Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Vonypeto

#21242of 56,330
13Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-85000
7.7
2026-09-03
N8N · N8N · CVE-2026-85168
**Name of the Vulnerable Software and Affected Versions** n8n versions prior to 1.123.73 n8n versions prior to 2.35.4 n8n versions prior to 2.36.2 **Description** A remote code execution issue exists in the Git node. The node fails to reset the `content-filter` and `merge-driver` configuration key families before operations. If a repository contains local configurations setting these keys with a matching attribute pattern, git executes the configured command during Add, Commit, Checkout, or Pull operations. The command is executed with the privileges of the n8n process user. **Recommendations** Update to version 1.123.73 or later. Update to version 2.35.4 or later. Update to version 2.36.2 or later.
PT-2026-78929
5.3
2026-08-20
N8N · N8N · CVE-2026-77073
**Name of the Vulnerable Software and Affected Versions** n8n versions prior to 2.34.1 **Description** A credential validation bypass exists in the MCP `create workflow from code` tool when the authentication type is configured as an expression. An attacker possessing a valid MCP Bearer API key and a target credential ID can establish unauthorized cross-project credential references on workflows located in different projects. **Recommendations** Update n8n to version 2.34.1 or later.