CVE-2026-33696
- EPSS 0.77%
- Veröffentlicht 25.03.2026 17:40:39
- Zuletzt bearbeitet 27.03.2026 19:40:55
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin n...
CVE-2026-33665
- EPSS 0.32%
- Veröffentlicht 25.03.2026 17:32:20
- Zuletzt bearbeitet 30.03.2026 14:23:59
n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if the LDAP email attribute matched the local account...
CVE-2026-33663
- EPSS 0.39%
- Veröffentlicht 25.03.2026 17:11:09
- Zuletzt bearbeitet 31.03.2026 16:39:13
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit chained authorization flaws in n8n's credential pipeline to steal plaintext secrets ...
CVE-2026-33660
- EPSS 0.95%
- Veröffentlicht 25.03.2026 17:09:09
- Zuletzt bearbeitet 30.03.2026 14:54:07
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n ho...
CVE-2026-27496
- EPSS 0.26%
- Veröffentlicht 25.03.2026 17:07:06
- Zuletzt bearbeitet 27.03.2026 19:48:33
n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory buffers. Unin...
CVE-2026-27498
- EPSS 0.72%
- Veröffentlicht 25.02.2026 22:42:21
- Zuletzt bearbeitet 04.03.2026 03:33:32
n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk node with git operations to achieve remote code ex...
CVE-2026-27578
- EPSS 0.19%
- Veröffentlicht 25.02.2026 22:40:38
- Zuletzt bearbeitet 04.03.2026 03:24:40
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could inject arbitrary scripts into pages rendered by the n8n application using dif...
CVE-2026-27577
- EPSS 8.59%
- Veröffentlicht 25.02.2026 22:19:44
- Zuletzt bearbeitet 28.07.2026 05:17:04
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user with permissio...
CVE-2026-27497
- EPSS 0.77%
- Veröffentlicht 25.02.2026 22:16:08
- Zuletzt bearbeitet 04.03.2026 03:35:58
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code and write ...
CVE-2026-27495
- EPSS 0.73%
- Veröffentlicht 25.02.2026 22:10:04
- Zuletzt bearbeitet 04.03.2026 03:41:31
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in the JavaScript Task Runner sandbox to execute arbi...