CVE-2026-77079
- EPSS -
- Veröffentlicht 20.08.2026 11:21:11
- Zuletzt bearbeitet 01.09.2026 19:45:02
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was projec...
CVE-2026-77076
- EPSS -
- Veröffentlicht 20.08.2026 11:21:10
- Zuletzt bearbeitet 01.09.2026 19:44:08
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the node re-throws the underlying HTTP client error unchanged instead of wrapp...
CVE-2026-77077
- EPSS -
- Veröffentlicht 20.08.2026 11:21:10
- Zuletzt bearbeitet 01.09.2026 19:44:33
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constructors such as EventEmitter, allowing an authentica...
CVE-2026-77075
- EPSS -
- Veröffentlicht 20.08.2026 11:21:09
- Zuletzt bearbeitet 01.09.2026 19:43:06
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the field's stored value directly into the node type's URL template wi...
CVE-2026-77073
- EPSS -
- Veröffentlicht 20.08.2026 11:21:08
- Zuletzt bearbeitet 01.09.2026 19:14:15
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persis...
CVE-2026-77074
- EPSS -
- Veröffentlicht 20.08.2026 11:21:08
- Zuletzt bearbeitet 01.09.2026 19:34:40
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound ...
CVE-2026-77072
- EPSS -
- Veröffentlicht 20.08.2026 11:21:07
- Zuletzt bearbeitet 01.09.2026 20:01:10
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page applied its sandboxing Content-Security-Policy only when respondWith was not set to 'redirect', but r...
CVE-2026-77070
- EPSS -
- Veröffentlicht 20.08.2026 11:21:06
- Zuletzt bearbeitet 01.09.2026 20:01:22
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. A...
CVE-2026-77071
- EPSS -
- Veröffentlicht 20.08.2026 11:21:06
- Zuletzt bearbeitet 01.09.2026 20:01:06
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping....
CVE-2026-77069
- EPSS -
- Veröffentlicht 20.08.2026 11:21:05
- Zuletzt bearbeitet 01.09.2026 20:01:16
n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-access-token exchange. While OAuth2 discovery and dynamic-client-registration requests use n8n's SSRF-protected HTTP client, the...