n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 2.19.3之前版本存在路径遍历漏洞,该漏洞源于旧ExecuteWorkflow节点的localFile source选项存在文件路径限制绕过问题,它从磁盘读取工作流文件时没有其他文件读取节点强制执行的访问检查。尽管自v1.2起用户界面已隐藏此选项,但仍可通过REST API访问。经过身份验证并拥有创建或修改工作流权限的用户可以提供任意文件路径来绕过N8N_RESTRICT_FILE_ACCESS_TO限制,从而确认主机上是否存在任意文件;若
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56353 | 4.8 MEDIUM | n8n - Authentication Bypass in Chat Trigger Node |
| CVE-2026-59259 | n8n - Permission Bypass via Expression Parser Mismatch in External Secrets | |
| CVE-2026-59254 | n8n - External Secrets Disclosure via Workflow Node Expressions | |
| CVE-2026-56349 | n8n - Guardrail Node Bypass via Crafted Input |
No comments yet