快来看,n8n更新了!Metabase安全事件更新

qimuai 发布于 阅读:4 一手编译

快来看,n8n更新了!Metabase安全事件更新

内容来源:https://blog.n8n.io/metabase-security-incident-update/

内容总结:

n8n披露第三方工具安全事件,建议部分用户重置密码

2026年8月6日,自动化工作流平台n8n对外披露一起涉及第三方分析工具Metabase的安全事件。该工具为n8n内部使用,未经授权的异常活动发生于2026年8月3日。目前,Metabase已修复相关漏洞。

n8n在事件发生后立即联合安全、法务及数据团队展开调查。调查确认,有第三方未经授权访问并查询了n8n Metabase环境中的部分数据。

受影响数据范围

经核实,在所有用户(包括自托管用户和n8n云服务用户)中,共有136条记录被访问,内容涉及姓名和电子邮件地址。其中5条记录包含n8n云账户的bcrypt加密密码(自托管用户的密码从不与n8n共享)。由于查询返回的数据行为动态且不确定,目前无法确认具体哪些记录遭到访问。

此外,调查还发现一个此前已修复的历史性漏洞,曾导致少量n8n云账户密码以明文形式存储。虽然n8n认为这些记录在此次事件中被访问的可能性较低,但已主动联系全部25位相关账户持有人,以防万一。

已采取的应对措施

Metabase已修补漏洞、终止相关会话并撤销事件中使用的凭证。n8n同步审查了自身审计日志,轮换可能受影响的凭证,修复历史漏洞对用户的影响,并已向数据保护官及柏林数据保护与信息自由专员进行通报。

用户应如何处理

如有疑问,可联系n8n官方邮箱 help@n8n.io。n8n团队对此次事件可能引发的担忧表示歉意,并重申将严肃对待账户安全。

中文翻译:

我们在2026年8月6日获悉一起安全事件,该事件影响了Metabase——一个由n8n内部使用的第三方分析工具。该未授权活动发生于2026年8月3日——Metabase此后已修复导致该问题的漏洞。

我们立即与Metabase以及我们的安全、法律和数据团队展开了调查。调查确认,一名未授权的第三方访问并查询了通过n8n的Metabase环境可获得的某些数据。

我们发布这份更新,是为了说明我们的调查发现,以及我们建议少量受影响账户采取的措施。

涉及哪些信息

我们已确认,在我们所有用户(包括自托管用户和n8n Cloud用户)中,共有136条包含姓名和电子邮件地址的记录被访问。其中5条记录包含n8n Cloud账户的bcrypt加密密码,自托管密码绝不会与n8n共享。由于所使用的查询每次运行时返回的行是可变且非确定性的,我们无法确定哪些具体记录被访问过。

我们的调查还发现了一个历史性漏洞(此前已修复),该漏洞曾导致少量n8n Cloud账户密码以明文形式存储。虽然我们认为这些记录在此次事件中被访问的可能性不大,但作为预防措施,我们已直接联系了全部25位相关账户持有人。

我们已采取的措施

Metabase已修复该漏洞、终止了相关会话,并撤销了事件中使用的凭据。自收到通知以来,我们一直在审查我们自己的审计日志;轮换了可能受到影响的凭据;修复了受历史漏洞影响的用户;并已通知我们的数据保护官以及柏林数据保护和信息自由专员。

您应采取的步骤

如果您收到了我们关于此事件的直接邮件,请按照该邮件中的说明操作,并尽快重置您的密码。

如果我们没有直接联系您,您仍然可以选择重置您的n8n Cloud密码作为额外预防措施。

您可以随时在帮助中心文章中描述的页面上重置密码。

如有疑问

如果您对本通知或您的账户有任何疑问,请联系help@n8n.io。

我们严肃对待您账户的安全,并对由此可能引起的担忧深表歉意。

n8n团队

英文来源:

We were made aware on 6 August 2026 of a security incident affecting Metabase, a third-party analytics tool used internally by n8n. The unauthorised activity took place on 3 August 2026 - Metabase has since patched the vulnerability that allowed it.
We immediately began an investigation with Metabase and our security, legal, and data teams. Our investigation confirmed that an unauthorized third party accessed and queried certain data available through n8n’s Metabase environment.
We're publishing this update to explain what we found and the action we're recommending for a small number of affected accounts.
What information was involved
We have confirmed that 136 records containing names and email addresses were accessed across all of our users, both self-hosted and n8n Cloud. Five of these records contained bcrypt-hashed passwords of n8n Cloud accounts, self-hosted passwords are never shared with n8n. Because the queries used returned a variable, non-deterministic set of rows each time they are run, we cannot determine which specific records were accessed.
Our investigation also identified a historical bug, which was previously fixed, that caused a small number of n8n Cloud account passwords to be stored in plain text. Whilst we consider it unlikely that these records were accessed during this incident, we have contacted all 25 account holders directly as a precaution.
What we have done
Metabase has patched the vulnerability, terminated the relevant sessions, and revoked the credentials used in the incident. Since being notified, we have been reviewing our own audit logs; rotated potentially affected credentials; rectified any users affected by the historical bug; and notified our Data Protection Officer as well as the Berlin Commissioner for Data Protection and Freedom of Information.
What you should do
If you received a direct email from us about this incident, please follow the instructions in that email and reset your password as soon as possible.
If we have not directly contacted you about this, you may still choose to reset your n8n Cloud password as an additional precaution.
You can reset your password at any time on the page described in this helpdesk article.
Questions
If you have questions about this notice or your account, please contact help@n8n.io.
We take the security of your account seriously and are sorry for the concern this may cause.
The n8n team

n8n

文章目录


    扫描二维码,在手机上阅读