π¨ CVE-2026-92814
changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watch_title token is used in templates.
π@cveNotify
changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watch_title token is used in templates.
π@cveNotify
GitHub
GitHub - dgtlmoon/changedetection.io: Best and simplest tool for website change detection, web page monitoring, and website changeβ¦
Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price drops, restock alerts, and website defacement monito...
π¨ CVE-2026-92815
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
π@cveNotify
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
π@cveNotify
GitHub
GitHub - dgtlmoon/changedetection.io: Best and simplest tool for website change detection, web page monitoring, and website changeβ¦
Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price drops, restock alerts, and website defacement monito...
π¨ CVE-2026-92816
ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.
π@cveNotify
ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled content to arbitrary locations, enabling code execution through modified startup files or package initializers.
π@cveNotify
GitHub
GitHub - Comfy-Org/ComfyUI: The most powerful and modular diffusion model GUI, api and backend with a graph/nodes interface. Theβ¦
The most powerful and modular diffusion model GUI, api and backend with a graph/nodes interface. The fastest local inference engine in the world. - Comfy-Org/ComfyUI
π¨ CVE-2026-85168
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter and merge-driver key families. A repository with local configuration setting one of those keys together with a matching attribute pattern causes git to execute the configured command during an ordinary Add, Commit, Checkout, or Pull operation. The command runs as the n8n process user.
π@cveNotify
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter and merge-driver key families. A repository with local configuration setting one of those keys together with a matching attribute pattern causes git to execute the configured command during an ordinary Add, Commit, Checkout, or Pull operation. The command runs as the n8n process user.
π@cveNotify
GitHub
Git Node Remote Code Execution via Incomplete Repository-Local Configuration Neutralization
## Impact
The Git node reset a fixed list of command-bearing configuration keys before each operation, and that list did not cover the content-filter and merge-driver key families. A repository wh...
The Git node reset a fixed list of command-bearing configuration keys before each operation, and that list did not cover the content-filter and merge-driver key families. A repository wh...
π¨ CVE-2026-85171
n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper outside any error handling, causing the plaintext secret to be persisted in execution error data. Any authenticated user can read the plaintext secret from their own execution through the REST API, bypassing the blank-value redaction enforced by the credentials API.
π@cveNotify
n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper outside any error handling, causing the plaintext secret to be persisted in execution error data. Any authenticated user can read the plaintext secret from their own execution through the REST API, bypassing the blank-value redaction enforced by the credentials API.
π@cveNotify
GitHub
Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error Data
## Impact
Strapi, SeaTable and Mailcheck nodes sent their decrypted credential to the authentication endpoint through the raw legacy HTTP helper outside any error handling. Any authenticated user ...
Strapi, SeaTable and Mailcheck nodes sent their decrypted credential to the authentication endpoint through the raw legacy HTTP helper outside any error handling. Any authenticated user ...
π¨ CVE-2026-85172
n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP client uses the url property when both are present, allowing attackers to bypass validation by supplying a safe uri alongside a malicious url to access internal addresses.
π@cveNotify
n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP client uses the url property when both are present, allowing attackers to bypass validation by supplying a safe uri alongside a malicious url to access internal addresses.
π@cveNotify
GitHub
Legacy Request Helper SSRF Check Validates uri While Axios Dispatches url
## Impact
The legacy `helpers.request()` function exposed to Code and Function nodes validated the request URL for SSRF before converting the request object for the underlying HTTP client. The con...
The legacy `helpers.request()` function exposed to Code and Function nodes validated the request URL for SSRF before converting the request object for the underlying HTTP client. The con...
π¨ CVE-2026-85173
n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
π@cveNotify
n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
π@cveNotify
GitHub
Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across Projects
## Impact
The Insights API routes (`/rest/insights/*`) were gated only by the instance-level `insights:list` scope and passed the client-supplied projectId straight through to the repository, with...
The Insights API routes (`/rest/insights/*`) were gated only by the instance-level `insights:list` scope and passed the client-supplied projectId straight through to the repository, with...
π¨ CVE-2026-69808
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
π@cveNotify
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-69813
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-69814
Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69816
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69817
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69818
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69820
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69822
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
π@cveNotify
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69829
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
π@cveNotify
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-69832
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
π@cveNotify
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-69834
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69838
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69839
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
π@cveNotify
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-2756
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify