GHSA-xp9c-82x8-7f67

    Dashboard / Vulnerabilities / GHSA-xp9c-82x8-7f67

    GHSA-xp9c-82x8-7f67

    Published: 26 Feb 2021Last Modified: 8 Jul 2026

    Summary: Prototype Pollution in Node-Red

    Details: ### Impact Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default behaviour of the Node-RED runtime. ### Patches The vulnerability is patched in the 1.2.8 release. ### Workarounds A workaround is to ensure only authorised users are able to access the editor url. ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected]) ### Acknowledgements Thanks to the Tencent Woodpecker Security Team for disclosing this vulnerability.

    Affected packages

    Package

    Name: @node-red/runtime

    Purl: pkg:npm/%40node-red/runtime

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.2.8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-xp9c-82x8-7f67 | CVE-DB