n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 1.123.55之前版本、2.25.7之前版本和2.26.2之前版本存在授权问题漏洞,该漏洞源于在三个改变状态的评估测试运行端点中,使用workflow:read范围而非workflow:execute范围进行授权,导致具有项目查看者角色的用户能够对仅具有读取权限的工作流启动新的评估测试运行、取消正在进行的运行以及删除运行记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56776 | 7.4 HIGH | n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint |
| CVE-2026-56778 | 6.4 MEDIUM | n8n - Authorization Bypass in Public API Execution Retry Endpoint |
| CVE-2026-56359 | 5.4 MEDIUM | n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL |
| CVE-2026-56360 | 4.0 MEDIUM | n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger |
| CVE-2026-59253 | n8n - Improper Authorization in Workflow Assignment to Folders | |
| CVE-2026-59257 | n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation |
No comments yet