CVE-2026-65597
- EPSS 0.21%
- Veröffentlicht 22.07.2026 11:21:44
- Zuletzt bearbeitet 27.07.2026 19:15:45
n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injec...
CVE-2026-65595
- EPSS 0.47%
- Veröffentlicht 22.07.2026 11:21:43
- Zuletzt bearbeitet 27.07.2026 19:14:35
n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privileged user who ...
CVE-2026-65593
- EPSS 0.14%
- Veröffentlicht 22.07.2026 11:21:42
- Zuletzt bearbeitet 27.07.2026 19:12:13
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to...
CVE-2026-65594
- EPSS 0.27%
- Veröffentlicht 22.07.2026 11:21:42
- Zuletzt bearbeitet 27.07.2026 19:13:07
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances...
CVE-2026-65592
- EPSS 0.17%
- Veröffentlicht 22.07.2026 11:21:41
- Zuletzt bearbeitet 27.07.2026 19:11:30
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker ...
CVE-2026-65590
- EPSS 0.32%
- Veröffentlicht 22.07.2026 11:21:40
- Zuletzt bearbeitet 27.07.2026 19:10:27
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or net...
CVE-2026-65591
- EPSS 0.47%
- Veröffentlicht 22.07.2026 11:21:40
- Zuletzt bearbeitet 27.07.2026 19:11:06
n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-lev...
CVE-2026-65589
- EPSS 0.37%
- Veröffentlicht 22.07.2026 11:21:39
- Zuletzt bearbeitet 27.07.2026 19:09:14
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed...
CVE-2026-65015
- EPSS 0.32%
- Veröffentlicht 22.07.2026 11:21:38
- Zuletzt bearbeitet 28.07.2026 18:17:25
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node to...
CVE-2026-65016
- EPSS 0.31%
- Veröffentlicht 22.07.2026 11:21:38
- Zuletzt bearbeitet 27.07.2026 19:08:16
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of...