N8n

N8n

193 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 30.06.2026 22:08:41
  • Zuletzt bearbeitet 02.07.2026 19:39:01

n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the vali...

  • EPSS 0.18%
  • Veröffentlicht 30.06.2026 22:08:35
  • Zuletzt bearbeitet 02.07.2026 19:38:43

n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed...

  • EPSS 0.28%
  • Veröffentlicht 30.06.2026 22:08:34
  • Zuletzt bearbeitet 02.07.2026 19:38:20

n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO polic...

  • EPSS 0.21%
  • Veröffentlicht 24.06.2026 11:53:19
  • Zuletzt bearbeitet 26.06.2026 02:01:57

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with...

  • EPSS 0.14%
  • Veröffentlicht 24.06.2026 11:53:19
  • Zuletzt bearbeitet 26.06.2026 02:02:10

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Att...

  • EPSS 0.33%
  • Veröffentlicht 23.06.2026 15:55:30
  • Zuletzt bearbeitet 24.06.2026 13:55:55

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a...

  • EPSS 0.63%
  • Veröffentlicht 23.06.2026 15:54:17
  • Zuletzt bearbeitet 24.06.2026 13:57:35

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, ...

  • EPSS 0.65%
  • Veröffentlicht 23.06.2026 15:53:13
  • Zuletzt bearbeitet 24.06.2026 13:54:08

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitr...

  • EPSS 0.88%
  • Veröffentlicht 23.06.2026 15:52:45
  • Zuletzt bearbeitet 24.06.2026 15:16:40

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTT...

  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 15:52:19
  • Zuletzt bearbeitet 26.06.2026 20:17:13

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-onl...