CVE-2026-33751 identifies an LDAP filter injection vulnerability (CWE-90) in n8n, an open-source workflow automation platform. This flaw allows unescaped LDAP metacharacters to pass through when user-controlled input is interpolated into LDAP search filters within specific workflow configurations. With a CVSS score of 4.8 (Medium), exploitation requires high attack complexity, as it depends on external user input being passed via expressions into the LDAP node's search parameters, potentially leading to unintended LDAP record retrieval or authentication bypass. There is currently no evidence of active exploitation, public exploit code is unavailable, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.123.27CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
>= 2.0.0, < 2.13.3CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | ||
2.14.0CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:2.14.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.