CVE-2026-25115
- EPSS 0.06%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:44:21
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. Thi...
CVE-2026-25056
- EPSS 0.17%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:42:20
n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files to the n8n ...
CVE-2026-25055
- EPSS 0.16%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:41:47
n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating their metadata the vulnerability can lead to files...
CVE-2026-25054
- EPSS 0.01%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:39:47
n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface, including workflow sticky notes and other areas tha...
CVE-2026-25053
- EPSS 0.02%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:32:37
n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or read arbitrary...
CVE-2026-25052
- EPSS 0.02%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:32:11
n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host s...
CVE-2026-25051
- EPSS 0.01%
- Veröffentlicht 04.02.2026 17:16:22
- Zuletzt bearbeitet 05.02.2026 20:23:13
n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP endpoints. Under certain conditions, the Content Securi...
CVE-2026-25049
- EPSS 0.04%
- Veröffentlicht 04.02.2026 17:16:22
- Zuletzt bearbeitet 05.02.2026 20:22:47
n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command ...
CVE-2025-61917
- EPSS 0.02%
- Veröffentlicht 04.02.2026 17:16:08
- Zuletzt bearbeitet 18.02.2026 17:46:40
n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buf...
CVE-2026-1470
- EPSS 0.58%
- Veröffentlicht 27.01.2026 14:23:53
- Zuletzt bearbeitet 20.02.2026 13:44:27
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficientl...