Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-85166

Опубликовано: 03 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/updating a workflow via the REST API, Public API, or MCP, can persist a node referencing a credential they do not own. When the workflow is later executed under an identity that holds the credential, the inline sub-workflow resolves the secret and can send it to an attacker-controlled endpoint, resulting in credential exfiltration.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия до 2.35.4 (исключая)
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Версия от 2.36.0 (включая) до 2.36.2 (исключая)

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
github
16 дней назад

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/updating a workflow via the REST API, Public API, or MCP, can persist a node referencing a credential they do not own. When the workflow is later executed under an identity that holds the credential, the inline sub-workflow resolves the secret and can send it to an attacker-controlled endpoint, resulting in credential exfiltration.

EPSS

Процентиль: 11%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863