CVE-2019-10756: Nodered Node-Red-Dashboard
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
Affected products
- Nodered Node-Red-Dashboard: before 2.17.0 (fixed in 2.17.0)
Published 2019-10-08. Last modified 2026-06-17.