N8n

N8n

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 10.07.2026 13:58:01
  • Zuletzt bearbeitet 13.07.2026 16:57:20

n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota check does not account for files already written to the shared temporary directory,...

  • EPSS 0.17%
  • Veröffentlicht 10.07.2026 13:57:57
  • Zuletzt bearbeitet 13.07.2026 16:54:48

n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authe...

  • EPSS 0.3%
  • Veröffentlicht 09.07.2026 15:32:27
  • Zuletzt bearbeitet 13.07.2026 15:28:25

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTT...

  • EPSS 0.38%
  • Veröffentlicht 09.07.2026 15:30:28
  • Zuletzt bearbeitet 09.07.2026 19:41:15

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via th...

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 09.07.2026 15:27:28
  • Zuletzt bearbeitet 14.07.2026 01:16:18

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim...

  • EPSS 0.26%
  • Veröffentlicht 09.07.2026 15:16:36
  • Zuletzt bearbeitet 09.07.2026 19:37:19

n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a ...

  • EPSS 0.31%
  • Veröffentlicht 08.07.2026 13:49:13
  • Zuletzt bearbeitet 09.07.2026 15:16:39

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the raw SQL st...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 13:49:12
  • Zuletzt bearbeitet 08.07.2026 19:25:45

n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request payloads d...

  • EPSS 0.17%
  • Veröffentlicht 08.07.2026 13:49:07
  • Zuletzt bearbeitet 08.07.2026 19:26:35

n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only access to ...

  • EPSS 0.18%
  • Veröffentlicht 08.07.2026 13:49:06
  • Zuletzt bearbeitet 08.07.2026 19:31:35

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:execute sco...