# \#security

**URL:** https://discourse.nodered.org/tag/security/10.md

[Latest](https://discourse.nodered.org/latest.md) · [Categories](https://discourse.nodered.org/categories.md) · [Tags](https://discourse.nodered.org/tags.md)

---

## [Protect Node Red from anywhere](https://discourse.nodered.org/t/protect-node-red-from-anywhere/101694)

<div class="topic-metadata">

**Author:** [@devifast](https://discourse.nodered.org/u/devifast)\
**Replies:** 2\
**Last updated:** [29 August 2026 14:25 UTC](https://discourse.nodered.org/t/protect-node-red-from-anywhere/101694 "2026-08-29T14:25:52Z")

</div>

Node-RED Security Variants Discussed and Tested Context The goal is to protect a Node-RED installation exposed through a router, while keeping the setup simple and understandable. The following four variants were discus…

---

## [Should Palette Manager show when a node downloads something from another server?](https://discourse.nodered.org/t/should-palette-manager-show-when-a-node-downloads-something-from-another-server/101638)

<div class="topic-metadata">

**Author:** [@Aaqu](https://discourse.nodered.org/u/Aaqu)\
**Replies:** 9\
**Last updated:** [16 August 2026 14:26 UTC](https://discourse.nodered.org/t/should-palette-manager-show-when-a-node-downloads-something-from-another-server/101638 "2026-08-16T14:26:39Z")

</div>

I noticed something in the Palette Manager and I wonder if it should be shown to users. When you install a module, Node-RED runs npm install for you. Sometimes a node has a dependency that is downloaded from another we…

---

## [Credential HUB – a self-hosted credential layer for automation tools](https://discourse.nodered.org/t/credential-hub-a-self-hosted-credential-layer-for-automation-tools/101615)

<div class="topic-metadata">

**Author:** [@luiscyphre](https://discourse.nodered.org/u/luiscyphre)\
**Replies:** 3\
**Last updated:** [11 August 2026 20:44 UTC](https://discourse.nodered.org/t/credential-hub-a-self-hosted-credential-layer-for-automation-tools/101615 "2026-08-11T20:44:52Z")

</div>

Credential HUB – a self-hosted credential layer for automation tools Hi everyone, I’ve been working on an open-source project called Credential HUB that grew out of a problem I kept running into with automation setu…

---

## [My flows disappears and is remplaced by another one without any action on my part](https://discourse.nodered.org/t/my-flows-disappears-and-is-remplaced-by-another-one-without-any-action-on-my-part/101452)

<div class="topic-metadata">

**Author:** [@Patrice](https://discourse.nodered.org/u/Patrice)\
**Replies:** 17\
**Last updated:** [12 July 2026 15:57 UTC](https://discourse.nodered.org/t/my-flows-disappears-and-is-remplaced-by-another-one-without-any-action-on-my-part/101452 "2026-07-12T15:57:29Z")

</div>

Hello, I’ve been using Node-RED to control my alarm system for a few years without any issues—until a few months ago, when I started regularly losing the dashboard. Let me explain: when the problem occurred, I checked …

---

## [Security issues with nr internal npm?](https://discourse.nodered.org/t/security-issues-with-nr-internal-npm/101034)

<div class="topic-metadata">

**Author:** [@ThingsTinkerer](https://discourse.nodered.org/u/ThingsTinkerer)\
**Replies:** 5\
**Last updated:** [16 May 2026 11:01 UTC](https://discourse.nodered.org/t/security-issues-with-nr-internal-npm/101034 "2026-05-16T11:01:17Z")

</div>

I have a docker container which includes npm v11. However due to some accidental PATH handling, I discovered there were npm audit security issues that couldn't be fixed because they originate from another npm version 10.…

---

## [Npm audit fails with recent node-red](https://discourse.nodered.org/t/npm-audit-fails-with-recent-node-red/100883)

<div class="topic-metadata">

**Author:** [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Replies:** 10\
**Last updated:** [7 May 2026 16:25 UTC](https://discourse.nodered.org/t/npm-audit-fails-with-recent-node-red/100883 "2026-05-07T16:25:58Z")

</div>

When running npm audit with recent node-red, I got the following error: uuid \<14.0.0 Severity: moderate uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided - https://github.com/advisories/GHSA-w5hq-g745-…

---

## [How to secure a flow if the settings file is accessible?](https://discourse.nodered.org/t/how-to-secure-a-flow-if-the-settings-file-is-accessible/100920)

<div class="topic-metadata">

**Author:** [@Xyntec](https://discourse.nodered.org/u/Xyntec)\
**Replies:** 6\
**Last updated:** [6 May 2026 14:46 UTC](https://discourse.nodered.org/t/how-to-secure-a-flow-if-the-settings-file-is-accessible/100920 "2026-05-06T14:46:45Z")

</div>

I have a windows panel PC which is available for a client as administrator, and run Node red on that to show some variables on a dashboard, the dashboard is available throughout the clients network so that it can be seen…

---

## [Security reminder re Internet-connected devices](https://discourse.nodered.org/t/security-reminder-re-internet-connected-devices/100912)

<div class="topic-metadata">

**Author:** [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Replies:** 0\
**Last updated:** [5 May 2026 10:01 UTC](https://discourse.nodered.org/t/security-reminder-re-internet-connected-devices/100912 "2026-05-05T10:01:32Z")

</div>

A quick reminder for folk who aren't sure whether they need to secure their home or small-office devices: https://www.ukauthority.com/articles/major-shift-in-chinese-cyber-attack-activity The UK’s National Cyber Secur…

---

## [Checking for installed npm packages and dependencies](https://discourse.nodered.org/t/checking-for-installed-npm-packages-and-dependencies/100701)

<div class="topic-metadata">

**Author:** [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Replies:** 18\
**Last updated:** [12 April 2026 21:33 UTC](https://discourse.nodered.org/t/checking-for-installed-npm-packages-and-dependencies/100701 "2026-04-12T21:33:24Z")

</div>

In recent months, there have been a number of high-profile supply-chain attacks on the npm package repository and some key packages. To make it easier to see whether you are impacted by such a compromise, I've created a…

---

## [Axios compromised, does this affect nodered?](https://discourse.nodered.org/t/axios-compromised-does-this-affect-nodered/100698)

<div class="topic-metadata">

**Author:** [@HybridZach](https://discourse.nodered.org/u/HybridZach)\
**Replies:** 17\
**Last updated:** [1 April 2026 15:09 UTC](https://discourse.nodered.org/t/axios-compromised-does-this-affect-nodered/100698 "2026-04-01T15:09:24Z")

</div>

Hello, not sure if this would be the appropriate place to ask this question. I just found out about a hack that happened regarding npm/axios. Since I don't use npm all that much I figured I'd be fine, but then I remember…

---

## [How to prevent Last-Mile Manipulation to Flows](https://discourse.nodered.org/t/how-to-prevent-last-mile-manipulation-to-flows/100546)

<div class="topic-metadata">

**Author:** [@AllanOricil](https://discourse.nodered.org/u/AllanOricil)\
**Replies:** 23\
**Last updated:** [20 March 2026 18:12 UTC](https://discourse.nodered.org/t/how-to-prevent-last-mile-manipulation-to-flows/100546 "2026-03-20T18:12:39Z")

</div>

Do you guys know a strategy to avoid flow tampering from the editor caused by evil plugins? I created one for NRG Sentinel that doesn't use the editor, but I want to know if you know a reliable way to do it from the edi…

---

## [Credential seret rotation](https://discourse.nodered.org/t/credential-seret-rotation/100579)

<div class="topic-metadata">

**Author:** [@sidisl16](https://discourse.nodered.org/u/sidisl16)\
**Replies:** 0\
**Last updated:** [17 March 2026 05:13 UTC](https://discourse.nodered.org/t/credential-seret-rotation/100579 "2026-03-17T05:13:43Z")

</div>

Is there any way to rotate secret credential?

---

## [Unexpected flow restart with lost of context files & tokens (google and telegram)!](https://discourse.nodered.org/t/unexpected-flow-restart-with-lost-of-context-files-tokens-google-and-telegram/100104)

<div class="topic-metadata">

**Author:** [@sebamelo](https://discourse.nodered.org/u/sebamelo)\
**Replies:** 24\
**Last updated:** [12 January 2026 12:11 UTC](https://discourse.nodered.org/t/unexpected-flow-restart-with-lost-of-context-files-tokens-google-and-telegram/100104 "2026-01-12T12:11:36Z")

</div>

Node-red 4.1.2 My flow randomly restart (each 2 or 3 days) and then all the context files are deleted (the variables are not re-written). Furtherlore the tokens field for telegram and google are blank. Is there a log …

---

## [Using Cloudflare Zero Trust with Node-RED](https://discourse.nodered.org/t/using-cloudflare-zero-trust-with-node-red/99864)

<div class="topic-metadata">

**Author:** [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Replies:** 11\
**Last updated:** [10 December 2025 12:27 UTC](https://discourse.nodered.org/t/using-cloudflare-zero-trust-with-node-red/99864 "2025-12-10T12:27:00Z")

</div>

Hi all, finally got round to starting a comprehensive guide to setting up Cloudflare's Zero Trust proxy access. This is the first draft, please let me know of any issues. Note that this has been taken direct from the UI…

---

## [How do you securely give credentials to a stand-alone Function node?](https://discourse.nodered.org/t/how-do-you-securely-give-credentials-to-a-stand-alone-function-node/99831)

<div class="topic-metadata">

**Author:** [@hoolahoous](https://discourse.nodered.org/u/hoolahoous)\
**Replies:** 61\
**Last updated:** [8 December 2025 16:45 UTC](https://discourse.nodered.org/t/how-do-you-securely-give-credentials-to-a-stand-alone-function-node/99831 "2025-12-08T16:45:33Z")

</div>

Hi all, I’m stuck on what should be a simple design question: How do you securely provide credentials to a stand-alone Function node without putting them in clear text anywhere in the flow? Most credential handling in…

---

## [Major CVE for react.js](https://discourse.nodered.org/t/major-cve-for-react-js/99866)

<div class="topic-metadata">

**Author:** [@JayDickson](https://discourse.nodered.org/u/JayDickson)\
**Replies:** 1\
**Last updated:** [4 December 2025 19:48 UTC](https://discourse.nodered.org/t/major-cve-for-react-js/99866 "2025-12-04T19:48:33Z")

</div>

Just a heads up for anyone using react.js in their projects, a major vulnerability was discovered and you should be taking steps to protect yourself.

---

## [Advice on how to handle the following reported vulnerabilities?](https://discourse.nodered.org/t/advice-on-how-to-handle-the-following-reported-vulnerabilities/99817)

<div class="topic-metadata">

**Author:** [@Nodi.Rubrum](https://discourse.nodered.org/u/Nodi.Rubrum)\
**Replies:** 3\
**Last updated:** [2 December 2025 14:58 UTC](https://discourse.nodered.org/t/advice-on-how-to-handle-the-following-reported-vulnerabilities/99817 "2025-12-02T14:58:07Z")

</div>

Advice on how to handle the following reported vulnerabilities? Seems that node-red-node-email has some issues? Or am I reading the following wrong? root@eccentric:/home/nodered/.node-red# npm audit fix npm warn audit…

---

## [Shai-Hulud / Sha1-Hulud - how can I tell whether my NR is affected](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794)

<div class="topic-metadata">

**Author:** [@gregorius](https://discourse.nodered.org/u/gregorius)\
**Replies:** 4\
**Last updated:** [28 November 2025 06:39 UTC](https://discourse.nodered.org/t/shai-hulud-sha1-hulud-how-can-i-tell-whether-my-nr-is-affected/99794 "2025-11-28T06:39:19Z")

</div>

Hi There, Is there any test to check whether my NR installation has been affected by this attack? I was reading the GitLab write up but it doesn't clearly state how to detect an infection.\\ Is there something simple s…

---

## [Important new law that may impact many on this forum](https://discourse.nodered.org/t/important-new-law-that-may-impact-many-on-this-forum/99530)

<div class="topic-metadata">

**Author:** [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Replies:** 4\
**Last updated:** [29 October 2025 16:00 UTC](https://discourse.nodered.org/t/important-new-law-that-may-impact-many-on-this-forum/99530 "2025-10-29T16:00:18Z")

</div>

Hi all, my newsfeed recently popped this up and I thought I should share it. Even though it is not directly Node-RED related, it may impact Node-RED, FlowFuse, the JavaScript Foundation and anyone using Node-RED or other…

---

## [Überlastung PI oder NodeRed](https://discourse.nodered.org/t/uberlastung-pi-oder-nodered/99460)

<div class="topic-metadata">

**Author:** [@schnuller](https://discourse.nodered.org/u/schnuller)\
**Replies:** 20\
**Last updated:** [29 October 2025 15:32 UTC](https://discourse.nodered.org/t/uberlastung-pi-oder-nodered/99460 "2025-10-29T15:32:30Z")

</div>

Hallo Ich betreibe seit fast 2 Jahren ein Smart Home mit einem PI4 und einer 32GB SD Karte. Habe ca 15 Dashboards mit Grafischer Kurvenanzeigen mit Daten alle 5 Minuten, welche verschiedene Analogwerte der letzten 24S…

---

## ["Supply Chain" security for developers](https://discourse.nodered.org/t/supply-chain-security-for-developers/99531)

<div class="topic-metadata">

**Author:** [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Replies:** 0\
**Last updated:** [29 October 2025 14:00 UTC](https://discourse.nodered.org/t/supply-chain-security-for-developers/99531 "2025-10-29T14:00:41Z")

</div>

With recent widespread attacks on the open source community, though I would share some additional security tooling that is free, easy to use and will help node.js, Python, etc developers against supply chain attacks. I…

---

## [Node.js Package: axios \< 1.12.0 - Remote Denial of Service Vulnerability](https://discourse.nodered.org/t/node-js-package-axios-1-12-0-remote-denial-of-service-vulnerability/99107)

<div class="topic-metadata">

**Author:** [@GowriAradhya](https://discourse.nodered.org/u/GowriAradhya)\
**Replies:** 2\
**Last updated:** [19 September 2025 08:44 UTC](https://discourse.nodered.org/t/node-js-package-axios-1-12-0-remote-denial-of-service-vulnerability/99107 "2025-09-19T08:44:40Z")

</div>

Package name: axios Node-RED version:4.1.0 Node-red-admin "version": "4.1.1", depends on axios version 1.11.0, which contains vulnerabilities. CVE reference link:

---

## [GitHub & npm Security](https://discourse.nodered.org/t/github-npm-security/99095)

<div class="topic-metadata">

**Author:** [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Replies:** 4\
**Last updated:** [18 September 2025 12:14 UTC](https://discourse.nodered.org/t/github-npm-security/99095 "2025-09-18T12:14:05Z")

</div>

Hi all, You are hopefully aware of the recent dramatic increase in attacks on open source supply chains. Especially code on GitHub and npm. I've been increasing security on my GitHub repositories over time and have re-…

---

## [Add helmet to the express server to avoid common security vulnerabilities](https://discourse.nodered.org/t/add-helmet-to-the-express-server-to-avoid-common-security-vulnerabilities/99081)

<div class="topic-metadata">

**Author:** [@AllanOricil](https://discourse.nodered.org/u/AllanOricil)\
**Replies:** 1\
**Last updated:** [17 September 2025 15:31 UTC](https://discourse.nodered.org/t/add-helmet-to-the-express-server-to-avoid-common-security-vulnerabilities/99081 "2025-09-17T15:31:46Z")

</div>

---

## [Supply-chain malware check on Node-RED](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988)

<div class="topic-metadata">

**Author:** [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Replies:** 10\
**Last updated:** [9 September 2025 09:02 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988 "2025-09-09T09:02:09Z")

</div>

There is a compromised dependency drawn into Node-RED. ( Malware in debug · GHSA-8mgj-vmr8-frr6 · GitHub Advisory Database · GitHub ) How can I avoid installing this dependency?

---

## [Malware found in node-red project](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799)

<div class="topic-metadata">

**Author:** [@Bolukan](https://discourse.nodered.org/u/Bolukan)\
**Replies:** 32\
**Last updated:** [6 September 2025 16:56 UTC](https://discourse.nodered.org/t/malware-found-in-node-red-project/98799 "2025-09-06T16:56:29Z")

</div>

I found malicious code in my project. It was not in my repository, not even proof It has been active as it errored an update. The prior edit of the project was 18 hours ago (no issues) and I updated portainer 2 days ago.…

---

## [Node-red-contrib-tuya-smart-device across VLANs](https://discourse.nodered.org/t/node-red-contrib-tuya-smart-device-across-vlans/98703)

<div class="topic-metadata">

**Author:** [@Sirhc](https://discourse.nodered.org/u/Sirhc)\
**Replies:** 9\
**Last updated:** [17 August 2025 12:43 UTC](https://discourse.nodered.org/t/node-red-contrib-tuya-smart-device-across-vlans/98703 "2025-08-17T12:43:25Z")

</div>

Hi All I have put all of my tuya devices on a separate VLAN. I can ping the devices from the nodered VLAN, but I get an error connecting to the devices on the other VLAN using Node-red-contrib-tuya-smart-device. Keep g…

---

## [Node Red starts mining Monero coins without my consent!](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344)

<div class="topic-metadata">

**Author:** [@devifast](https://discourse.nodered.org/u/devifast)\
**Replies:** 34\
**Last updated:** [28 July 2025 14:59 UTC](https://discourse.nodered.org/t/node-red-starts-mining-monero-coins-without-my-consent/98344 "2025-07-28T14:59:05Z")

</div>

I noticed that Node red has started mining Monero cryptocurrency without my knowledge and permission. I remove the process in htop but after deploying the flow in Node red it reappears. How did this happen?

---

## [NATS communication with credential file as authentification](https://discourse.nodered.org/t/nats-communication-with-credential-file-as-authentification/98266)

<div class="topic-metadata">

**Author:** [@KRR](https://discourse.nodered.org/u/KRR)\
**Replies:** 2\
**Last updated:** [24 July 2025 07:05 UTC](https://discourse.nodered.org/t/nats-communication-with-credential-file-as-authentification/98266 "2025-07-24T07:05:31Z")

</div>

In a project i have to use NATS communication. For the authentification on the NATS-server a credential file (based on JWT) is used. The credential file should be stored on the docker container of NodeRed. With currently…

---

## [Admin auth: password issue](https://discourse.nodered.org/t/admin-auth-password-issue/97815)

<div class="topic-metadata">

**Author:** [@mus-ab03](https://discourse.nodered.org/u/mus-ab03)\
**Replies:** 2\
**Last updated:** [29 June 2025 10:59 UTC](https://discourse.nodered.org/t/admin-auth-password-issue/97815 "2025-06-29T10:59:06Z")

</div>

I have node-red 4.0.9 running as a service using nssm, I set up the password using node-red-admin hash-pw. After a few days it seems that the password was changed automatically and I had to reset the password in settings…

[Next page](https://discourse.nodered.org/tag/security/10.md?match_all_tags=true&page=1&tags%5B%5D=security)
