0.2.0
7 months ago
7 months ago
Known vulnerabilities in the @n8n/api-types package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@n8n/api-types is a fair-code workflow automation platform with native AI capabilities Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via a lack of MIME type validation on uploaded binary files, which can be controlled through a GET parameter. This allows an authenticated attacker with member-level privileges to upload a crafted HTML file containing malicious code. If another authenticated user visits the binary data endpoint with the MIME type specified as How to fix Cross-site Scripting (XSS)? Upgrade | <0.25.0 |