CVE-2026-42232
- EPSS 0.48%
- Veröffentlicht 04.05.2026 18:34:11
- Zuletzt bearbeitet 06.05.2026 17:15:28
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when comb...
CVE-2026-42231
- EPSS 0.85%
- Veröffentlicht 04.05.2026 18:30:27
- Zuletzt bearbeitet 06.05.2026 17:14:03
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authe...
CVE-2026-42230
- EPSS 0.18%
- Veröffentlicht 04.05.2026 18:28:43
- Zuletzt bearbeitet 06.05.2026 14:57:11
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. ...
CVE-2026-42229
- EPSS 0.34%
- Veröffentlicht 04.05.2026 18:27:44
- Zuletzt bearbeitet 06.05.2026 14:56:49
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query strings witho...
CVE-2026-42228
- EPSS 0.38%
- Veröffentlicht 04.05.2026 18:27:06
- Zuletzt bearbeitet 06.05.2026 18:08:21
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact...
CVE-2026-42227
- EPSS 0.2%
- Veröffentlicht 04.05.2026 18:26:18
- Zuletzt bearbeitet 06.05.2026 18:08:47
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projects they are not a member of by supplying an arbitra...
CVE-2026-42226
- EPSS 0.26%
- Veröffentlicht 04.05.2026 18:26:08
- Zuletzt bearbeitet 06.05.2026 18:09:25
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An authenticated u...
CVE-2026-33751
- EPSS 0.25%
- Veröffentlicht 25.03.2026 18:47:39
- Zuletzt bearbeitet 27.03.2026 19:28:01
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacharacters to pass through unescaped when user-controlled input was interpolated into L...
- EPSS 0.25%
- Veröffentlicht 25.03.2026 18:39:54
- Zuletzt bearbeitet 27.03.2026 19:30:08
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows could craft a workflow that produces an HTML binary data object without a filename...
CVE-2026-33724
- EPSS 0.29%
- Veröffentlicht 25.03.2026 18:26:54
- Zuletzt bearbeitet 27.03.2026 19:32:03
n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command used for git operations explicitly disabled host key verification. A network attacker positioned bet...