<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — n8n</title><description>Vulnerabilities in n8n, the open-source workflow automation platform — including Enterprise-only auth, token-exchange, and OEM-integration flaws that surface as CVEs against multi-issuer SSO deployments. Combined article + CVE feed for the n8n beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2025-68613 — n8n Improper Control of Dynamically-Managed Code Resources Vulnerability</title><link>https://0daynews.com/cve/cve-2025-68613/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-68613/</guid><description>n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>n8n</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-59208 — n8n cross-issuer token exchange authentication bypass</title><link>https://0daynews.com/cve/cve-2026-59208/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-59208/</guid><description>n8n Enterprise instances with two or more trusted JWT issuers matched incoming tokens on `sub` alone, letting a valid token from one issuer log in as a same-`sub` user under another. Fixed in 2.27.4 and 2.28.1.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>n8n</category><category>medium</category><category>cve</category></item><item><title>n8n Sandbox Escape Bypasses February CVE-2026-27577 Patch</title><link>https://0daynews.com/articles/2026-07-27-n8n-sandbox-escape-cve-2026-27577-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-n8n-sandbox-escape-cve-2026-27577-bypass/</guid><description>Security Joes found a new n8n expression-sandbox escape while auditing the February CVE-2026-27577 fix. Update to 2.31.5 or 2.32.1.</description><pubDate>Mon, 27 Jul 2026 14:00:00 GMT</pubDate><category>n8n</category><category>article</category></item><item><title>n8n cross-issuer JWT bypass logs attackers in as anyone</title><link>https://0daynews.com/articles/2026-07-17-n8n-cve-2026-59208-cross-issuer-token-exchange-sub-iss/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-n8n-cve-2026-59208-cross-issuer-token-exchange-sub-iss/</guid><description>CVE-2026-59208: n8n Enterprise instances trusting two or more JWT issuers matched incoming tokens on `sub` alone, letting a token from issuer A log in as B&apos;s user.</description><pubDate>Fri, 17 Jul 2026 00:20:00 GMT</pubDate><category>n8n</category><category>article</category></item></channel></rss>