I mean, that’s like saying that software on Android contains vulnerabilities because of the Play Store. n8n itself is a full application that someone’s developed, not just a library. n8n being a brand new ‘powerful automation’ platform is something you’d not want to publish online.
Further to this, as no-one ever seems to read the fucking CVE (in general and not aimed at you) - Exploiting requires an authenticated account! “Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime.” This is what you get in a rapidly developed piece of software that has access to low-level APIs
I mean, that’s like saying that software on Android contains vulnerabilities because of the Play Store. n8n itself is a full application that someone’s developed, not just a library. n8n being a brand new ‘powerful automation’ platform is something you’d not want to publish online.
Further to this, as no-one ever seems to read the fucking CVE (in general and not aimed at you) - Exploiting requires an authenticated account! “Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime.” This is what you get in a rapidly developed piece of software that has access to low-level APIs