NCSC Advisory: Multiple Vulnerabilities Patched in n8n Workflow Automation Platform (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Vulnerabilities in n8n before versions 2.10.1, 2.9.3, and 1.123.22
- Remote code execution via sandbox escapes and insecure nodes
- Missing signature verification on webhooks allows unauthorized workflow triggers
- Authentication bypass in SSO and Chat Trigger
"The Dutch NCSC advisory reports multiple vulnerabilities in n8n, including remote code execution, authentication bypass, and sandbox escapes. Affected versions: before 2.10.1, 2.9.3, and 1.123.22. Attackers can exploit unsanitized inputs, missing signature verification, and insecure nodes to take over systems."
no comments yet.