n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 2.28.1之前版本存在授权问题漏洞,该漏洞源于在工作流节点表达式中错误解析凭据范围外的外部秘密信息,可能导致已通过身份验证的项目编辑者通过引用节点表达式中的外部秘密值读取明文秘密值,而无需显式的秘密访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56352 | 6.4 MEDIUM | n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter |
| CVE-2026-56353 | 4.8 MEDIUM | n8n - Authentication Bypass in Chat Trigger Node |
| CVE-2026-59259 | n8n - Permission Bypass via Expression Parser Mismatch in External Secrets | |
| CVE-2026-56349 | n8n - Guardrail Node Bypass via Crafted Input |
No comments yet