CVE-2026-56357
- EPSS 0.19%
- Veröffentlicht 22.06.2026 21:04:52
- Zuletzt bearbeitet 24.06.2026 16:47:01
n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workfl...
CVE-2026-56348
- EPSS 0.26%
- Veröffentlicht 22.06.2026 21:04:51
- Zuletzt bearbeitet 24.06.2026 16:46:14
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can ca...
CVE-2026-42237
- EPSS 0.25%
- Veröffentlicht 04.05.2026 18:39:56
- Zuletzt bearbeitet 06.05.2026 17:16:17
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolati...
CVE-2026-42236
- EPSS 0.49%
- Veröffentlicht 04.05.2026 18:38:51
- Zuletzt bearbeitet 06.05.2026 17:16:02
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthentic...
CVE-2026-42235
- EPSS 0.33%
- Veröffentlicht 04.05.2026 18:38:09
- Zuletzt bearbeitet 06.05.2026 18:05:44
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dial...
CVE-2026-42234
- EPSS 0.38%
- Veröffentlicht 04.05.2026 18:36:55
- Zuletzt bearbeitet 06.05.2026 18:05:52
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code ...
CVE-2026-42233
- EPSS 0.33%
- Veröffentlicht 04.05.2026 18:35:42
- Zuletzt bearbeitet 06.05.2026 18:07:22
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated dir...
CVE-2026-42232
- EPSS 0.48%
- Veröffentlicht 04.05.2026 18:34:11
- Zuletzt bearbeitet 06.05.2026 17:15:28
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when comb...
CVE-2026-42231
- EPSS 0.85%
- Veröffentlicht 04.05.2026 18:30:27
- Zuletzt bearbeitet 06.05.2026 17:14:03
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authe...
CVE-2026-42230
- EPSS 0.18%
- Veröffentlicht 04.05.2026 18:28:43
- Zuletzt bearbeitet 06.05.2026 14:57:11
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. ...