StackRadar

CVE-2026-92937

Critical

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
Critical
worst across findings
CVSS
10.0
base score, highest
EPSS
0.010
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3
of 18,071 indexed, latest versions
Container images
2
deployed by those charts
Fix available
1 of 1
affected package

vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection

Carried by container images the latest versions of 3 of 18,071 indexed charts deploy, on 2 images.

Affected packageAffected versionsFixed inImages
vm2npm3.11.63.11.72
OSV records
GHSA-647f-g98j-qq25

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-92937.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
vm2@3.11.6
3.11.7

Open the chart page →

2,378
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-92937.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
vm2@3.11.6
3.11.7

Open the chart page →

2,378
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-92937.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
vm2@3.11.6
3.11.7

Open the chart page →

2,378

Container images carrying it

2 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
n8nio/n8n:2.36.714c4285bc303
vm2@3.11.6
3.11.7
2
n8nio/n8n:2.36.8cfe2704ff858
vm2@3.11.6
3.11.7
1

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.