CNNVD-202602-613 Information

CNNVD ID

CNNVD-202602-613

CVE-2026-25054

  • CNNVD Published: 2026-02-04

Description (Chinese)

n8n是n8n开源的一个可扩展的工作流自动化工具。 n8n 1.123.9之前版本和2.2.1之前版本存在安全漏洞,该漏洞源于Markdown渲染组件处理不当,可能导致跨站脚本攻击、会话劫持和账户接管。

Description (English)

n8n is an expanded workflow automation tool for n8n open source. n8n 1.123.9 There is a security loophole in the previous version and in the previous version of 2.2.1 which stems from the inappropriate handling of the Markdown retrofitting component, which may lead to cross-site scrip attacks, session hijackings and account takeovers.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

n8n

Published

2026-02-04

Last Modified

2026-02-24

References

https://github.com/n8n-io/n8n/security/advisories/GHSA-qpq4-pw7f-pp8w https://access.redhat.com/security/cve/cve-2026-25054

Patch

https://github.com/n8n-io/n8n/releases

Share on: