n8n是n8n公司开源的一个可扩展的工作流自动化工具。 n8n 1.123.61之前版本、2.27.4版本之前和2.28.1版本之前存在授权问题漏洞,该漏洞源于外部秘密处理过程中静态验证检查与运行时表达式引擎之间的不匹配,导致权限绕过,允许具有凭证创建或更新权限但缺少externalSecret:list范围的认证用户,以静态验证无法检测的形式将外部秘密引用嵌入凭证中,这些引用在工作流执行时解析,暴露用户未授权访问的秘密值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56352 | 6.4 MEDIUM | n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter |
| CVE-2026-56353 | 4.8 MEDIUM | n8n - Authentication Bypass in Chat Trigger Node |
| CVE-2026-59254 | n8n - External Secrets Disclosure via Workflow Node Expressions | |
| CVE-2026-56349 | n8n - Guardrail Node Bypass via Crafted Input |
No comments yet