N8n

N8n

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 25.03.2026 18:09:37
  • Zuletzt bearbeitet 27.03.2026 19:34:18

n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plaintext value...

  • EPSS 0.18%
  • Veröffentlicht 25.03.2026 18:06:38
  • Zuletzt bearbeitet 27.03.2026 19:38:03

n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` environment variable is set to `true`, the OAuth callback handler skips ownership verification of the OAuth state parameter. This a...

  • EPSS 0.42%
  • Veröffentlicht 25.03.2026 17:47:44
  • Zuletzt bearbeitet 27.03.2026 19:39:36

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection vulnerability in the Data Table Get node. On default...

Medienbericht
  • EPSS 0.77%
  • Veröffentlicht 25.03.2026 17:40:39
  • Zuletzt bearbeitet 27.03.2026 19:40:55

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin n...

  • EPSS 0.32%
  • Veröffentlicht 25.03.2026 17:32:20
  • Zuletzt bearbeitet 30.03.2026 14:23:59

n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if the LDAP email attribute matched the local account...

Medienbericht
  • EPSS 0.39%
  • Veröffentlicht 25.03.2026 17:11:09
  • Zuletzt bearbeitet 31.03.2026 16:39:13

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit chained authorization flaws in n8n's credential pipeline to steal plaintext secrets ...

Medienbericht
  • EPSS 0.95%
  • Veröffentlicht 25.03.2026 17:09:09
  • Zuletzt bearbeitet 30.03.2026 14:54:07

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n ho...

  • EPSS 0.26%
  • Veröffentlicht 25.03.2026 17:07:06
  • Zuletzt bearbeitet 27.03.2026 19:48:33

n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory buffers. Unin...

  • EPSS 0.72%
  • Veröffentlicht 25.02.2026 22:42:21
  • Zuletzt bearbeitet 04.03.2026 03:33:32

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk node with git operations to achieve remote code ex...

Medienbericht
  • EPSS 0.19%
  • Veröffentlicht 25.02.2026 22:40:38
  • Zuletzt bearbeitet 04.03.2026 03:24:40

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could inject arbitrary scripts into pages rendered by the n8n application using dif...