CVE-2026-27577
- EPSS 10.16%
- Veröffentlicht 25.02.2026 22:19:44
- Zuletzt bearbeitet 04.03.2026 14:00:14
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user with permissio...
CVE-2026-27497
- EPSS 0.77%
- Veröffentlicht 25.02.2026 22:16:08
- Zuletzt bearbeitet 04.03.2026 03:35:58
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code and write ...
CVE-2026-27495
- EPSS 0.6%
- Veröffentlicht 25.02.2026 22:10:04
- Zuletzt bearbeitet 04.03.2026 03:41:31
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in the JavaScript Task Runner sandbox to execute arbi...
CVE-2026-27494
- EPSS 0.35%
- Veröffentlicht 25.02.2026 22:08:00
- Zuletzt bearbeitet 05.03.2026 16:22:42
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could use the Python Code node to escape the sandbox. The sandbox did not sufficien...
- EPSS 1.07%
- Veröffentlicht 25.02.2026 22:05:00
- Zuletzt bearbeitet 05.03.2026 16:29:28
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and evaluate arbit...
CVE-2026-25631
- EPSS 0.28%
- Veröffentlicht 06.02.2026 20:34:53
- Zuletzt bearbeitet 19.02.2026 17:51:02
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domains, potentia...
CVE-2026-21893
- EPSS 1.34%
- Veröffentlicht 04.02.2026 17:36:51
- Zuletzt bearbeitet 20.02.2026 17:07:21
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrat...
CVE-2026-25115
- EPSS 0.53%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:44:21
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. Thi...
CVE-2026-25056
- EPSS 0.66%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:42:20
n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files to the n8n ...
CVE-2026-25055
- EPSS 1.71%
- Veröffentlicht 04.02.2026 17:16:23
- Zuletzt bearbeitet 05.02.2026 20:41:47
n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating their metadata the vulnerability can lead to files...