n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 1.0.0版本至2.0.0之前版本存在安全漏洞,该漏洞源于Python Code Node存在沙箱绕过问题,可能导致执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/Threekiii/Awesome-POC/blob/master/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/n8n%20Pyodide%20%E6%B2%99%E7%AE%B1%E9%80%83%E9%80%B8%E5%AF%BC%E8%87%B4%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2025-68668.md | POC Details |
| 2 | This project was built during the Cryptonic Area Cybersecurity Virtual Internship Program. This is a study of a n8n vulnerability (CVE-2025-68668) | https://github.com/eshan014/Internship_project_02 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-61914 | 7.3 HIGH | n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox |
| CVE-2025-68697 | 7.1 HIGH | Self-hosted n8n has Legacy Code node that enables arbitrary file read/write |
No comments yet