CVE-2026-72772
- EPSS 0.22%
- Veröffentlicht 11.08.2026 12:17:11
- Zuletzt bearbeitet 11.08.2026 16:17:36
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email clai...
CVE-2026-65599
- EPSS 0.15%
- Veröffentlicht 22.07.2026 11:21:46
- Zuletzt bearbeitet 27.07.2026 19:18:25
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only for a key ide...
CVE-2026-65598
- EPSS 0.24%
- Veröffentlicht 22.07.2026 11:21:45
- Zuletzt bearbeitet 27.07.2026 19:18:06
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the cl...
CVE-2026-65596
- EPSS 0.21%
- Veröffentlicht 22.07.2026 11:21:44
- Zuletzt bearbeitet 27.07.2026 19:15:28
n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user ab...
CVE-2026-65597
- EPSS 0.21%
- Veröffentlicht 22.07.2026 11:21:44
- Zuletzt bearbeitet 27.07.2026 19:15:45
n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injec...
CVE-2026-65595
- EPSS 0.47%
- Veröffentlicht 22.07.2026 11:21:43
- Zuletzt bearbeitet 27.07.2026 19:14:35
n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privileged user who ...
CVE-2026-65593
- EPSS 0.14%
- Veröffentlicht 22.07.2026 11:21:42
- Zuletzt bearbeitet 27.07.2026 19:12:13
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to...
CVE-2026-65594
- EPSS 0.27%
- Veröffentlicht 22.07.2026 11:21:42
- Zuletzt bearbeitet 27.07.2026 19:13:07
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances...
CVE-2026-65592
- EPSS 0.17%
- Veröffentlicht 22.07.2026 11:21:41
- Zuletzt bearbeitet 27.07.2026 19:11:30
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker ...
CVE-2026-65590
- EPSS 0.32%
- Veröffentlicht 22.07.2026 11:21:40
- Zuletzt bearbeitet 27.07.2026 19:10:27
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or net...