OSV 1.4.0 · unreviewed · 修改于 2026-09-02 05:31
发布时间
2026-08-20 20:31
GitHub 审查时间
—
NVD 发布时间
2026-08-20 20:16
源文件
advisories/unreviewed/2026/08/GHSA-hf5p-745p-2j3h/GHSA-hf5p-745p-2j3h.json
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects.
该公告没有提供结构化的受影响软件包信息。