www.vulncheck.com
Remote Code Execution Vulnerabilities in n8n and LibreNMS Disclosed
Article Content
Recent advisories from VulnCheck detail critical remote code execution vulnerabilities affecting n8n versions before 1.123.73 and LibreNMS versions before 26.5.0. The n8n vulnerability, categorized as CWE-78, allows attackers to execute arbitrary code via the Git Node. Similarly, the LibreNMS vulnerability, classified as CWE-77, enables remote code execution through the AboutController. Both vulnerabilities pose significant risks to users of these platforms, with potential for exploitation if not addressed. The advisories recommend immediate action to mitigate these risks. No specific exploitation in the wild was reported at the time of publication, but the vulnerabilities are serious enough to warrant urgent attention.
Key Points: • n8n versions before 1.123.73 and LibreNMS before 26.5.0 are vulnerable to RCE. • CWE-78 and CWE-77 classifications indicate serious command injection risks. • Immediate patching is recommended to prevent potential exploitation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.