Threats Tagged 'ghsa-9cmh-xcqm-5hqr'
View all threats tagged with 'ghsa-9cmh-xcqm-5hqr'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-9cmh-xcqm-5hqr'
Click on any threat for detailed analysis and mitigation recommendations
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner 0 n8n's JavaScript task runner shared a module cache across all users executing Code nodes, allowing a user to poison this cache and affect other users' Code-node executions on the same runner. This vulnerability breaks user isolation within a single n8n instance but does not enable sandbox escape or remote code execution. It affects all multi-user n8n instances running the JS task runner with built-in or external modules enabled. The issue is fixed in n8n versions 1.123.67, 2.31.5, and 2.32.1. Temporary mitigations include restricting access to trusted users, disabling module access in Code nodes, or using dedicated external runners per user or project. Join the discussion | GCVE Database | 07/22/2026, 23:18:39 UTC Added: 07/23/2026, 01:18:03 UTC |
Showing 1 to 1 of 1 result