Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-25889 Source A vulnerability in File Browser software allows authenticated users to change passwords without providing the current password by using capitalization in API requests. This can lead to account takeover if attackers obtain valid authentication tokens. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-28492 Source A vulnerability in File Browser allows attackers to access all sibling directories and their files through public share links for directories, instead of only the intended shared directory. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-32761 Source A vulnerability in File Browser allows users without download permissions to still download files through public share links, bypassing access restrictions and enabling unauthorized data access. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-29188 Source A security vulnerability in File Browser software allows authenticated users to delete arbitrary files and directories despite being explicitly denied delete permissions, by using an alternative TUS endpoint that incorrectly checks only create permissions instead of delete permissions. |
File Browser | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-54089 Source File Browser with proxy authentication blindly trusts HTTP headers from any attacker, allowing them to impersonate any user including admin without requiring passwords or other credentials. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-32758 Source A vulnerability in File Browser allows authenticated users to bypass administrator access restrictions by using path traversal sequences to copy or move files into directories that should be blocked by configured deny rules. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-32760 Source File Browser allows unauthorized visitors to create administrator accounts when self-registration is enabled and default user permissions include admin rights, enabling complete control over the server and files. |
File Browser | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-32759 Source A vulnerability in File Browser allows authenticated users to trigger upload hooks unlimited times by using negative values in the Upload-Length header, causing hooks to execute with empty files and arbitrary filenames. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-34528 Source A security vulnerability in File Browser allows unauthenticated users to self-register and inherit shell execution permissions, enabling them to run arbitrary commands on the server. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-34529 Source File Browser contains a Stored Cross-Site Scripting vulnerability in the EPUB preview feature that allows attackers to execute malicious JavaScript code through crafted EPUB files and access user data. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-34530 Source File Browser contains a Stored Cross-Site Scripting vulnerability where administrators can inject malicious JavaScript code into branding fields that then executes for all website visitors. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-35604 Source File Browser fails to re-validate the current permissions of share creators when accessing public share links, allowing previously created links to remain accessible to unauthenticated users even after administrators revoke the creator's Share and Download permissions. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-35605 Source A vulnerability in File Browser software allows authenticated users to access directories they shouldn't by exploiting how path checking only compares prefixes without considering directory boundaries. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-35606 Source A vulnerability in File Browser allows users without download permission to read text files through an alternative API endpoint, even though downloading is explicitly prohibited for them. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-35607 Source A security flaw in File Browser allows automatically created users through proxy authentication to unintentionally receive execution permissions and system commands, even though these rights should be explicitly granted by administrators. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-54088 Source A critical security vulnerability in File Browser allows attackers to execute arbitrary system commands by injecting special characters into username or password fields during login, without requiring authentication. |
File Browser | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-35585 Source A security vulnerability in File Browser allows attackers to execute arbitrary system commands by creating malicious filenames with shell metacharacters that get injected into hook commands without sanitization. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-54091 Source A security vulnerability in File Browser allows attackers to access files and directories through public share URLs that the owner explicitly blocked with rules, as long as those blocked paths are located underneath the shared directory. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-54097 Source A vulnerability in File Browser allows low-privileged users to delete share links belonging to other users (including administrators) by removing files in their own directory whose path serves as a prefix in other users' link paths. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-54090 Source A security vulnerability in File Browser allows users with command execution permissions to bypass the command whitelist and execute arbitrary system commands by using shell metacharacters like semicolons or pipes. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-54095 Source File Browser does not invalidate existing JWT tokens when an administrator resets a user's password, allowing attackers with old tokens to continue accessing resources until natural token expiration. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-54094 Source File Browser allows users to access files outside their assigned scope through symbolic links, even though they should be restricted to their designated area. Attackers can read, overwrite, or publicly share unauthorized files through this vulnerability. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-54096 Source A vulnerability in File Browser allows authenticated users to create public shares for non-existent file paths that automatically become valid later when a file is created at that path. |
File Browser | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-54093 Source A security vulnerability in File Browser allows attackers to create malicious archives that, when extracted on Windows systems, can write files outside the intended directory, leading to arbitrary file write operations. |
File Browser | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2021-21404 Source A vulnerability in Syncthing and its relay server allows attackers to crash the software by sending specially crafted messages, but does not expose or compromise sensitive data. |
Syncthing | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2022-46165 Source A vulnerability in Syncthing software allows attackers to inject malicious HTML and JavaScript code through file names or device names into the web interface, enabling script execution when users hover over these elements. |
Syncthing | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2021-21297 Source Node-RED versions 1.2.7 and earlier contain a vulnerability where maliciously crafted requests to the admin API can affect the behavior of the JavaScript runtime environment. |
Node-RED | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2021-21298 Source A vulnerability in Node-RED allows users with project read permissions to access arbitrary files on the system through the Projects API, potentially exposing sensitive data. |
Node-RED | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-27578 Source A vulnerability in the n8n workflow automation software allows authenticated users to inject malicious scripts into web pages that then execute in other users' browsers, potentially enabling account takeovers. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-27577 Source A vulnerability in the n8n workflow software allows authenticated users with workflow permissions to execute system commands on the server through crafted expressions. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-27497 Source A security vulnerability in the n8n workflow software allows authenticated users with workflow permissions to execute arbitrary code and write files on the server through the Merge node. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| GHSA-f3f2-mcxc-pwjx Source A security vulnerability in the n8n workflow software allows SQL injection attacks through crafted table or column names in MySQL, PostgreSQL, and Microsoft SQL database nodes, enabling attackers to execute arbitrary SQL commands. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42230 Source A vulnerability in the n8n workflow automation software allows attackers to redirect users to external websites through malicious OAuth links when users deny permission requests. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-3c7f-5hgj-h279 Source A security vulnerability in the n8n workflow software allows authenticated users to inject malicious JavaScript code through the Custom CSS field, leading to stored cross-site scripting attacks on public chat pages. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-q4fm-pjq6-m63g Source A vulnerability in n8n allows authenticated users with workflow permissions to inject malicious scripts into Form Trigger nodes, which then execute for every visitor of published forms, enabling phishing attacks and form hijacking. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42234 Source A security vulnerability in the n8n workflow software allows authenticated users who can create Python Code nodes to escape the sandbox and execute arbitrary code on the server. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-33696 Source A critical security vulnerability in the n8n workflow software allows authenticated users to execute malicious code on the server through the GSuiteAdmin node by using specially crafted parameters. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-33749 Source A vulnerability in the n8n workflow software allows authenticated users to create malicious HTML content that executes in other users' browsers, potentially granting access to workflows, credentials, or administrator privileges. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42233 Source A vulnerability in n8n's Oracle Database node allows SQL injection attacks through the Limit field when external user input is processed without validation, enabling attackers to steal data from the connected Oracle database. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-33663 Source A vulnerability in the n8n workflow automation software allows authenticated users with limited privileges to steal HTTP credentials from other users and access their passwords in plaintext. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-42227 Source A vulnerability in n8n workflow software allows authenticated users to read variables from projects they shouldn't have access to by manipulating the project ID in API requests. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42237 Source A security vulnerability in n8n workflow software allows SQL injection attacks through Snowflake and MySQL v1 nodes when user input is unsafely incorporated into database queries. Attackers could steal, modify, or delete data from connected databases. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42236 Source A vulnerability in the n8n workflow automation software allows attackers to send large amounts of data to an OAuth registration endpoint without authentication, exhausting server memory and causing the application to become unavailable. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-42229 Source A SQL injection vulnerability in n8n's SeaTable node allows attackers to gain unauthorized access to database rows and bypass security filters by manipulating user input passed through workflow expressions. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-49465 Source A vulnerability in the n8n workflow software allows authenticated users to access and read local files outside configured security restrictions through Git operations. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42226 Source A vulnerability in the n8n workflow automation software allows authenticated users to steal other users' API keys by tricking the system into sending foreign credentials to attacker-controlled servers. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-42228 Source A vulnerability in n8n workflow software allows attackers to hijack chat connections without authorization and intercept or manipulate messages when certain conditions are met. |
n8n | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42235 Source A vulnerability in the n8n workflow automation software allows attackers to inject malicious JavaScript code through OAuth client names, which executes when notifications are displayed and can steal credentials or manipulate workflows. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-49444 Source A security vulnerability in the n8n workflow software allows authenticated users who can create Python Code nodes to escape the sandbox and execute arbitrary code on the server. |
n8n | Self-hosted apps | High | 07.06.2026 |
| GHSA-3875-8gcx-7v46 Source A vulnerability in the n8n workflow automation software allowed authenticated users to bypass security restrictions and send HTTP requests with credentials to unauthorized servers. |
n8n | Self-hosted apps | Medium | 07.06.2026 |