Low-code programming for event-driven applications
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11080 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. node-red is vulnerable to Argument Injection in versions 0.18.0 - 4.1.10. | 0.18.0 - 4.1.10 | Medium |
CVE-2019-15607 node-red is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 0.20.7. | 0.0.0 - 0.20.7 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
cors Version 2.8.5 | — | — |
nopt Version 5.0.0 | — | — |
semver Version 7.7.4 | — | — |
express Version 4.22.2 | — | — |
bcryptjs Version 3.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant