The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade @n8n/ai-utilities to version 0.24.3, 0.25.1 or higher.
@n8n/ai-utilities is an Utilities for building AI nodes in n8n
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the searxngSearch function in packages/@n8n/ai-utilities/src/web-search/searxng-search.ts, which issues its request to the credential's API URL with the global fetch rather than a client carrying the centralized SSRF policy, so the URL is never validated against it. A user with permission to create SearXNG credentials and configure a personal agent can make the server connect to an internal host and read the response, by setting that credential's API URL to the internal address and reading the Agent chat output. This requires an authenticated account with those two permissions, and it matters specifically on instances running with N8N_SSRF_PROTECTION_ENABLED=true, where the request would otherwise be screened.