CVE-2026-42235
- EPSS 0.33%
- Veröffentlicht 04.05.2026 18:38:09
- Zuletzt bearbeitet 06.05.2026 18:05:44
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dial...
CVE-2026-42234
- EPSS 0.38%
- Veröffentlicht 04.05.2026 18:36:55
- Zuletzt bearbeitet 06.05.2026 18:05:52
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code ...
CVE-2026-42233
- EPSS 0.33%
- Veröffentlicht 04.05.2026 18:35:42
- Zuletzt bearbeitet 06.05.2026 18:07:22
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated dir...
CVE-2026-42232
- EPSS 0.48%
- Veröffentlicht 04.05.2026 18:34:11
- Zuletzt bearbeitet 06.05.2026 17:15:28
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when comb...
CVE-2026-42231
- EPSS 0.85%
- Veröffentlicht 04.05.2026 18:30:27
- Zuletzt bearbeitet 06.05.2026 17:14:03
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authe...
CVE-2026-42230
- EPSS 0.18%
- Veröffentlicht 04.05.2026 18:28:43
- Zuletzt bearbeitet 06.05.2026 14:57:11
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. ...
CVE-2026-42229
- EPSS 0.34%
- Veröffentlicht 04.05.2026 18:27:44
- Zuletzt bearbeitet 06.05.2026 14:56:49
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query strings witho...
CVE-2026-42228
- EPSS 0.38%
- Veröffentlicht 04.05.2026 18:27:06
- Zuletzt bearbeitet 06.05.2026 18:08:21
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact...
CVE-2026-42227
- EPSS 0.2%
- Veröffentlicht 04.05.2026 18:26:18
- Zuletzt bearbeitet 06.05.2026 18:08:47
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projects they are not a member of by supplying an arbitra...
CVE-2026-42226
- EPSS 0.26%
- Veröffentlicht 04.05.2026 18:26:08
- Zuletzt bearbeitet 06.05.2026 18:09:25
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An authenticated u...