Results for "n8n"
- Article
n8n Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
Authorization bypass in n8n’s dynamic-credentials OAuth endpoints allows any authenticated user to operate on another user’s OAuth credential by supplying its I…
- Article
CVE-2026-42227: n8n Public API Variables IDOR Allows Cross-Project Secret Disclosure
An IDOR vulnerability in n8n’s public variables API allows authenticated users to read project variables outside their authorized scope, exposing secrets across…
- Article
CVE-2026-21894: n8n Missing Stripe-Signature Verification Allows Forged Webhooks
Authentication bypass in n8n’s StripeTrigger node allows unauthenticated attackers to forge arbitrary Stripe webhooks without knowing the signing secret.
- Article
CVE-2026-25055: n8n Arbitrary File Write on Remote Systems via SSH Node
Path traversal vulnerability in n8n’s Webhook node allows attackers to write files to arbitrary locations on remote servers connected via SSH.
- Article
Best AI-Powered Application Security Testing Tools
Compare the best AI-powered application security testing tools. Find which tools detect business logic flaws and broken access control.
- Article
Codex Security: Complete Guide to Codex Security’s Code Vulnerability Scanner
Learn how Codex Security detects code vulnerabilities through semantic analysis. A complete guide covering methodology and performance.
- Article
Gecko Security vs ZeroPath: Which Is Better?
Gecko Security vs ZeroPath, compared. See which SAST tool finds authorization bugs, handles microservices, and reduces false positives better.
- Article
Business Logic Is AppSec’s Unsolved Problem
Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the g…
Showing 1 - 8 of 8 results