CVE-2026-77068
- EPSS -
- Veröffentlicht 20.08.2026 11:21:04
- Zuletzt bearbeitet 01.09.2026 19:11:08
n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied ...
CVE-2026-72775
- EPSS 0.21%
- Veröffentlicht 11.08.2026 12:17:13
- Zuletzt bearbeitet 03.09.2026 16:06:50
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An ...
CVE-2026-72773
- EPSS 0.38%
- Veröffentlicht 11.08.2026 12:17:12
- Zuletzt bearbeitet 01.09.2026 20:19:41
n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the config...
CVE-2026-72774
- EPSS 0.3%
- Veröffentlicht 11.08.2026 12:17:12
- Zuletzt bearbeitet 18.09.2026 19:44:53
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type vi...
CVE-2026-72772
- EPSS 0.22%
- Veröffentlicht 11.08.2026 12:17:11
- Zuletzt bearbeitet 18.09.2026 19:45:22
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email clai...
CVE-2026-72771
- EPSS 0.22%
- Veröffentlicht 11.08.2026 12:17:10
- Zuletzt bearbeitet 28.08.2026 18:32:54
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can...
CVE-2026-72769
- EPSS 0.25%
- Veröffentlicht 11.08.2026 12:17:09
- Zuletzt bearbeitet 18.09.2026 19:46:21
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to ...
CVE-2026-72770
- EPSS 0.47%
- Veröffentlicht 11.08.2026 12:17:09
- Zuletzt bearbeitet 01.09.2026 19:38:17
n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated users to bypass repository-path containment checks. Attackers with workflow create/execute rights ca...
CVE-2026-72768
- EPSS 0.23%
- Veröffentlicht 11.08.2026 12:17:08
- Zuletzt bearbeitet 01.09.2026 20:19:31
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocke...
CVE-2026-72766
- EPSS 0.28%
- Veröffentlicht 11.08.2026 12:17:07
- Zuletzt bearbeitet 28.08.2026 18:31:55
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression...