1/completions` with prompt embeds payload with models that use M-RoPE

Open WebUIlow

Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUImedium

`WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUIhigh

Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUIlow

Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUImedium

Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Astrohigh

Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

CVE-2026-59731Fixed in 6.4.8Advisory
Open WebUImedium

POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

n8nhigh

Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

n8nmedium

MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

GHSA-hwmj-qg4v-cvg9Fixed in 2.27.4Advisory
n8nhigh

Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration

n8nhigh

"Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector

n8nmedium

External Secrets Accessible via Workflow Expressions Outside Credentials

GHSA-2434-3x6q-8r99Fixed in 2.27.4Advisory
n8nmedium

Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

GHSA-2xgm-wc4g-5jvgFixed in 2.28.0Advisory
n8nmedium

Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

GHSA-w867-jm58-p9pvFixed in 2.28.0Advisory
vLLMhigh

Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

Astrohigh

Reflected XSS via unescaped slot name

CVE-2026-50146Fixed in 6.3.3Advisory
Astromedium

@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config

CVE-2026-54300Fixed in 7.0.13Advisory
Astromedium

XSS via Unescaped Attribute Names in Spread Props

CVE-2026-54298Fixed in 6.4.6Advisory
Astrohigh

Host header SSRF in prerendered error page fetch

CVE-2026-54299Fixed in 6.4.6Advisory
vLLMmedium

vLLM image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

vLLMmedium

GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

vLLMmedium

temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

vLLMmedium

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router (CWE-532)

Open WebUImedium

Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

vLLMmedium

Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors

n8nmedium

Public API Execution Retry Authorization Bypass

GHSA-h3jj-5f3v-3685Fixed in 2.26.2Advisory
n8nmedium

Python Code Node AST Validator Bypass

GHSA-jwm3-qcfw-c5ppFixed in 2.26.2Advisory
n8nhigh

Stored XSS in Chat Trigger Node

CVE-2026-54302Fixed in 1.123.55Advisory
n8nmedium

Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints

CVE-2026-54303Fixed in 2.24.0Advisory
n8nhigh

Microsoft SQL Node Prototype Pollution

CVE-2026-54312Fixed in 2.24.0Advisory
n8nmedium

Merge Node SQL Mode Prototype Pollution

CVE-2026-54311Fixed in 2.26.2Advisory
n8nmedium

Prototype Pollution enables confused-deputy execution via public webhooks

CVE-2026-54306Fixed in 2.26.2Advisory
n8nhigh

Same-Origin XSS in Respond to Webhook Node

CVE-2026-54301Fixed in 1.123.55Advisory
n8nmedium

Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

CVE-2026-54308Fixed in 2.26.2Advisory
n8nmedium

Wrong OAuth Scope On Evaluations Test Run Creation Endpoint

GHSA-hv7x-3x78-gx53Fixed in 1.123.55Advisory
n8nmedium

NoSQL Injection in MongoDB Node Find And Replace Operation

CVE-2026-54313Fixed in 2.24.0Advisory
n8nmedium

SQL Injection in Postgres v1/TimesclaeDB Nodes

CVE-2026-54310Fixed in 2.26.2Advisory
n8nhigh

SecurityScorecard Node Leaks API Token to User-Controlled Host

CVE-2026-54304Fixed in 1.123.55Advisory
n8nhigh

n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

CVE-2026-54309Fixed in 2.26.2Advisory
n8nhigh

Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

CVE-2026-54305Fixed in 1.123.55Advisory
n8nhigh

Credential Exfiltration via Permission Bypass

CVE-2026-54307Fixed in 1.123.55Advisory
n8nmedium

Wrong OAuth Scope on Evaluation Test Runs Endpoints

GHSA-664h-gpgq-h6xxFixed in 1.123.55Advisory
n8nmedium

Denial of Service via ZIP decompression in webhook workflow

CVE-2026-54314Fixed in 2.24.0Advisory
n8nmedium

Git Node Clone and Push Operations Bypass File Sandbox

CVE-2026-49465Fixed in 1.123.48Advisory
n8nhigh

Python sandbox escape

CVE-2026-49444Fixed in 1.123.48Advisory
Denomedium

BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions

Denomedium

Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks

Denomedium

process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access

Difylow

Dify API Extension has SSRF Vulnerability

GHSA-cg9f-q34p-p9h3Fixed in 0.6.8Advisory
Difyhigh

Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint

GHSA-8235-vv5j-mmvgFixed in 1.13.0Advisory
n8nmedium

Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

GHSA-2vx9-7wpg-88jqFixed in 2.20.0Advisory
n8nmedium

Credential exfiltration via Allowed HTTP Request Domains Bypass

GHSA-3875-8gcx-7v46Fixed in 2.20.0Advisory
n8ncritical

Arbitrary File Read via Git Node

CVE-2026-44790Fixed in 1.123.43Advisory
n8ncritical

HTTP Request Node Pagination Prototype Pollution to RCE

CVE-2026-44789Fixed in 1.123.43Advisory
n8nhigh

Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints

CVE-2026-45732Fixed in 1.123.43Advisory
n8nhigh

Source Control Pull SQL Injection

CVE-2026-44792Fixed in 1.123.43Advisory
n8ncritical

XML Node Prototype Pollution Patch Bypass

CVE-2026-44791Fixed in 1.123.43Advisory
Open WebUImedium

Sharing models for others to use (read permission) also exposes model details (system prompt leakage)

Open WebUIhigh

Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

Open WebUIhigh

SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

Open WebUIhigh

Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption

Open WebUIhigh

Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution

Open WebUImedium

Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation

Open WebUImedium

Missing authorization check at the model update function - models from other users can be updated

CVE-2026-45345Fixed in 0.5.7Advisory
Open WebUImedium

Blind server side request forgery (SSRF) via the PDF generate function

CVE-2026-45347Fixed in 0.5.11Advisory
Open WebUImedium

API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints

Open WebUIlow

Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

Open WebUIhigh

Missing permission check in files API allows authenticated users to list, access and delete every uploaded file

CVE-2026-45301Fixed in 0.3.16Advisory
Open WebUIhigh

Stored XSS via the HTML renedering view

CVE-2026-45303Fixed in 0.6.5Advisory
Astrolow

Server island encrypted parameters vulnerable to cross-component replay

CVE-2026-45028Fixed in 6.1.10Advisory
Next.jshigh

Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up

Open WebUIhigh

KL-CAN-2024-004: Open WebUI Improper Authorization Control

CVE-2026-44567Fixed in 0.1.124Advisory
Open WebUIhigh

KL-CAN-2024-005: Open WebUI Arbitrary File Write, Delete via Path Traversal

CVE-2026-44565Fixed in 0.6.10Advisory
Open WebUIhigh

GitHub Security Lab (GHSL) Vulnerability Report, open-webui: GHSL-2024-174, GHSL-2024-175

GHSA-6xcp-7mpr-m7wmFixed in 0.3.33Advisory
Open WebUIhigh

Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

LangChainhigh

Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists

vLLMmedium

extract_hidden_states speculative decoding crashes server on any request with penalty parameters

n8nmedium

Open Redirect in MCP OAuth Consent Flow

CVE-2026-42230Fixed in 1.123.32Advisory
n8nhigh

Python Task Runner Sandbox Escape

CVE-2026-42234Fixed in 1.123.32Advisory
n8nmedium

SQL Injection in Oracle Database Node via Limit Field

CVE-2026-42233Fixed in 1.123.32Advisory