StackRadar

CVE-2026-12866

Critical

Advisory

Published 23 Jun 2026In the index since 23 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
8
of 17,985 indexed, latest versions
Container images
8
deployed by those charts
Fix available
None
affected package

expr-eval vulnerable to Code Execution

Carried by container images the latest versions of 8 of 17,985 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
expr-evalnpm2.0.2no fix listed8
OSV records
GHSA-q9v2-7m5w-4693

Charts affected

8 by stars
ChartLatestAffected imagesRadar Score
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
expr-eval@2.0.2
no fix listed

Open the chart page →

6,117
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
expr-eval@2.0.2
no fix listed

Open the chart page →

3,191
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
expr-eval@2.0.2
no fix listed

Open the chart page →

40,834
activepiecesadnoctemVerified publisher0.6.01 of 1See more

activepieces adnoctem 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
activepieces/activepieces:0.91.058414dfc94c4
expr-eval@2.0.2
no fix listed

Open the chart page →

1,533
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
expr-eval@2.0.2
no fix listed

Open the chart page →

5,300
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
expr-eval@2.0.2
no fix listed

Open the chart page →

3,565
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
expr-eval@2.0.2
no fix listed

Open the chart page →

6,598
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-12866.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
expr-eval@2.0.2
no fix listed

Open the chart page →

7,093

Container images carrying it

8 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
activepieces/activepieces:0.91.058414dfc94c4
expr-eval@2.0.2
no fix listed
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
expr-eval@2.0.2
no fix listed
1
n8nio/n8n:1.86.08b39ed5a2de9
expr-eval@2.0.2
no fix listed
1
n8nio/n8n:1.33.1dd171d45102a
expr-eval@2.0.2
no fix listed
1
n8nio/n8n:1.115.1ed16e560c40e
expr-eval@2.0.2
no fix listed
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
expr-eval@2.0.2
no fix listed
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
expr-eval@2.0.2
no fix listed
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
expr-eval@2.0.2
no fix listed
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.