n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 1.123.32之前版本、2.17.4之前版本和2.18.1之前版本存在跨站脚本漏洞,该漏洞源于未经身份验证的攻击者可注册恶意MCP OAuth客户端并包含特制client_name,可能导致受害者用户授权后第二个用户撤销访问时渲染注入脚本,点击链接执行任意JavaScript,实现凭据和会话令牌窃取、工作流操纵或权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42232 | n8n: XML Node Prototype Pollution to RCE | |
| CVE-2026-42233 | n8n: SQL Injection in Oracle Database Node via Limit Field | |
| CVE-2026-42229 | n8n: SQL Injection in SeaTable Node | |
| CVE-2026-42228 | n8n: Hijacking of Unauthenticated Chat Execution | |
| CVE-2026-42236 | n8n: Unauthenticated Denial of Service via MCP Client Registration | |
| CVE-2026-42237 | n8n: SQL Injection in Snowflake and MySQL Nodes | |
| CVE-2026-42226 | n8n: Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Rep | |
| CVE-2026-42230 | n8n: Open Redirect in MCP OAuth Consent Flow | |
| CVE-2026-42234 | n8n: Python Task Runner Sandbox Escape | |
| CVE-2026-42227 | n8n: Public API Variables IDOR Allows Cross-Project Secret Disclosure | |
| CVE-2026-42231 | n8n: Prototype Pollution in XML Webhook Body Parser Leads to RCE |
No comments yet