Node.js Vulnerabilities

4 advisories affecting Node.js

4

Total CVEs

3

Critical

1

High

CVE-2026-28292

Mar 10, 2026

Critical (9.8)

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and...

Read Advisory

CVE-2026-30966

Mar 10, 2026

Critical (10.0)

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field ma...

Read Advisory

CVE-2026-29784

Mar 7, 2026

High (7.5)

Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the reque...

Read Advisory

CVE-2026-27574

Feb 21, 2026

Critical (9.9)

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a secur...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.