N8n

N8n

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 23.06.2026 15:44:58
  • Zuletzt bearbeitet 26.06.2026 02:25:03

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Content-Type. The...

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 15:43:12
  • Zuletzt bearbeitet 26.06.2026 20:17:26

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object copying. These...

  • EPSS 0.28%
  • Veröffentlicht 23.06.2026 15:42:39
  • Zuletzt bearbeitet 26.06.2026 02:20:35

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL could submi...

  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 15:41:11
  • Zuletzt bearbeitet 25.06.2026 18:41:32

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox context was cac...

  • EPSS 0.39%
  • Veröffentlicht 23.06.2026 15:40:15
  • Zuletzt bearbeitet 25.06.2026 18:41:18

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitra...

  • EPSS 0.4%
  • Veröffentlicht 23.06.2026 15:36:13
  • Zuletzt bearbeitet 25.06.2026 18:40:16

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-...

  • EPSS 0.43%
  • Veröffentlicht 23.06.2026 15:33:52
  • Zuletzt bearbeitet 25.06.2026 18:42:34

n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated attacker could...

  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 15:33:10
  • Zuletzt bearbeitet 25.06.2026 18:41:59

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as the table par...

  • EPSS 0.18%
  • Veröffentlicht 23.06.2026 15:32:06
  • Zuletzt bearbeitet 25.06.2026 18:39:59

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabling reflect...

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 15:31:07
  • Zuletzt bearbeitet 25.06.2026 18:42:11

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before being pass...