N8n

N8n

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Veröffentlicht 22.07.2026 11:21:40
  • Zuletzt bearbeitet 27.07.2026 19:11:06

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-lev...

  • EPSS 0.37%
  • Veröffentlicht 22.07.2026 11:21:39
  • Zuletzt bearbeitet 27.07.2026 19:09:14

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed...

  • EPSS 0.32%
  • Veröffentlicht 22.07.2026 11:21:38
  • Zuletzt bearbeitet 28.07.2026 18:17:25

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node to...

  • EPSS 0.31%
  • Veröffentlicht 22.07.2026 11:21:38
  • Zuletzt bearbeitet 27.07.2026 19:08:16

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of...

  • EPSS 0.33%
  • Veröffentlicht 22.07.2026 11:21:37
  • Zuletzt bearbeitet 27.07.2026 19:00:42

n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that...

  • EPSS 0.32%
  • Veröffentlicht 15.07.2026 11:25:35
  • Zuletzt bearbeitet 16.07.2026 20:08:36

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential...

  • EPSS 0.27%
  • Veröffentlicht 15.07.2026 11:25:34
  • Zuletzt bearbeitet 15.07.2026 18:20:21

n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by refe...

  • EPSS 0.23%
  • Veröffentlicht 15.07.2026 11:25:29
  • Zuletzt bearbeitet 16.07.2026 20:09:02

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat T...

  • EPSS 0.25%
  • Veröffentlicht 15.07.2026 11:25:28
  • Zuletzt bearbeitet 15.07.2026 18:20:21

n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the file-access checks enforced by other file-reading nodes. Although hidden from the...

  • EPSS 0.34%
  • Veröffentlicht 15.07.2026 11:25:27
  • Zuletzt bearbeitet 15.07.2026 18:20:21

n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflo...