Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-65593

17 дней назад

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-9w78-79q7-r4fp

16 дней назад

n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65593

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.

CVSS3: 5.4
0%
Низкий
17 дней назад
github логотип
GHSA-9w78-79q7-r4fp

n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

0%
Низкий
16 дней назад

Уязвимостей на страницу