n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n存在输入验证错误漏洞,该漏洞源于Python Code节点中存在抽象语法树(AST)安全验证器绕过问题,可能导致经过身份验证且具有创建或修改包含Python Code节点工作流权限的用户绕过验证器并访问任务执行器模块命名空间。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56350 | 6.3 MEDIUM | n8n - SSO Enforcement Bypass via API |
| CVE-2026-56356 | 5.4 MEDIUM | n8n - Stored Cross-Site Scripting in Chat Trigger Node Custom CSS Field |
No comments yet