N8n

N8n

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 15:47:25
  • Zuletzt bearbeitet 26.06.2026 02:20:12

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership...

  • EPSS 0.21%
  • Veröffentlicht 23.06.2026 15:46:21
  • Zuletzt bearbeitet 26.06.2026 02:24:34

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webhookId. When...

  • EPSS 0.34%
  • Veröffentlicht 23.06.2026 15:45:52
  • Zuletzt bearbeitet 26.06.2026 02:24:03

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on ...

  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 15:44:58
  • Zuletzt bearbeitet 26.06.2026 02:25:03

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Content-Type. The...

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 15:43:12
  • Zuletzt bearbeitet 26.06.2026 20:17:26

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object copying. These...

  • EPSS 0.28%
  • Veröffentlicht 23.06.2026 15:42:39
  • Zuletzt bearbeitet 26.06.2026 02:20:35

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL could submi...

  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 15:41:11
  • Zuletzt bearbeitet 25.06.2026 18:41:32

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox context was cac...

  • EPSS 0.39%
  • Veröffentlicht 23.06.2026 15:40:15
  • Zuletzt bearbeitet 25.06.2026 18:41:18

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitra...

  • EPSS 0.4%
  • Veröffentlicht 23.06.2026 15:36:13
  • Zuletzt bearbeitet 25.06.2026 18:40:16

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-...

  • EPSS 0.38%
  • Veröffentlicht 23.06.2026 15:33:52
  • Zuletzt bearbeitet 25.06.2026 18:42:34

n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated attacker could...