n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n存在SQL注入漏洞,该漏洞源于legacy MySQL v1节点executeQuery操作中未对表达式值进行参数化,直接将评估后的{{ ... }}表达式值替换到原始SQL字符串中,当工作流使用此操作并连接外部可访问触发器(如Webhook节点)时,攻击者控制的输入可导致SQL注入,从而使用配置的MySQL凭据权限执行任意SQL。以下版本受到影响:1.123.61之前版本、2.27.4之前版本和2.28.1之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56776 | 7.4 HIGH | n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint |
| CVE-2026-56778 | 6.4 MEDIUM | n8n - Authorization Bypass in Public API Execution Retry Endpoint |
| CVE-2026-56359 | 5.4 MEDIUM | n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL |
| CVE-2026-56775 | 5.4 MEDIUM | n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints |
| CVE-2026-56360 | 4.0 MEDIUM | n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger |
| CVE-2026-59253 | n8n - Improper Authorization in Workflow Assignment to Folders |
No comments yet