Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-455f-pg36-wx7g

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 4.8

Описание

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

EPSS

Процентиль: 26%
0.0033
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 4.8
nvd
около 2 месяцев назад

n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.

EPSS

Процентиль: 26%
0.0033
Низкий

6.3 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-287