← العودة للجدول
CVE-2026-42233
CVE-2026-42233 — n8n is an open source workflow automation platform. Prior to versions 1.123.32,
📅 2026-05-04
🔴 Critical 🔥 No NVD Exploit Oracle CVSS 9.8 🎯 EPSS 0.06%

📋 الوصف الكامل

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the Limit field (e.g., from a

💻 الأنظمة المتأثرة

Oracle Database

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-42233

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v1.123.32

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←