Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-jqwr-vx3p-r266 |
|
SQL Injection in n8n (GHSA-jqwr-vx3p-r266)
SQL injection in n8n (GHSA-jqwr-vx3p-r266). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-9cmh-xcqm-5hqr |
|
Vulnerability in n8n (GHSA-9cmh-xcqm-5hqr)
vulnerability in n8n (GHSA-9cmh-xcqm-5hqr). Risk of unauthorized operations or information disclosure. Exploitable via ``NODE_FUNCTION_ALLOW_BUILTIN``. Mitigation: upgrade to `2.31.5` or later.
|
| CVE-2026-61246 |
|
Privilege Escalation in c (CVE-2026-61246)
vulnerability in c (CVE-2026-61246). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60455 |
|
Privilege Escalation in c (CVE-2026-60455)
vulnerability in c (CVE-2026-60455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60439 |
|
Privilege Escalation in c (CVE-2026-60439)
vulnerability in c (CVE-2026-60439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60373 |
|
Privilege Escalation in c (CVE-2026-60373)
vulnerability in c (CVE-2026-60373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60372 |
|
Privilege Escalation in c (CVE-2026-60372)
vulnerability in c (CVE-2026-60372). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60371 |
|
Information Disclosure in c (CVE-2026-60371)
vulnerability in c (CVE-2026-60371). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60370 |
|
Vulnerability in c (CVE-2026-60370)
vulnerability in c (CVE-2026-60370). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60369 |
|
Privilege Escalation in c (CVE-2026-60369)
vulnerability in c (CVE-2026-60369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60368 |
|
Vulnerability in c (CVE-2026-60368)
vulnerability in c (CVE-2026-60368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60367 |
|
Privilege Escalation in c (CVE-2026-60367)
vulnerability in c (CVE-2026-60367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60366 |
|
Privilege Escalation in c (CVE-2026-60366)
vulnerability in c (CVE-2026-60366). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38766 |
|
Privilege Escalation in CVE-2026-38766 (CVE-2026-38766)
vulnerability in CVE-2026-38766 (CVE-2026-38766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38765 |
|
Privilege Escalation in CVE-2026-38765 (CVE-2026-38765)
vulnerability in CVE-2026-38765 (CVE-2026-38765). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38763 |
|
Vulnerability in dos (CVE-2026-38763)
vulnerability in dos (CVE-2026-38763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16630 |
|
Command Injection in CVE-2026-16630 (CVE-2026-16630)
command injection in CVE-2026-16630 (CVE-2026-16630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73417 |
|
Cross-Site Scripting (XSS) in jupyterlab (CVE-2026-73417)
cross-site scripting in jupyterlab (CVE-2026-73417). Risk of unauthorized operations or information disclosure. Exploitable via ``Import``. Mitigation: upgrade to `4.5.10` or later.
|
| CVE-2026-73415 |
|
Cross-Site Scripting (XSS) in jupyterlab (CVE-2026-73415)
cross-site scripting in jupyterlab (CVE-2026-73415). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.5.10` or later.
|
| CVE-2026-73416 |
|
Vulnerability in jupyterlab (CVE-2026-73416)
vulnerability in jupyterlab (CVE-2026-73416). Risk of unauthorized operations or information disclosure. Exploitable via ``blocked_extensions_uris``. Mitigation: upgrade to `4.5.10` or later.
|
| GHSA-h5v5-8746-g7mm |
|
Vulnerability in jupyterlab (GHSA-h5v5-8746-g7mm)
vulnerability in jupyterlab (GHSA-h5v5-8746-g7mm). Risk of unauthorized operations or information disclosure. Exploitable via ``jupyterlab``. Mitigation: upgrade to `4.5.10` or later.
|
| GHSA-whvh-wf3x-g77j |
|
Vulnerability in jupyterlab (GHSA-whvh-wf3x-g77j)
vulnerability in jupyterlab (GHSA-whvh-wf3x-g77j). Risk of unauthorized operations or information disclosure. Exploitable via ``PyPIExtensionManager``. Mitigation: upgrade to `4.5.10` or later.
|
| CVE-2026-64649 |
|
SSRF (Server-Side Request Forgery) in next (CVE-2026-64649)
SSRF in next (CVE-2026-64649). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64648 |
|
Vulnerability in next (CVE-2026-64648)
vulnerability in next (CVE-2026-64648). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64647 |
|
Vulnerability in next (CVE-2026-64647)
vulnerability in next (CVE-2026-64647). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64646 |
|
Vulnerability in next (CVE-2026-64646)
vulnerability in next (CVE-2026-64646). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64645 |
|
Open Redirect in next (CVE-2026-64645)
vulnerability in next (CVE-2026-64645). Risk of unauthorized operations or information disclosure. Exploitable via ``has``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64644 |
|
Vulnerability in next (CVE-2026-64644)
vulnerability in next (CVE-2026-64644). Risk of unauthorized operations or information disclosure. Exploitable via ``config.images.remotePatterns``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64643 |
|
Vulnerability in next (CVE-2026-64643)
vulnerability in next (CVE-2026-64643). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64642 |
|
Vulnerability in next (CVE-2026-64642)
vulnerability in next (CVE-2026-64642). Confidential information can be exposed externally. Exploitable via ``config.i18n.locales``. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-64641 |
|
Vulnerability in next (CVE-2026-64641)
vulnerability in next (CVE-2026-64641). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-10050 |
|
Vulnerability in org.eclipse.jetty:jetty-security (CVE-2026-10050)
vulnerability in org.eclipse.jetty:jetty-security (CVE-2026-10050). Confidential information can be exposed externally. Mitigation: upgrade to `12.1.10` or later.
|
| CVE-2026-59943 |
|
Vulnerability in dompdf/dompdf (CVE-2026-59943)
vulnerability in dompdf/dompdf (CVE-2026-59943). Risk of unauthorized operations or information disclosure. Exploitable via ``href``. Mitigation: upgrade to `3.1.6` or later.
|
| CVE-2026-59942 |
|
Vulnerability in dompdf/dompdf (CVE-2026-59942)
vulnerability in dompdf/dompdf (CVE-2026-59942). Risk of unauthorized operations or information disclosure. Exploitable via ``exploit.py``. Mitigation: upgrade to `3.1.6` or later.
|
| CVE-2026-59941 |
|
Vulnerability in dompdf/dompdf (CVE-2026-59941)
vulnerability in dompdf/dompdf (CVE-2026-59941). Risk of unauthorized operations or information disclosure. Exploitable via `POST /render`. Mitigation: upgrade to `3.1.6` or later.
|
| CVE-2026-16629 |
|
Command Injection in CVE-2026-16629 (CVE-2026-16629)
command injection in CVE-2026-16629 (CVE-2026-16629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16628 |
|
Command Injection in CVE-2026-16628 (CVE-2026-16628)
command injection in CVE-2026-16628 (CVE-2026-16628). Risk of unauthorized operations or information disclosure.
|
| GHSA-pf2q-pxhf-hgmw |
|
Path Traversal in n8n (GHSA-pf2q-pxhf-hgmw)
path traversal in n8n (GHSA-pf2q-pxhf-hgmw). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-hx4h-vr3m-45vh |
|
Vulnerability in n8n (GHSA-hx4h-vr3m-45vh)
vulnerability in n8n (GHSA-hx4h-vr3m-45vh). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-xwx6-jjhv-84p8 |
|
Vulnerability in n8n (GHSA-xwx6-jjhv-84p8)
vulnerability in n8n (GHSA-xwx6-jjhv-84p8). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-xmc9-4f2h-jf9c |
|
Vulnerability in n8n (GHSA-xmc9-4f2h-jf9c)
vulnerability in n8n (GHSA-xmc9-4f2h-jf9c). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-cj9h-qx8g-pq2g |
|
Authorization Flaw in n8n (GHSA-cj9h-qx8g-pq2g)
vulnerability in n8n (GHSA-cj9h-qx8g-pq2g). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-6qc9-mqvw-jg7x |
|
Authorization Flaw in n8n (GHSA-6qc9-mqvw-jg7x)
vulnerability in n8n (GHSA-6qc9-mqvw-jg7x). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-gv7g-jm28-cr3m |
|
Code Injection in n8n (GHSA-gv7g-jm28-cr3m)
code injection in n8n (GHSA-gv7g-jm28-cr3m). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-2x35-3fw4-9jr4 |
|
Information Disclosure in n8n (GHSA-2x35-3fw4-9jr4)
vulnerability in n8n (GHSA-2x35-3fw4-9jr4). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-rcv6-pvrj-4xcg |
|
OS Command Injection in n8n (GHSA-rcv6-pvrj-4xcg)
OS command injection in n8n (GHSA-rcv6-pvrj-4xcg). Risk of unauthorized operations or information disclosure. Exploitable via ``git``. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-vhf8-cg2h-cg3p |
|
SSRF (Server-Side Request Forgery) in n8n (GHSA-vhf8-cg2h-cg3p)
SSRF in n8n (GHSA-vhf8-cg2h-cg3p). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-gf29-4f56-r2jf |
|
Path Traversal in n8n (GHSA-gf29-4f56-r2jf)
path traversal in n8n (GHSA-gf29-4f56-r2jf). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-64xh-79j6-r5v8 |
|
Authorization Flaw in n8n (GHSA-64xh-79j6-r5v8)
vulnerability in n8n (GHSA-64xh-79j6-r5v8). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.31.5` or later.
|
| GHSA-8342-988q-86cr |
|
Vulnerability in n8n (GHSA-8342-988q-86cr)
vulnerability in n8n (GHSA-8342-988q-86cr). Risk of unauthorized operations or information disclosure. Exploitable via ``allowedRoles``. Mitigation: upgrade to `2.31.5` or later.
|