n8n 在 2.39.6 之前以及 2.40.1 之前的版本中,存在一个审批绕过漏洞,该漏洞位于“发送并等待”(Send and Wait)节点的“在聊天中审批”(Approve Within Chat)模式。攻击者可以在未验证请求者身份或审批权限的情况下提交恢复(resume)请求,从而允许未经认证的用户推进处于等待状态的执行流程,并触发受保护的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103248 | 9.0 CRITICAL | n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase |
| CVE-2026-103255 | 9.0 CRITICAL | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase |
| CVE-2026-103253 | 8.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table |
| CVE-2026-103247 | 8.5 HIGH | n8n before 1.123.80 Credential Tampering via Duplicate Node IDs |
| CVE-2026-103250 | 8.1 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory |
| CVE-2026-103257 | 7.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node |
| CVE-2026-103246 | 7.7 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspecti |
| CVE-2026-103252 | 7.7 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential Test Endpoin |
| CVE-2026-103249 | 7.6 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator |
| CVE-2026-103259 | 7.6 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Credentials |
| CVE-2026-103251 | 7.1 HIGH | n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub |
| CVE-2026-103256 | 7.1 HIGH | n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook |
| CVE-2026-103258 | 6.8 MEDIUM | n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interpolation |
| CVE-2026-103254 | 6.3 MEDIUM | n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation |
| CVE-2026-103245 | 5.3 MEDIUM | n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification |
No comments yet