N8n

N8n

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.63%
  • Veröffentlicht 23.06.2026 15:54:17
  • Zuletzt bearbeitet 24.06.2026 13:57:35

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, ...

  • EPSS 0.65%
  • Veröffentlicht 23.06.2026 15:53:13
  • Zuletzt bearbeitet 24.06.2026 13:54:08

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitr...

  • EPSS 0.88%
  • Veröffentlicht 23.06.2026 15:52:45
  • Zuletzt bearbeitet 24.06.2026 15:16:40

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTT...

  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 15:52:19
  • Zuletzt bearbeitet 26.06.2026 20:17:13

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-onl...

  • EPSS 0.36%
  • Veröffentlicht 23.06.2026 15:50:31
  • Zuletzt bearbeitet 26.06.2026 02:23:24

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution...

  • EPSS 0.5%
  • Veröffentlicht 23.06.2026 15:49:46
  • Zuletzt bearbeitet 26.06.2026 02:23:34

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's Clone opera...

  • EPSS 0.35%
  • Veröffentlicht 23.06.2026 15:48:44
  • Zuletzt bearbeitet 26.06.2026 02:24:52

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure t...

  • EPSS 0.35%
  • Veröffentlicht 23.06.2026 15:47:25
  • Zuletzt bearbeitet 26.06.2026 02:20:12

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership...

  • EPSS 0.21%
  • Veröffentlicht 23.06.2026 15:46:21
  • Zuletzt bearbeitet 26.06.2026 02:24:34

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webhookId. When...

Medienbericht
  • EPSS 0.43%
  • Veröffentlicht 23.06.2026 15:45:52
  • Zuletzt bearbeitet 26.06.2026 02:24:03

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on ...