PatchSiren

node-red CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH node-red CVE published 2026-08-05

CVE-2026-71269

Node-RED's local-filesystem library storage module is vulnerable to path traversal attacks due to improper handling of user-supplied path parameters in the getLibraryEntry() and saveLibraryEntry() functions. An authenticated user can exploit this by providing paths with `../` sequences to access arbitrary files outside the library directory. For users with write access, this enables remote code execution [truncated]