CVE-2026-65014
- EPSS 0.33%
- Veröffentlicht 22.07.2026 11:21:37
- Zuletzt bearbeitet 27.07.2026 19:00:42
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that...
CVE-2026-59259
- EPSS 0.32%
- Veröffentlicht 15.07.2026 11:25:35
- Zuletzt bearbeitet 16.07.2026 20:08:36
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential...
CVE-2026-59254
- EPSS 0.27%
- Veröffentlicht 15.07.2026 11:25:34
- Zuletzt bearbeitet 15.07.2026 18:20:21
n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by refe...
CVE-2026-56353
- EPSS 0.23%
- Veröffentlicht 15.07.2026 11:25:29
- Zuletzt bearbeitet 16.07.2026 20:09:02
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat T...
CVE-2026-56352
- EPSS 0.25%
- Veröffentlicht 15.07.2026 11:25:28
- Zuletzt bearbeitet 15.07.2026 18:20:21
n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the file-access checks enforced by other file-reading nodes. Although hidden from the...
CVE-2026-56349
- EPSS 0.34%
- Veröffentlicht 15.07.2026 11:25:27
- Zuletzt bearbeitet 15.07.2026 18:20:21
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflo...
CVE-2026-58661
- EPSS 0.23%
- Veröffentlicht 10.07.2026 13:58:01
- Zuletzt bearbeitet 13.07.2026 16:57:20
n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota check does not account for files already written to the shared temporary directory,...
CVE-2026-56354
- EPSS 0.17%
- Veröffentlicht 10.07.2026 13:57:57
- Zuletzt bearbeitet 13.07.2026 16:54:48
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authe...
CVE-2026-59209
- EPSS 0.3%
- Veröffentlicht 09.07.2026 15:32:27
- Zuletzt bearbeitet 13.07.2026 15:28:25
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTT...
CVE-2026-59206
- EPSS 0.38%
- Veröffentlicht 09.07.2026 15:30:28
- Zuletzt bearbeitet 09.07.2026 19:41:15
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via th...