N8n

N8n

193 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 09.07.2026 15:27:28
  • Zuletzt bearbeitet 14.07.2026 01:16:18

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim...

  • EPSS 0.26%
  • Veröffentlicht 09.07.2026 15:16:36
  • Zuletzt bearbeitet 09.07.2026 19:37:19

n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a ...

  • EPSS 0.31%
  • Veröffentlicht 08.07.2026 13:49:13
  • Zuletzt bearbeitet 09.07.2026 15:16:39

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the raw SQL st...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 13:49:12
  • Zuletzt bearbeitet 08.07.2026 19:25:45

n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request payloads d...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 13:49:07
  • Zuletzt bearbeitet 08.07.2026 19:26:35

n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only access to ...

  • EPSS 0.18%
  • Veröffentlicht 08.07.2026 13:49:06
  • Zuletzt bearbeitet 08.07.2026 19:31:35

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:execute sco...

  • EPSS 0.16%
  • Veröffentlicht 08.07.2026 13:49:06
  • Zuletzt bearbeitet 09.07.2026 16:16:45

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-on...

  • EPSS 0.19%
  • Veröffentlicht 08.07.2026 13:49:03
  • Zuletzt bearbeitet 08.07.2026 19:32:49

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

  • EPSS 0.14%
  • Veröffentlicht 08.07.2026 13:49:02
  • Zuletzt bearbeitet 09.07.2026 15:16:38

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials...

  • EPSS 0.41%
  • Veröffentlicht 04.07.2026 01:23:42
  • Zuletzt bearbeitet 06.10.2026 22:10:00

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to ...