n8n 在 2.35.4 之前以及 2.36.x 中 2.36.2 之前存在一个查询注入漏洞,该漏洞位于“Elasticsearch 获取所有文档”和“Google Cloud Firestore 查询文档”操作中。这些操作在解析之前,会将表达式值直接插入到查询字符串中以构建 JSON 查询。如果某个值包含引号和花括号字符,就可能闭合预期的字段并引入新的查询运算符,从而将原本的单文档查询变为对整个集合的读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85169 | 8.7 HIGH | n8n before 1.123.73 Remote Code Execution via $fromAI Prototype Leak |
| CVE-2026-85168 | 7.7 HIGH | n8n before 1.123.73 Remote Code Execution via Git Node |
| CVE-2026-85165 | 7.2 HIGH | n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement |
| CVE-2026-85166 | 7.2 HIGH | n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node |
| CVE-2026-85171 | 7.1 HIGH | n8n before 1.123.73 Credential Exposure via Error Logging |
| CVE-2026-85170 | 7.1 HIGH | n8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodes |
| CVE-2026-85172 | 5.3 MEDIUM | n8n before 2.34.1 SSRF via Request Helper URI Validation Bypass |
| CVE-2026-85173 | 5.3 MEDIUM | n8n before 2.36.2 Missing Authorization via Insights API |
No comments yet