Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted workflow and read its returned data. The affected path is packages/cli/src/modules/agents/tools/workflow-tool-factory.ts, where executeWorkflow omitted SubworkflowPolicyChecker.checkForProject. This issue is fixed in versions 2.37.7 and 2.38.2. Join the discussion | CVE Database V5 | 09/08/2026, 21:15:38 UTC Added: 09/09/2026, 11:05:15 UTC |
A Server-Side Request Forgery (SSRF) vulnerability exists in the n8n workflow automation platform prior to versions 2.37.7 and 2.38.2. The issue occurs in the Instance AI credential setup flow, where a credential test or verification URL is accepted without verifying that it matches the workflow node's origin. This allows attacker-controlled content to influence the URL, potentially causing authenticated requests, redirects, or probes to unintended origins. The vulnerability affects specific code handling credential URLs and is fixed in versions 2.37.7 and 2.38.2. Join the discussion | CVE Database V5 | 09/08/2026, 17:38:11 UTC Added: 09/08/2026, 17:52:59 UTC |
0 CVE-2026-77084 is a high-severity OS command injection vulnerability in the n8n automation tool's Git node. Versions before 1.123.69 and certain 2.x versions prior to 2.33.4/2.34.1 are affected. The vulnerability arises because the Git node executes repository-local git configuration values without proper neutralization, allowing malicious values to be executed as the n8n process user. Exploitation requires an additional file-write vulnerability to plant the malicious configuration value, as the Git node's own configuration controls do not allow direct exploitation. Join the discussion | CVE Database V5 | 08/20/2026, 12:31:25 UTC Added: 08/20/2026, 11:37:44 UTC |
0 CVE-2026-77080 is a high-severity vulnerability in n8n that allows an authenticated user with valid Snowflake credentials to perform arbitrary file read and write operations on the n8n host. This occurs because the Snowflake node passes free-form Execute Query input directly to the Snowflake SDK without enforcing n8n's file-access restrictions. The vulnerability affects multiple versions of n8n prior to 1.123.69, 2.33.4, and 2.34.1. A patch is available to address this issue. Join the discussion | CVE Database V5 | 08/20/2026, 12:31:25 UTC Added: 08/20/2026, 11:37:44 UTC |
0 n8n versions prior to 1.123.69, 2.33.4, and 2.34.1 have an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the error message includes sensitive information such as decrypted credential secrets in the request headers. This sensitive data is stored verbatim in the execution engine's run data, accessible to any authenticated user who can read the execution results. Join the discussion | CVE Database V5 | 08/20/2026, 12:31:25 UTC Added: 08/20/2026, 11:37:42 UTC |
0 n8n versions before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 have an expression injection vulnerability in the resource-locator field used for link preview rendering. This flaw allows an authenticated user to inject malicious JavaScript expressions that are evaluated in the context of other users when they open the affected node in the editor, resulting in cross-user script execution. Join the discussion | CVE Database V5 | 08/20/2026, 12:31:25 UTC Added: 08/20/2026, 11:37:42 UTC |
0 CVE-2026-77074 is a medium severity vulnerability in n8n versions before 1.123.69 that affects the Edit Image node's Draw Text operation. Authenticated users can exploit this flaw to inject MVG primitives, enabling blind outbound HTTP requests to arbitrary addresses or access to local files. The vulnerability arises from improper control of code generation, specifically a server-side request forgery (SSRF) vector. Multiple version ranges of n8n are affected, including versions before 1.123.69 and certain 2.x releases prior to specific patch versions. Join the discussion | CVE Database V5 | 08/20/2026, 12:31:25 UTC Added: 08/20/2026, 11:37:42 UTC |
0 n8n versions prior to 1.123.69, 2.33.4, and 2.34.1 contain a stored cross-site scripting (XSS) vulnerability in the Form node's completion page. This vulnerability arises because the completion page applies its Content-Security-Policy sandbox only when respondWith is not set to 'redirect', but always renders responseText as raw HTML. An authenticated user can exploit this by setting respondWith to 'redirect' while keeping responseText populated, causing unsanitized HTML and scripts to be served from the n8n origin. Visitors submitting the affected public form may have malicious scripts execute in their session context. Join the discussion | CVE Database V5 | 08/20/2026, 12:31:25 UTC Added: 08/20/2026, 11:37:42 UTC |
0 CVE-2026-77071 is a SQL injection vulnerability in the n8n workflow automation tool affecting the Supabase node's Row Get Many, Delete, and Update operations. The flaw arises from improper neutralization of special elements in SQL commands, allowing an attacker to inject conditions that expand filters beyond intended single-row operations. This can lead to full-table data disclosure, deletion, or modification. The vulnerability affects multiple versions prior to 1.123.69, 2.33.4, and 2.34.1. It has a high severity score of 7.1. No known exploits are reported in the wild, and no vendor patch links were provided in the input data. Join the discussion | CVE Database V5 | 08/20/2026, 12:31:25 UTC Added: 08/20/2026, 11:37:42 UTC |
0 CVE-2026-77083 is a prototype pollution vulnerability in the JavaScript Code node's VM sandbox of the n8n workflow automation platform. In affected versions, the sandbox does not freeze Function.prototype, allowing an authenticated user with workflow execution privileges to modify the prototype and escape the sandbox. This vulnerability requires the presence of specific allowlisted modules in the deployment configuration to complete the exploit chain. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1. Join the discussion | CVE Database V5 | 08/20/2026, 11:21:14 UTC Added: 08/20/2026, 11:37:44 UTC |
Showing 1 to 10 of 88 results