OpenAI Node Vulnerabilities

npm LLM APIs

AI Threat Alert tracks 22 known vulnerabilities in OpenAI Node, 5 rated critical — an AI/ML llm apis in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
34
Risk Score
22
Total CVEs
5
Critical
npm
Ecosystem
Sep 22, 2026
Last CVE
46%
Patch Rate
212d
Avg Time to Patch
11,189 stars 1,607 forks 8 issues 1,431 dependents Last push Sep 26, 2026
View on GitHub

Known Vulnerabilities (22 total, page 1 of 1)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-85709 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_server.py. The detail=str(e), detail=str(exc), and equivalent formatted-message paths expose server filesystem paths, database host, port, user, and database names, language-model provider diagnostics, configuration details, and Python library internals t 5.3 Sep 22, 2026 HIGH GHSA-m3wp-48jr-vr4g mistral.rs: unbounded media fetch enables DoS 7.5 Sep 10, 2026 HIGH CVE-2026-19592 Codex CLI: git core.fsmonitor hook enables RCE 7.3 Sep 1, 2026 CRITICAL CVE-2026-19593 Codex Desktop: Git config filter triggers sandbox-escape RCE 9.8 Sep 1, 2026 HIGH CVE-2026-19591 Codex CLI: PowerShell parsing flaw bypasses approval, RCE 8.8 Sep 1, 2026 HIGH CVE-2026-19590 Codex Desktop: Git hook trust flaw enables RCE 7.3 Sep 1, 2026 HIGH CVE-2026-55638 9router: /codex bypass exposes LLM proxy credentials 8.6 Aug 28, 2026 HIGH CVE-2026-55641 9router: Host-header spoof bypasses auth, enables SSRF 8.2 Aug 28, 2026 CRITICAL CVE-2026-61539 Xinference: eval() on LLM output enables RCE 10.0 Aug 21, 2026 HIGH CVE-2026-69249 cryptography: exponential DoS in cert chain validation -- Aug 3, 2026 HIGH CVE-2026-67425 Flyto2 Core: SSRF leaks LLM API keys via base_url 8.6 Jul 29, 2026 CRITICAL GHSA-vjc7-jrh9-9j86 9Router: no-auth API leaks keys, chats, provider control 10.0 Jul 6, 2026 HIGH CVE-2024-22198 Nginx-UI: command injection via settings API 7.1 Jan 11, 2024 HIGH CVE-2024-22197 Nginx-UI: authenticated command injection to RCE 7.7 Jan 11, 2024 CRITICAL CVE-2024-23827 Nginx-UI: arbitrary file write via cert import leads to RCE 9.8 Jan 29, 2024 HIGH CVE-2025-69134 OpenAI Chatbot WP Helper: unauth content deletion 7.5 Jul 2, 2026 MEDIUM CVE-2026-42045 LobeChat: XSS-to-RCE via exposed Electron IPC 6.2 May 5, 2026 HIGH GHSA-w8hx-hqjv-vjcq Paperclip: RCE via workspace runtime command injection 7.3 Apr 16, 2026 HIGH GHSA-gqqj-85qm-8qhf paperclipai: connector trust bypass enables Gmail read/write 8.7 Apr 16, 2026 LOW GHSA-r7w7-9xr2-qq2r langchain-openai: SSRF DNS rebinding, blind network probe 3.1 Apr 16, 2026 CRITICAL CVE-2025-61260 OpenAI Codex CLI: RCE via malicious MCP config files 9.8 Apr 14, 2026 MEDIUM CVE-2026-39411 LobeChat: auth bypass via forged XOR obfuscated header 5.0 Apr 8, 2026

Frequently asked questions

What is OpenAI Node?

OpenAI Node is an AI/ML llm apis tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does OpenAI Node have?

OpenAI Node has 22 known CVEs, 5 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is OpenAI Node distributed in?

OpenAI Node is distributed via the npm ecosystem and categorized as llm apis.

Where does the OpenAI Node vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of OpenAI Node?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor OpenAI Node in your stack

Get instant alerts when new vulnerabilities affect OpenAI Node. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring