CVE-2025-55526
- EPSS 0.76%
- Veröffentlicht 26.08.2025 00:00:00
- Zuletzt bearbeitet 15.09.2025 19:38:14
n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
CVE-2025-57749
- EPSS 0.45%
- Veröffentlicht 20.08.2025 21:46:39
- Zuletzt bearbeitet 03.09.2025 15:07:16
n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly account fo...
CVE-2025-52478
- EPSS 0.35%
- Veröffentlicht 19.08.2025 16:32:34
- Zuletzt bearbeitet 03.09.2025 15:12:04
n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifically in the Form Trigger node's HTML form element. An authenticated attacker can inject malicious HT...
CVE-2025-52554
- EPSS 0.27%
- Veröffentlicht 03.07.2025 20:15:23
- Zuletzt bearbeitet 04.09.2025 16:53:45
n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow executions that they do not own or that have not b...
CVE-2025-49595
- EPSS 0.38%
- Veröffentlicht 03.07.2025 12:16:47
- Zuletzt bearbeitet 04.09.2025 16:49:06
n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or filesystem-v2://). This allows authenticated attackers to...
CVE-2025-49592
- EPSS 0.19%
- Veröffentlicht 26.06.2025 19:45:27
- Zuletzt bearbeitet 02.09.2025 17:52:02
n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains after logging in, by crafting malicious URLs with a...
CVE-2025-46343
- EPSS 0.21%
- Veröffentlicht 29.04.2025 04:35:16
- Zuletzt bearbeitet 09.05.2025 19:37:16
n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary files, which are accessible to authenticated users....
CVE-2023-27564
- EPSS 1.21%
- Veröffentlicht 10.05.2023 15:15:09
- Zuletzt bearbeitet 27.01.2025 21:15:09
The n8n package 0.218.0 for Node.js allows Information Disclosure.
CVE-2023-27563
- EPSS 1.22%
- Veröffentlicht 10.05.2023 15:15:09
- Zuletzt bearbeitet 27.01.2025 22:15:10
The n8n package 0.218.0 for Node.js allows Escalation of Privileges.
CVE-2023-27562
- EPSS 2.32%
- Veröffentlicht 10.05.2023 15:15:08
- Zuletzt bearbeitet 27.01.2025 22:15:10
The n8n package 0.218.0 for Node.js allows Directory Traversal.