8.8

CVSS4.0

CVE-2026-42235 - n8n: XSS via MCP OAuth client

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that ac…

πŸ“… Published: May 4, 2026, 6:38 p.m. πŸ”„ Last Modified: May 6, 2026, 6:05 p.m.

7.1

CVSS4.0

CVE-2026-42234 - n8n: Python Task Runner Sandbox Escape

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This issu…

πŸ“… Published: May 4, 2026, 6:36 p.m. πŸ”„ Last Modified: May 6, 2026, 6:05 p.m.

5.3

CVSS4.0

CVE-2026-42233 - n8n: SQL Injection in Oracle Database Node via Limit Field

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or …

πŸ“… Published: May 4, 2026, 6:35 p.m. πŸ”„ Last Modified: May 6, 2026, 6:07 p.m.

9.4

CVSS4.0

CVE-2026-42232 - n8n: XML Node Prototype Pollution to RCE

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype po…

πŸ“… Published: May 4, 2026, 6:34 p.m. πŸ”„ Last Modified: May 6, 2026, 5:15 p.m.

9.4

CVSS4.0

CVE-2026-42231 - n8n: Prototype Pollution in XML Webhook Body Parser Leads to RCE

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or modify…

πŸ“… Published: May 4, 2026, 6:30 p.m. πŸ”„ Last Modified: May 6, 2026, 5:14 p.m.

8.7

CVSS4.0

CVE-2026-25863 - Conditional Fields for Contact Form 7 < 2.7.3 DoS via Uncontrolled Resource Consumption

Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iteration count directly from user-supplied POST parameters with…

πŸ“… Published: May 4, 2026, 6:29 p.m. πŸ”„ Last Modified: May 6, 2026, 9:22 a.m.

5.1

CVSS4.0

CVE-2026-42230 - n8n: Open Redirect in MCP OAuth Consent Flow

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. When a user denies the MCP OAuth consent dialog, …

πŸ“… Published: May 4, 2026, 6:28 p.m. πŸ”„ Last Modified: May 6, 2026, 2:57 p.m.

5.3

CVSS4.0

CVE-2026-42229 - n8n: SQL Injection in SeaTable Node

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query strings without escaping or parameterization. In workflows whe…

πŸ“… Published: May 4, 2026, 6:27 p.m. πŸ”„ Last Modified: May 6, 2026, 2:56 p.m.

6.3

CVSS4.0

CVE-2026-42228 - n8n: Hijacking of Unauthenticated Chat Execution

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated re…

πŸ“… Published: May 4, 2026, 6:27 p.m. πŸ”„ Last Modified: May 6, 2026, 6:08 p.m.

6

CVSS4.0

CVE-2026-42227 - n8n: Public API Variables IDOR Allows Cross-Project Secret Disclosure

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projects they are not a member of by supplying an arbitrary projectId query parameter to the public API va…

πŸ“… Published: May 4, 2026, 6:26 p.m. πŸ”„ Last Modified: May 6, 2026, 6:08 p.m.
Total resulsts: 349182
Page 127 of 34,919
Β« previous page Β» next page
Filters