N8n

N8n

193 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 08.09.2026 21:18:43
  • Zuletzt bearbeitet 10.09.2026 21:01:20

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, a...

  • EPSS 0.32%
  • Veröffentlicht 08.09.2026 21:17:38
  • Zuletzt bearbeitet 10.09.2026 20:57:05

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validatin...

  • EPSS 0.24%
  • Veröffentlicht 08.09.2026 21:15:38
  • Zuletzt bearbeitet 10.09.2026 20:54:58

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user abl...

  • EPSS 0.36%
  • Veröffentlicht 08.09.2026 18:21:14
  • Zuletzt bearbeitet 11.09.2026 18:20:24

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetc...

  • EPSS 0.32%
  • Veröffentlicht 08.09.2026 17:01:24
  • Zuletzt bearbeitet 11.09.2026 18:07:39

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the r...

  • EPSS 0.26%
  • Veröffentlicht 03.09.2026 11:22:21
  • Zuletzt bearbeitet 16.09.2026 21:21:54

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supp...

  • EPSS 0.37%
  • Veröffentlicht 03.09.2026 11:22:20
  • Zuletzt bearbeitet 16.09.2026 21:38:07

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper outside any ...

  • EPSS 0.25%
  • Veröffentlicht 03.09.2026 11:22:20
  • Zuletzt bearbeitet 16.09.2026 21:26:46

n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP client use...

  • EPSS 0.24%
  • Veröffentlicht 03.09.2026 11:22:19
  • Zuletzt bearbeitet 18.09.2026 14:42:49

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an o...

  • EPSS 0.39%
  • Veröffentlicht 03.09.2026 11:22:18
  • Zuletzt bearbeitet 18.09.2026 14:47:22

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; against a primiti...