n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 2.10.0之前版本存在输入验证错误漏洞,该漏洞源于Guardrail节点输入验证不足,可能导致攻击者绕过默认防护指令,最终用户可制作恶意输入绕过防护并破坏工作流完整性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56352 | 6.4 MEDIUM | n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter |
| CVE-2026-56353 | 4.8 MEDIUM | n8n - Authentication Bypass in Chat Trigger Node |
| CVE-2026-59259 | n8n - Permission Bypass via Expression Parser Mismatch in External Secrets | |
| CVE-2026-59254 | n8n - External Secrets Disclosure via Workflow Node Expressions |
No comments yet