n8n Vulnerable to Stored XSS via Various Nodes
수정: 2026. 2. 28.
package
pkg:npm/n8n
n8n Vulnerable to Stored XSS via Various Nodes
수정: 2026. 2. 28.
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
수정: 2026. 6. 16.
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
수정: 2026. 5. 19.
n8n's domain allowlist bypass enables credential exfiltration
수정: 2026. 2. 19.
n8n has XSS in its Credential Management Flow
수정: 2026. 3. 27.
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
수정: 2025. 10. 9.
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
수정: 2026. 5. 19.
n8n has Webhook Forgery on Zendesk Trigger Node
수정: 2026. 2. 26.
n8n has XSS in Chat Trigger Node through Custom CSS
수정: 2026. 4. 3.
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no
수정: 2026. 3. 25.
n8n has a Python Task Runner Sandbox Escape Vulnerability
수정: 2026. 5. 8.
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
수정: 2026. 5. 8.
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
수정: 2026. 2. 4.
n8n Vulnerable to XSS via MCP OAuth client
수정: 2026. 5. 8.
n8n Has an Arbitrary File Read via Git Node
수정: 2026. 5. 14.
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox
수정: 2025. 12. 27.
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
수정: 2026. 4. 12.
n8n allows open redirects via the /signin endpoint
수정: 2025. 6. 27.
n8n: Git Node Clone and Push Operations Bypass File Sandbox
수정: 2026. 6. 16.
n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
수정: 2026. 2. 3.
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
수정: 2026. 2. 3.
n8n Has Expression Escape Vulnerability Leading to RCE
수정: 2026. 2. 4.
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
수정: 2026. 5. 14.
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
수정: 2026. 5. 8.
n8n has Unauthenticated Expression Evaluation via Form Node
수정: 2026. 2. 28.
n8n Vulnerable to Command Injection in Community Package Installation
수정: 2026. 2. 4.
n8n's Improper CSP Enforcement in Webhook Responses May Allow Stored XSS
수정: 2026. 2. 4.
n8n has a Python sandbox escape
수정: 2026. 3. 25.
n8n Privilege Escalation vulnerability
수정: 2023. 11. 8.
n8n has SQL Injection in Data Table Node via orderByColumn Expression
수정: 2026. 3. 26.
n8n: Merge Node SQL Mode Prototype Pollution
수정: 2026. 6. 16.
n8n has OS Command Injection in Git Node
수정: 2026. 2. 4.
n8n: Python sandbox escape
수정: 2026. 6. 16.
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
수정: 2026. 6. 16.
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
수정: 2026. 3. 25.
n8n Vulnerable to Stored XSS through Attachments View Endpoint
수정: 2025. 4. 29.
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
수정: 2026. 5. 14.
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
수정: 2026. 2. 26.
n8n has Open Redirect in MCP OAuth Consent Flow
수정: 2026. 5. 8.
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
수정: 2026. 5. 8.
n8n has a Guardrail Node Bypass
수정: 2026. 2. 26.
n8n Has External Secrets Authorization Bypass in Credential Saving
수정: 2026. 3. 25.
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
수정: 2026. 2. 5.
n8n symlink traversal vulnerability in "Read/Write File" node allows access to restricted files
수정: 2025. 8. 21.
n8n is vulnerable to Improper Authorization through its `/stop` endpoint
수정: 2025. 7. 3.
Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source
수정: 2025. 8. 19.
n8n has SQL Injection in Snowflake and MySQL Nodes
수정: 2026. 5. 8.
n8n has XML Node Prototype Pollution that to RCE
수정: 2026. 5. 8.
n8n Merge Node has Arbitrary File Write leading to RCE
수정: 2026. 2. 4.
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
수정: 2026. 6. 16.
Self-hosted n8n has Legacy Code node that enables arbitrary file read/write
수정: 2025. 12. 31.
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
수정: 2026. 2. 3.
n8n has an Authentication Bypass in its Chat Trigger Node
수정: 2026. 2. 26.
n8n has a Sandbox Escape in its JavaScript Task Runner
수정: 2026. 2. 28.
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
수정: 2026. 6. 16.
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
수정: 2026. 6. 16.
n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
수정: 2026. 3. 25.
n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node
수정: 2026. 2. 4.
n8n Has a Source Control Pull SQL Injection
수정: 2026. 5. 14.
n8n has Arbitrary File Read via Python Code Node Sandbox Escape
수정: 2026. 2. 28.
n8n has SQL Injection in SeaTable Node
수정: 2026. 5. 8.
n8n: Webhook Forgery on Github Webhook Trigger
수정: 2026. 2. 26.
Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter
수정: 2025. 9. 15.
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
수정: 2026. 3. 26.
n8n Directory Traversal vulnerability
수정: 2023. 11. 8.
n8n Vulnerable to Denial of Service via Malformed Binary Data Requests
수정: 2025. 7. 3.
n8n has a Stored XSS Vulnerability in its Form Trigger
수정: 2026. 3. 27.
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
수정: 2026. 5. 8.
n8n Vulnerable to XSS via Binary Data Inline HTML Rendering
수정: 2026. 3. 26.
n8n Has Stored Cross-site Scripting via Markdown Rendering in Workflow UI
수정: 2026. 2. 4.
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
수정: 2026. 5. 8.
n8n has SQL Injection in Oracle Database Node via Limit Field
수정: 2026. 5. 8.
n8n Information Disclosure vulnerability
수정: 2023. 11. 8.
n8n Vulnerable to RCE via Arbitrary File Write
수정: 2026. 2. 3.
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
수정: 2026. 2. 3.
n8n: Same-Origin XSS in Respond to Webhook Node
수정: 2026. 6. 16.
n8n Vulnerable to Remote Code Execution via Expression Injection
수정: 2026. 3. 13.
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
수정: 2026. 2. 26.
n8n: Expression Sandbox Escape Leads to RCE
수정: 2026. 2. 28.
n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK
수정: 2026. 3. 25.
n8n: Authenticated XSS and Open Redirect via Form Node
수정: 2026. 3. 27.
n8n Vulnerable to LDAP Filter Injection in LDAP Node
수정: 2026. 3. 26.
n8n: Webhook Node IP Whitelist Bypass via Partial String Matching
수정: 2026. 2. 3.
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
수정: 2025. 12. 9.
n8n Has an XML Node Prototype Pollution Patch Bypass
수정: 2026. 5. 14.
n8n has Potential Remote Code Execution via Merge Node
수정: 2026. 2. 28.
n8n has Arbitrary Command Execution via File Write and Git Operations
수정: 2026. 2. 28.
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
수정: 2025. 10. 30.
n8n has In-Process Memory Disclosure in its Task Runner
수정: 2026. 3. 27.