n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n存在跨站脚本漏洞,该漏洞源于sanitize-html库配置不当,可能导致经过身份验证且具有创建或修改工作流权限的用户注入绕过清理的JavaScript,造成存储型跨站脚本。以下版本受到影响:1.123.27之前版本、2.0.0至2.13.2版本和2.14.0版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56350 | 6.3 MEDIUM | n8n - SSO Enforcement Bypass via API |
| CVE-2026-56777 | 5.0 MEDIUM | n8n - AST Validator Bypass in Python Code Node |
No comments yet