N8n

N8n

193 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 11:21:04
  • Zuletzt bearbeitet 01.09.2026 19:11:08

n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied ...

  • EPSS 0.21%
  • Veröffentlicht 11.08.2026 12:17:13
  • Zuletzt bearbeitet 03.09.2026 16:06:50

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An ...

  • EPSS 0.38%
  • Veröffentlicht 11.08.2026 12:17:12
  • Zuletzt bearbeitet 01.09.2026 20:19:41

n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the config...

  • EPSS 0.3%
  • Veröffentlicht 11.08.2026 12:17:12
  • Zuletzt bearbeitet 18.09.2026 19:44:53

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type vi...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 12:17:11
  • Zuletzt bearbeitet 18.09.2026 19:45:22

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email clai...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 12:17:10
  • Zuletzt bearbeitet 28.08.2026 18:32:54

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can...

  • EPSS 0.25%
  • Veröffentlicht 11.08.2026 12:17:09
  • Zuletzt bearbeitet 18.09.2026 19:46:21

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to ...

  • EPSS 0.47%
  • Veröffentlicht 11.08.2026 12:17:09
  • Zuletzt bearbeitet 01.09.2026 19:38:17

n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated users to bypass repository-path containment checks. Attackers with workflow create/execute rights ca...

  • EPSS 0.23%
  • Veröffentlicht 11.08.2026 12:17:08
  • Zuletzt bearbeitet 01.09.2026 20:19:31

n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocke...

  • EPSS 0.28%
  • Veröffentlicht 11.08.2026 12:17:07
  • Zuletzt bearbeitet 28.08.2026 18:31:55

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression...