Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54314 | n8n: Denial of Service via ZIP decompression in webhook workflow | |
| CVE-2026-44791 | n8n: XML Node Prototype Pollution Patch Bypass | |
| CVE-2026-44789 | n8n: HTTP Request Node Pagination Prototype Pollution to RCE | |
| CVE-2026-44792 | n8n: Source Control Pull SQL Injection | |
| CVE-2026-44790 | n8n: Arbitrary File Read via Git Node | |
| CVE-2026-49444 | n8n: Python sandbox escape | |
| CVE-2026-49465 | n8n: Git Node Clone and Push Operations Bypass File Sandbox | |
| CVE-2026-54304 | n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host | |
| CVE-2026-54301 | n8n: Same-Origin XSS in Respond to Webhook Node | |
| CVE-2026-54310 | n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes | |
| CVE-2026-45732 | n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints | |
| CVE-2026-54302 | n8n: Stored XSS in Chat Trigger Node | |
| CVE-2026-54306 | n8n: Prototype Pollution enables confused-deputy execution via public webhooks | |
| CVE-2026-54313 | n8n: NoSQL Injection in MongoDB Node Find And Replace Operation | |
| CVE-2026-54303 | n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verificatio | |
| CVE-2026-54305 | n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints | |
| CVE-2026-54308 | n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node | |
| CVE-2026-54312 | n8n: Microsoft SQL Node Prototype Pollution | |
| CVE-2026-54309 | n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions | |
| CVE-2026-54311 | n8n: Merge Node SQL Mode Prototype Pollution |
No comments yet