CVE-2026-33751
- EPSS 0.07%
- Veröffentlicht 25.03.2026 18:47:39
- Zuletzt bearbeitet 27.03.2026 19:28:01
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacharacters to pass through unescaped when user-controlled input was interpolated into L...
- EPSS 0.04%
- Veröffentlicht 25.03.2026 18:39:54
- Zuletzt bearbeitet 27.03.2026 19:30:08
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows could craft a workflow that produces an HTML binary data object without a filename...
CVE-2026-33724
- EPSS 0.02%
- Veröffentlicht 25.03.2026 18:26:54
- Zuletzt bearbeitet 27.03.2026 19:32:03
n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command used for git operations explicitly disabled host key verification. A network attacker positioned bet...
CVE-2026-33722
- EPSS 0.01%
- Veröffentlicht 25.03.2026 18:09:37
- Zuletzt bearbeitet 27.03.2026 19:34:18
n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plaintext value...
CVE-2026-33720
- EPSS 0.01%
- Veröffentlicht 25.03.2026 18:06:38
- Zuletzt bearbeitet 27.03.2026 19:38:03
n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` environment variable is set to `true`, the OAuth callback handler skips ownership verification of the OAuth state parameter. This a...
CVE-2026-33713
- EPSS 0.02%
- Veröffentlicht 25.03.2026 17:47:44
- Zuletzt bearbeitet 27.03.2026 19:39:36
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection vulnerability in the Data Table Get node. On default...
CVE-2026-33696
- EPSS 0.33%
- Veröffentlicht 25.03.2026 17:40:39
- Zuletzt bearbeitet 27.03.2026 19:40:55
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin n...
CVE-2026-33665
- EPSS 0.02%
- Veröffentlicht 25.03.2026 17:32:20
- Zuletzt bearbeitet 30.03.2026 14:23:59
n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if the LDAP email attribute matched the local account...
CVE-2026-33663
- EPSS 0.02%
- Veröffentlicht 25.03.2026 17:11:09
- Zuletzt bearbeitet 31.03.2026 16:39:13
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit chained authorization flaws in n8n's credential pipeline to steal plaintext secrets ...
CVE-2026-33660
- EPSS 0.07%
- Veröffentlicht 25.03.2026 17:09:09
- Zuletzt bearbeitet 30.03.2026 14:54:07
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n ho...