Threats Tagged 'ghsa-q6mx-qvhp-fqmg'
View all threats tagged with 'ghsa-q6mx-qvhp-fqmg'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-q6mx-qvhp-fqmg'
Click on any threat for detailed analysis and mitigation recommendations
N8n: Duplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch 0 n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability related to external secrets handling. The issue arises from a mismatch between static validation and the runtime expression engine, allowing authenticated users with credential create or update permissions—but without externalSecret:list scope—to embed external secret references undetected. These references resolve during workflow execution, exposing secret values the user should not access. This vulnerability affects only instances with an external secrets provider configured and Advanced Permissions enabled. The advisory is a duplicate and has been withdrawn in favor of GHSA-jp7m-xcgx-57qm. Join the discussion | GCVE Database | 07/15/2026, 12:32:03 UTC Added: 07/22/2026, 23:22:50 UTC |
Showing 1 to 1 of 1 result