n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 2.10.1之前版本、2.9.3之前版本和1.123.22之前版本存在代码注入漏洞,该漏洞源于具有权限的认证用户可利用Merge节点的SQL查询模式,可能导致执行任意代码和写入任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27577 | 9.4 CRITICAL | n8n: Expression Sandbox Escape Leads to RCE |
| CVE-2026-27495 | n8n has a Sandbox Escape in its JavaScript Task Runner | |
| CVE-2026-27493 | n8n has Unauthenticated Expression Evaluation via Form Node | |
| CVE-2026-27494 | n8n has Arbitrary File Read via Python Code Node Sandbox Escape | |
| CVE-2026-27578 | n8n Vulnerable to Stored XSS via Various Nodes | |
| CVE-2026-27498 | n8n has Arbitrary Command Execution via File Write and Git Operations |
No comments yet