The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,626
Mitigations15,990
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
n8n< 2.29.8
NPM: n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
5.5
6 minutes ago
n8n< 1.123.58
NPM: n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
5.3
9 minutes ago
n8n< 2.28.0
NPM: n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
5.3
10 minutes ago
n8n< 2.27.4
NPM: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
6.3
11 minutes ago
n8n< 1.123.61
NPM: n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
12 minutes ago
n8n< 1.123.61
NPM: n8n: External Secrets Permission Bypass via Expression Parser Mismatch
6
13 minutes ago
n8n< 2.31.5
NPM: n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
4.9
21 minutes ago
n8n< 1.123.67
NPM: n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
6.1
21 minutes ago
n8n< 1.123.67
NPM: n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
7.1
22 minutes ago
n8n< 1.123.67
NPM: n8n: Edit Image Node Format Injection Allows Arbitrary File Write
7.7
23 minutes ago
n8n< 1.123.67
NPM: n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
7.2
23 minutes ago
n8n< 1.123.67
NPM: n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
7.1
24 minutes ago
n8n< 2.31.5
NPM: n8n: Expression sandbox escape via arrow-function bodies enabling command execution
8.7
24 minutes ago
n8n< 1.123.67
NPM: n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
8.2
25 minutes ago
n8n< 1.123.67
NPM: n8n: Authenticated code execution in the n8n Git node
8.7
26 minutes ago
n8n< 2.31.5
NPM: n8n: SSRF Protection Bypass via MCP Client Node
6.4
27 minutes ago
n8n< 1.123.67
NPM: n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
7.1
28 minutes ago
n8n< 2.31.5
NPM: n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
7.1
28 minutes ago
n8n< 2.31.5
NPM: n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
8.9
29 minutes ago
n8n< 1.123.64
NPM: n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
7.7
30 minutes ago