CVE-2026-85167
- EPSS 0.24%
- Veröffentlicht 03.09.2026 11:22:17
- Zuletzt bearbeitet 10.09.2026 19:53:08
n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression values directly in...
CVE-2026-85168
- EPSS 0.37%
- Veröffentlicht 03.09.2026 11:22:17
- Zuletzt bearbeitet 16.09.2026 21:41:59
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter an...
CVE-2026-85166
- EPSS 0.22%
- Veröffentlicht 03.09.2026 11:22:16
- Zuletzt bearbeitet 10.09.2026 19:54:12
n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/updating a work...
CVE-2026-85165
- EPSS 0.26%
- Veröffentlicht 03.09.2026 11:22:15
- Zuletzt bearbeitet 10.09.2026 19:55:37
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission...
CVE-2026-77084
- EPSS -
- Veröffentlicht 20.08.2026 11:21:15
- Zuletzt bearbeitet 01.09.2026 19:50:06
n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation agai...
CVE-2026-77085
- EPSS -
- Veröffentlicht 20.08.2026 11:21:15
- Zuletzt bearbeitet 01.09.2026 19:10:43
n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API URL using a raw HTTP client that did not route through n8n's centralized SSRF protection. On inst...
CVE-2026-77083
- EPSS -
- Veröffentlicht 20.08.2026 11:21:14
- Zuletzt bearbeitet 01.09.2026 19:49:07
n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute wor...
CVE-2026-77081
- EPSS -
- Veröffentlicht 20.08.2026 11:21:13
- Zuletzt bearbeitet 01.09.2026 19:47:02
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is treated as acti...
CVE-2026-77082
- EPSS -
- Veröffentlicht 20.08.2026 11:21:13
- Zuletzt bearbeitet 01.09.2026 19:47:33
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synch...
CVE-2026-77080
- EPSS -
- Veröffentlicht 20.08.2026 11:21:12
- Zuletzt bearbeitet 01.09.2026 19:45:49
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK w...