CVE-2026-103258
- EPSS 0.3%
- Veröffentlicht 01.10.2026 10:42:02
- Zuletzt bearbeitet 06.10.2026 01:16:32
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass filters by breaking out of query literals. Attackers can ex...
CVE-2026-103259
- EPSS 0.24%
- Veröffentlicht 01.10.2026 10:42:02
- Zuletzt bearbeitet 01.10.2026 20:17:22
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by ...
CVE-2026-103256
- EPSS 0.21%
- Veröffentlicht 01.10.2026 10:42:00
- Zuletzt bearbeitet 01.10.2026 14:17:22
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permission...
- EPSS 0.28%
- Veröffentlicht 01.10.2026 10:41:59
- Zuletzt bearbeitet 06.10.2026 01:16:32
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals. Attackers with workflow creation permissions can mint valid appr...
CVE-2026-103253
- EPSS 0.23%
- Veröffentlicht 01.10.2026 10:41:58
- Zuletzt bearbeitet 01.10.2026 16:17:35
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields t...
CVE-2026-103252
- EPSS 0.27%
- Veröffentlicht 01.10.2026 10:41:57
- Zuletzt bearbeitet 01.10.2026 14:17:21
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can...
CVE-2026-103247
- EPSS 0.24%
- Veröffentlicht 01.10.2026 10:41:54
- Zuletzt bearbeitet 01.10.2026 20:17:22
n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retai...
CVE-2026-103245
- EPSS 0.16%
- Veröffentlicht 01.10.2026 10:41:52
- Zuletzt bearbeitet 01.10.2026 15:17:26
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook handler. Unauthenticated attackers can send forged webhook requests with attacker-co...
CVE-2026-86075
- EPSS 0.29%
- Veröffentlicht 08.09.2026 21:29:38
- Zuletzt bearbeitet 11.09.2026 18:20:42
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated remote caller c...
CVE-2026-86076
- EPSS 0.33%
- Veröffentlicht 08.09.2026 21:28:52
- Zuletzt bearbeitet 11.09.2026 18:20:56
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __sanitize could...