Node-Red is a flow-based programming platform widely embedded in IoT, automation, and integration workflows where its visual node composition paradigm reduces barriers to building networked applications. Its vulnerability footprint concentrates in the core Node-Red product and dashboard components and recurs through application-layer weakness classes—particularly cross-site scripting, path traversal, and prototype pollution—that arise from the dynamic nature of web-based node configuration and the platform's acceptance of user-supplied object manipulation. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting both the accessibility of the platform and the appeal of its pervasive deployment in less-heavily-monitored infrastructure; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nodered over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3223HIGH Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. | Jan 26, 2021 | 7.5 | 43 | NO | YES |
CVE-2022-3783MEDIUM A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-compon | Oct 31, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-21297MEDIUM Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A bad | Feb 26, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-21298MEDIUM Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Pr | Feb 26, 2021 | 6.5 | 21 | NO | NO |
CVE-2019-10756MEDIUM It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default. | Oct 8, 2019 | 5.4 | 20 | NO | NO |
CVE-2019-15607MEDIUM A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker | Jan 28, 2020 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nodered.
Media articles that mention a CVE ID that affects a product developed by Nodered — matched by CVE ID, not by vendor name.