在 n8n 1.123.73、2.35.4 和 2.36.2 之前的版本中,Gmail(v1)和 Brevo 节点在将消息内容传递给邮件编辑器时,未验证其是否为字符串类型。能够执行工作流的认证用户可以提供一个表达式,该表达式解析为包含 或 属性的对象,从而导致邮件编辑器读取 n8n 进程可访问的本地文件,或获取内部 URL(SSRF,即服务端请求伪造),并将结果附加到即将发送的消息中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85169 | 8.7 HIGH | n8n before 1.123.73 Remote Code Execution via $fromAI Prototype Leak |
| CVE-2026-85168 | 7.7 HIGH | n8n before 1.123.73 Remote Code Execution via Git Node |
| CVE-2026-85165 | 7.2 HIGH | n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement |
| CVE-2026-85166 | 7.2 HIGH | n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node |
| CVE-2026-85171 | 7.1 HIGH | n8n before 1.123.73 Credential Exposure via Error Logging |
| CVE-2026-85167 | 6.3 MEDIUM | n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes |
| CVE-2026-85172 | 5.3 MEDIUM | n8n before 2.34.1 SSRF via Request Helper URI Validation Bypass |
| CVE-2026-85173 | 5.3 MEDIUM | n8n before 2.36.2 Missing Authorization via Insights API |
No comments yet