n8n 在以下版本中存在授权绕过漏洞:1.123.80 之前的版本、2.0.0 至 2.39.6 之间的版本,以及 2.40.0 至 2.40.1 之前的版本。该漏洞存在于凭据测试端点中,系统在解析项目作用域变量时未验证调用者的访问权限。攻击者可在请求体中指定任意的项目 ID,从而将敏感变量插值到发送至攻击者控制主机的凭据测试请求中,进而实现数据外泄。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103248 | 9.0 CRITICAL | n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase |
| CVE-2026-103255 | 9.0 CRITICAL | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase |
| CVE-2026-103253 | 8.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table |
| CVE-2026-103247 | 8.5 HIGH | n8n before 1.123.80 Credential Tampering via Duplicate Node IDs |
| CVE-2026-103250 | 8.1 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory |
| CVE-2026-103257 | 7.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node |
| CVE-2026-103246 | 7.7 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspecti |
| CVE-2026-103249 | 7.6 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator |
| CVE-2026-103259 | 7.6 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials |
| CVE-2026-103251 | 7.1 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub |
| CVE-2026-103256 | 7.1 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook |
| CVE-2026-103258 | 6.8 MEDIUM | n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation |
| CVE-2026-103254 | 6.3 MEDIUM | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation |
| CVE-2026-103245 | 5.3 MEDIUM | n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification |
| CVE-2026-103260 | 4.0 MEDIUM | n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait Node |
No comments yet