n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 2.10.1之前版本、2.9.3之前版本和1.123.22之前版本存在安全漏洞,该漏洞源于具有权限的认证用户可在不同节点上注入任意脚本,可能导致会话劫持和账户接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27577 | 9.4 CRITICAL | n8n: Expression Sandbox Escape Leads to RCE |
| CVE-2026-27495 | n8n has a Sandbox Escape in its JavaScript Task Runner | |
| CVE-2026-27493 | n8n has Unauthenticated Expression Evaluation via Form Node | |
| CVE-2026-27494 | n8n has Arbitrary File Read via Python Code Node Sandbox Escape | |
| CVE-2026-27497 | n8n has Potential Remote Code Execution via Merge Node | |
| CVE-2026-27498 | n8n has Arbitrary Command Execution via File Write and Git Operations |
No comments yet