n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 2.25.7之前版本和2.26.2之前版本存在会话机制问题漏洞,该漏洞源于会话机制问题,可能导致经过身份验证且有权限创建或修改工作流的用户污染Merge node的SQL Query模式使用的沙箱,通过沙箱环境上下文被缓存和重用,使得低权限攻击者能够拦截同实例上其他用户处理的工作流数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54314 | n8n: Denial of Service via ZIP decompression in webhook workflow | |
| CVE-2026-44791 | n8n: XML Node Prototype Pollution Patch Bypass | |
| CVE-2026-44789 | n8n: HTTP Request Node Pagination Prototype Pollution to RCE | |
| CVE-2026-44792 | n8n: Source Control Pull SQL Injection | |
| CVE-2026-44790 | n8n: Arbitrary File Read via Git Node | |
| CVE-2026-49444 | n8n: Python sandbox escape | |
| CVE-2026-49465 | n8n: Git Node Clone and Push Operations Bypass File Sandbox | |
| CVE-2026-54304 | n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host | |
| CVE-2026-54301 | n8n: Same-Origin XSS in Respond to Webhook Node | |
| CVE-2026-54310 | n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes | |
| CVE-2026-45732 | n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints | |
| CVE-2026-54302 | n8n: Stored XSS in Chat Trigger Node | |
| CVE-2026-54306 | n8n: Prototype Pollution enables confused-deputy execution via public webhooks | |
| CVE-2026-54313 | n8n: NoSQL Injection in MongoDB Node Find And Replace Operation | |
| CVE-2026-54303 | n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verificatio | |
| CVE-2026-54305 | n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints | |
| CVE-2026-54307 | n8n: Credential Exfiltration via Permission Bypass | |
| CVE-2026-54308 | n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node | |
| CVE-2026-54312 | n8n: Microsoft SQL Node Prototype Pollution | |
| CVE-2026-54309 | n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions |
No comments yet