@node-red/runtime
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @node-red/runtimepage 1 of 1
- CVE-2021-21297HIGHCVSS 7.7EG 7.7✓ Fixed in 1.2.82021-02-26
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default J…
- CVE-2021-21298LOWCVSS 3.5EG 3.5✓ Fixed in 1.2.82021-02-26
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is enabled, a user with…
Check whether @node-red/runtime is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @node-red/runtime CVEs against the assets you own.
Start Free Scan →