<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[critical security patch 2.17.5]]></title><description><![CDATA[<p dir="auto">Hello,<br />
I just got this notification from the N8N security team regarding several issues, one of them beeing a 10/10 CVE that the current Cloudron package is vulnerable to:</p>
<ul>
<li>critical |** XML Node Prototype Pollution to RCE** ( <a href="https://email.info.n8n.io/e/c/eyJlbWFpbF9pZCI6ImRnU2kyZ1VEQU82M0V1MjNFZ0dkdGF2RVZSOHZ3ZU1FdWI5RTBnYz0iLCJocmVmIjoiaHR0cHM6Ly9naXRodWIuY29tL244bi1pby9uOG4vc2VjdXJpdHkvYWR2aXNvcmllcy9HSFNBLWhxcjQtaDN4di05bTNyIiwiaW50ZXJuYWwiOiJhMmRhMDUwYThkMTBlZWI3MTIiLCJsaW5rX2lkIjo5Njk5fQ/a4314244308c4a37f6fc094d3326c00dd34089e59300cb50ac52fe0e5c86c6b5" target="_blank" rel="noopener noreferrer nofollow ugc">GHSA-hqr4-h3xv-9m3r</a> )</li>
<li>critical |** Prototype Pollution in XML Webhook Body Parser Leads to RCE** ( <a href="https://email.info.n8n.io/e/c/eyJlbWFpbF9pZCI6ImRnU2kyZ1VEQU82M0V1MjNFZ0dkdGF2RVZSOHZ3ZU1FdWI5RTBnYz0iLCJocmVmIjoiaHR0cHM6Ly9naXRodWIuY29tL244bi1pby9uOG4vc2VjdXJpdHkvYWR2aXNvcmllcy9HSFNBLXE1ZjQtOTlqdi1wZ2c1IiwiaW50ZXJuYWwiOiJhMmRhMDUwYThkMTBlZWI3MTIiLCJsaW5rX2lkIjo5NzAwfQ/90b3118102da04693a0c9ba4bebad9b6284b4754627eae24121f7c9970551ce1" target="_blank" rel="noopener noreferrer nofollow ugc">GHSA-q5f4-99jv-pgg5</a> )</li>
<li>high |** Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay** ( <a href="https://email.info.n8n.io/e/c/eyJlbWFpbF9pZCI6ImRnU2kyZ1VEQU82M0V1MjNFZ0dkdGF2RVZSOHZ3ZU1FdWI5RTBnYz0iLCJocmVmIjoiaHR0cHM6Ly9naXRodWIuY29tL244bi1pby9uOG4vc2VjdXJpdHkvYWR2aXNvcmllcy9HSFNBLXI0djYtOWZxYy13NWpyIiwiaW50ZXJuYWwiOiJhMmRhMDUwYThkMTBlZWI3MTIiLCJsaW5rX2lkIjo5NzAxfQ/7868bd681bc91680fb49d5dc2c7beca61a99f7127918c93624cdc02df6400afe" target="_blank" rel="noopener noreferrer nofollow ugc">GHSA-r4v6-9fqc-w5jr</a> )</li>
<li>high |** Python Task Runner Sandbox Escape** ( <a href="https://email.info.n8n.io/e/c/eyJlbWFpbF9pZCI6ImRnU2kyZ1VEQU82M0V1MjNFZ0dkdGF2RVZSOHZ3ZU1FdWI5RTBnYz0iLCJocmVmIjoiaHR0cHM6Ly9naXRodWIuY29tL244bi1pby9uOG4vc2VjdXJpdHkvYWR2aXNvcmllcy9HSFNBLTQ0djYtamhnbS1wM200IiwiaW50ZXJuYWwiOiJhMmRhMDUwYThkMTBlZWI3MTIiLCJsaW5rX2lkIjo5NzAyfQ/05cc887a1c911b9e0f6ee9a4f4010abcdc2ee5caa44627f219d51f52b00cffb0" target="_blank" rel="noopener noreferrer nofollow ugc">GHSA-44v6-jhgm-p3m4</a> )</li>
<li>high |** XSS via MCP OAuth client** ( <a href="https://email.info.n8n.io/e/c/eyJlbWFpbF9pZCI6ImRnU2kyZ1VEQU82M0V1MjNFZ0dkdGF2RVZSOHZ3ZU1FdWI5RTBnYz0iLCJocmVmIjoiaHR0cHM6Ly9naXRodWIuY29tL244bi1pby9uOG4vc2VjdXJpdHkvYWR2aXNvcmllcy9HSFNBLTUzN2otZ3FwYy1wN2ZxIiwiaW50ZXJuYWwiOiJhMmRhMDUwYThkMTBlZWI3MTIiLCJsaW5rX2lkIjo5NzAzfQ/eca2ab811489e22f3ba3c59303a79e7b41b85d020645c941317c23ba607916ee" target="_blank" rel="noopener noreferrer nofollow ugc">GHSA-537j-gqpc-p7fq</a> )</li>
<li>high |** Unauthenticated Denial of Service via MCP Client Registration** ( <a href="https://email.info.n8n.io/e/c/eyJlbWFpbF9pZCI6ImRnU2kyZ1VEQU82M0V1MjNFZ0dkdGF2RVZSOHZ3ZU1FdWI5RTBnYz0iLCJocmVmIjoiaHR0cHM6Ly9naXRodWIuY29tL244bi1pby9uOG4vc2VjdXJpdHkvYWR2aXNvcmllcy9HSFNBLTQ5bTktcGd3dy05dnE2IiwiaW50ZXJuYWwiOiJhMmRhMDUwYThkMTBlZWI3MTIiLCJsaW5rX2lkIjo5NzA0fQ/f488faf63607869bd50304cea4899614028eb41d168b7c1db6819bc5d69b3c40" target="_blank" rel="noopener noreferrer nofollow ugc">GHSA-49m9-pgww-9vq6</a> )</li>
</ul>
<p dir="auto">Please update the package to 2.17.5 as soon as possible.</p>
<p dir="auto">Best,<br />
Dominik</p>
]]></description><link>https://forum.cloudron.io/topic/15430/critical-security-patch-2.17.5</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 22:52:01 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/15430.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 22 Apr 2026 15:12:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to critical security patch 2.17.5 on Wed, 22 Apr 2026 16:20:28 GMT]]></title><description><![CDATA[<p dir="auto">the update is live, thanks!</p>
]]></description><link>https://forum.cloudron.io/post/123864</link><guid isPermaLink="true">https://forum.cloudron.io/post/123864</guid><dc:creator><![CDATA[dominikjannis]]></dc:creator><pubDate>Wed, 22 Apr 2026 16:20:28 GMT</pubDate></item></channel></rss>