StackRadar

CVE-2026-85063

Medium

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
32
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
1 of 1
affected package

node-csv: Prototype replacement still reachable via columns path

Carried by container images the latest versions of 32 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
csv-parsenpm3.2.0, 4.11.1, 4.12.0, 4.16.0+6 more7.0.231
OSV records
GHSA-8cw4-87c7-c6xx

Charts affected

32 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
csv-parse@6.2.1
7.0.2

Open the chart page →

1,038
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
csv-parse@5.5.0
7.0.2

Open the chart page →

5,639
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
csv-parse@6.2.1
7.0.2

Open the chart page →

1,339
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
csv-parse@4.12.0
7.0.2

Open the chart page →

8,213
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
csv-parse@4.16.3
7.0.2

Open the chart page →

2,521
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
csv-parse@4.16.3
7.0.2

Open the chart page →

2,851
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
csv-parse@4.16.3
7.0.2

Open the chart page →

38,346
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
csv-parse@6.2.1
7.0.2

Open the chart page →

2,575
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
csv-parse@6.2.1
7.0.2

Open the chart page →

5,482
crowdsec-web-uizekker6Verified publisher0.51.01 of 1See more

crowdsec-web-ui zekker6 0.51.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
csv-parse@6.2.1
7.0.2

Open the chart page →

1,411
adeptia-automate-mcpadeptia-automate-mcp1.0.01 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
csv-parse@6.1.0
7.0.2

Open the chart page →

3,600
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
csv-parse@5.6.0
7.0.2

Open the chart page →

1,055
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
csv-parse@4.16.0
7.0.2

Open the chart page →

2,783
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
csv-parse@4.16.3
7.0.2

Open the chart page →

5,488
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
csv-parse@4.12.0
7.0.2

Open the chart page →

4,043
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
csv-parse@4.11.1
7.0.2
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
csv-parse@4.11.1
7.0.2
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
csv-parse@4.11.1
7.0.2
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
csv-parse@4.11.1
7.0.2

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
csv-parse@4.12.0
7.0.2

Open the chart page →

8,213
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
csv-parse@5.6.0
7.0.2

Open the chart page →

3,014
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
csv-parse@4.16.3
7.0.2

Open the chart page →

4,944
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
csv-parse@5.5.0
7.0.2

Open the chart page →

5,826
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
csv-parse@4.16.0
7.0.2

Open the chart page →

1,614
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
csv-parse@6.1.0
7.0.2

Open the chart page →

14,809
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
csv-parse@6.1.0
7.0.2

Open the chart page →

1,948
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
csv-parse@4.16.3
7.0.2

Open the chart page →

6,608
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
csv-parse@6.2.1
7.0.2

Open the chart page →

1,038
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
csv-parse@6.2.1
7.0.2

Open the chart page →

1,038
walletconnect-relayparadeum-teamVerified publisher0.1.21 of 1See more

walletconnect-relay paradeum-team 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
csv-parse@4.16.3
7.0.2

Open the chart page →

1,243
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
csv-parse@3.2.0
7.0.2

Open the chart page →

5,215
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
csv-parse@5.6.0
7.0.2

Open the chart page →

3,014
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
csv-parse@5.2.2
7.0.2

Open the chart page →

4,017
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
csv-parse@6.2.1
7.0.2

Open the chart page →

1,787
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-85063.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
csv-parse@4.16.3
7.0.2

Open the chart page →

3,129

Container images carrying it

31 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
infisical/infisical:latest:v0.165.602082bf13163
csv-parse@5.6.0
7.0.2
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
csv-parse@4.12.0
7.0.2
2
mojaloop/reporting:v12.1.0d480a62103d6
csv-parse@6.1.0
7.0.2
2
n8nio/n8n:2.36.714c4285bc303
csv-parse@6.2.1
7.0.2
2
activepieces/activepieces:0.90.430c10a04fe3d
csv-parse@5.6.0
7.0.2
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
csv-parse@6.1.0
7.0.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
csv-parse@4.16.3
7.0.2
1
gristlabs/grist:0.7.96e71b1914a7e
csv-parse@3.2.0
7.0.2
1
ianw/quickchart:v1.7.1dc49dd460c37
csv-parse@4.16.3
7.0.2
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
csv-parse@4.16.0
7.0.2
1
n8nio/n8n:2.25.7761374d4eb84
csv-parse@6.2.1
7.0.2
1
n8nio/n8n:1.86.08b39ed5a2de9
csv-parse@5.5.0
7.0.2
1
n8nio/n8n:2.36.8cfe2704ff858
csv-parse@6.2.1
7.0.2
1
n8nio/n8n:1.33.1dd171d45102a
csv-parse@5.5.0
7.0.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
csv-parse@4.12.0
7.0.2
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
csv-parse@4.16.3
7.0.2
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
csv-parse@4.16.3
7.0.2
1
polonel/trudesk:1.2.60cf6513f6fe3
csv-parse@5.2.2
7.0.2
1
rocketadmin/rocketadmin:1.17.710955ef540b9
csv-parse@6.2.1
7.0.2
1
stanfordoval/almond-server:latest1a63cdccedaf
csv-parse@4.16.3
7.0.2
1
veecode/devportalc443520aebf7
csv-parse@6.2.1
7.0.2
1
zazuko/trifid:2.3.7054be137de70
csv-parse@4.16.0
7.0.2
1
zooz/predator:1.6f491d1f7a865
csv-parse@4.16.3
7.0.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
csv-parse@4.11.1
7.0.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
csv-parse@4.11.1
7.0.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
csv-parse@4.11.1
7.0.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
csv-parse@4.11.1
7.0.2
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
csv-parse@4.16.3
7.0.2
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
csv-parse@6.2.1
7.0.2
1
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
csv-parse@4.16.3
7.0.2
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
csv-parse@6.2.1
7.0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.