CVE-2026-56776
- EPSS 0.16%
- Veröffentlicht 08.07.2026 13:49:06
- Zuletzt bearbeitet 09.07.2026 16:16:45
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-on...
CVE-2026-56360
- EPSS 0.19%
- Veröffentlicht 08.07.2026 13:49:03
- Zuletzt bearbeitet 08.07.2026 19:32:49
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
CVE-2026-56359
- EPSS 0.14%
- Veröffentlicht 08.07.2026 13:49:02
- Zuletzt bearbeitet 09.07.2026 15:16:38
n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials...
CVE-2025-71380
- EPSS 0.41%
- Veröffentlicht 04.07.2026 01:23:42
- Zuletzt bearbeitet 06.07.2026 19:01:14
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to ...
CVE-2026-56777
- EPSS 0.25%
- Veröffentlicht 30.06.2026 22:08:41
- Zuletzt bearbeitet 02.07.2026 19:39:01
n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the vali...
CVE-2026-56356
- EPSS 0.18%
- Veröffentlicht 30.06.2026 22:08:35
- Zuletzt bearbeitet 02.07.2026 19:38:43
n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed...
CVE-2026-56350
- EPSS 0.28%
- Veröffentlicht 30.06.2026 22:08:34
- Zuletzt bearbeitet 02.07.2026 19:38:20
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO polic...
CVE-2026-56351
- EPSS 0.21%
- Veröffentlicht 24.06.2026 11:53:19
- Zuletzt bearbeitet 26.06.2026 02:01:57
n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with...
CVE-2026-56358
- EPSS 0.14%
- Veröffentlicht 24.06.2026 11:53:19
- Zuletzt bearbeitet 26.06.2026 02:02:10
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Att...
- EPSS 0.33%
- Veröffentlicht 23.06.2026 15:55:30
- Zuletzt bearbeitet 24.06.2026 13:55:55
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a...