n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 2.2.0之前版本和1.123.8之前版本存在代码注入漏洞,该漏洞源于具有权限的认证用户可链式利用Read/Write Files from Disk节点与git操作,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27577 | 9.4 CRITICAL | n8n: Expression Sandbox Escape Leads to RCE |
| CVE-2026-27495 | n8n has a Sandbox Escape in its JavaScript Task Runner | |
| CVE-2026-27493 | n8n has Unauthenticated Expression Evaluation via Form Node | |
| CVE-2026-27494 | n8n has Arbitrary File Read via Python Code Node Sandbox Escape | |
| CVE-2026-27497 | n8n has Potential Remote Code Execution via Merge Node | |
| CVE-2026-27578 | n8n Vulnerable to Stored XSS via Various Nodes |
No comments yet