n8n 在以下版本中存在漏洞:1.123.80 之前的版本、2.0.0 至 2.39.6 之间的版本,以及 2.40.0 至 2.40.1 之前的版本。这些版本未能正确验证 Webflow Trigger 节点 webhook 处理器中的 x-webflow-signature HMAC。未经身份验证的攻击者可以发送伪造的 webhook 请求,并携带由攻击者控制的载荷,从而触发工作流并操纵下游操作(例如创建记录或发起 API 调用)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103248 | 9.0 CRITICAL | n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase |
| CVE-2026-103255 | 9.0 CRITICAL | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase |
| CVE-2026-103253 | 8.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table |
| CVE-2026-103247 | 8.5 HIGH | n8n before 1.123.80 Credential Tampering via Duplicate Node IDs |
| CVE-2026-103250 | 8.1 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory |
| CVE-2026-103257 | 7.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node |
| CVE-2026-103246 | 7.7 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspecti |
| CVE-2026-103252 | 7.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential Test Endpoin |
| CVE-2026-103249 | 7.6 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator |
| CVE-2026-103259 | 7.6 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials |
| CVE-2026-103251 | 7.1 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub |
| CVE-2026-103256 | 7.1 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook |
| CVE-2026-103258 | 6.8 MEDIUM | n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation |
| CVE-2026-103254 | 6.3 MEDIUM | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation |
| CVE-2026-103260 | 4.0 MEDIUM | n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node |
No comments yet