CVE-2026-72767
- EPSS 0.39%
- Veröffentlicht 11.08.2026 12:17:07
- Zuletzt bearbeitet 18.09.2026 19:46:49
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to ru...
CVE-2026-72765
- EPSS 0.37%
- Veröffentlicht 11.08.2026 12:17:06
- Zuletzt bearbeitet 01.09.2026 20:19:04
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbo...
CVE-2026-72764
- EPSS 0.37%
- Veröffentlicht 11.08.2026 12:17:05
- Zuletzt bearbeitet 18.09.2026 19:47:30
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' C...
CVE-2026-72762
- EPSS 0.2%
- Veröffentlicht 11.08.2026 12:17:04
- Zuletzt bearbeitet 18.09.2026 19:47:49
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run work...
CVE-2026-72763
- EPSS 0.22%
- Veröffentlicht 11.08.2026 12:17:04
- Zuletzt bearbeitet 01.09.2026 20:18:51
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with Editor access to a shared workflo...
CVE-2026-72750
- EPSS 0.21%
- Veröffentlicht 11.08.2026 12:17:03
- Zuletzt bearbeitet 28.08.2026 18:30:42
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-con...
CVE-2026-72749
- EPSS 0.31%
- Veröffentlicht 11.08.2026 12:17:02
- Zuletzt bearbeitet 01.09.2026 20:18:33
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated user to na...
CVE-2026-65599
- EPSS 0.15%
- Veröffentlicht 22.07.2026 11:21:46
- Zuletzt bearbeitet 27.07.2026 19:18:25
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only for a key ide...
CVE-2026-65598
- EPSS 0.24%
- Veröffentlicht 22.07.2026 11:21:45
- Zuletzt bearbeitet 27.07.2026 19:18:06
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the cl...
CVE-2026-65596
- EPSS 0.21%
- Veröffentlicht 22.07.2026 11:21:44
- Zuletzt bearbeitet 27.07.2026 19:15:28
n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user ab...