CVE-2026-86077
- EPSS 0.36%
- Veröffentlicht 08.09.2026 21:28:06
- Zuletzt bearbeitet 14.09.2026 13:18:57
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous form submitter...
CVE-2026-86078
- EPSS 0.28%
- Veröffentlicht 08.09.2026 21:27:21
- Zuletzt bearbeitet 11.09.2026 18:21:20
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contai...
CVE-2026-86079
- EPSS 0.32%
- Veröffentlicht 08.09.2026 21:26:28
- Zuletzt bearbeitet 11.09.2026 18:21:33
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An identifier con...
CVE-2026-86080
- EPSS 0.2%
- Veröffentlicht 08.09.2026 21:25:48
- Zuletzt bearbeitet 11.09.2026 18:21:38
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow static data then...
CVE-2026-86081
- EPSS 0.32%
- Veröffentlicht 08.09.2026 21:24:20
- Zuletzt bearbeitet 09.09.2026 20:16:54
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern ^(./)....
CVE-2026-86082
- EPSS 0.25%
- Veröffentlicht 08.09.2026 21:23:23
- Zuletzt bearbeitet 14.09.2026 13:18:57
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set ...
CVE-2026-86083
- EPSS 0.28%
- Veröffentlicht 08.09.2026 21:22:40
- Zuletzt bearbeitet 11.09.2026 16:12:56
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating time...
CVE-2026-86084
- EPSS 0.32%
- Veröffentlicht 08.09.2026 21:21:55
- Zuletzt bearbeitet 10.09.2026 21:10:42
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administra...
CVE-2026-86085
- EPSS 0.26%
- Veröffentlicht 08.09.2026 21:20:35
- Zuletzt bearbeitet 14.09.2026 13:18:57
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A caller with...
CVE-2026-86993
- EPSS 0.27%
- Veröffentlicht 08.09.2026 21:19:53
- Zuletzt bearbeitet 10.09.2026 21:02:49
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user wit...