n8n
npm105 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting n8npage 2 of 3
- CVE-2026-49444HIGHCVSS 8.5EG 8.5✓ Fixed in 2.21.82026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary cod…
- CVE-2026-49465HIGHCVSS 7.7EG 7.7✓ Fixed in 2.21.82026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's …
- CVE-2026-54301MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Conten…
- CVE-2026-54302MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webh…
- CVE-2026-54303MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabl…
- CVE-2026-54304HIGHCVSS 7.7EG 7.7✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could …
- CVE-2026-54305CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope…
- CVE-2026-54306MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object cop…
- CVE-2026-54307CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credentia…
- CVE-2026-54308HIGHCVSS 7.2EG 7.2✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL …
- CVE-2026-54309CRITICALCVSS 10.0EG 10.0✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. A…
- CVE-2026-54310CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allow…
- CVE-2026-54311HIGHCVSS 7.7EG 7.7✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox cont…
- CVE-2026-54312HIGHCVSS 8.5EG 8.5✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as th…
- CVE-2026-54313HIGHCVSS 7.7EG 7.7✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before…
- CVE-2026-54314HIGHCVSS 7.5EG 7.5✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated att…
- CVE-2026-56348CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.20.02026-05-19
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential ac…
- CVE-2026-56349MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.10.02026-07-15
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and comprom…
- CVE-2026-56350HIGHCVSS 7.7EG 7.7✓ Fixed in 2.8.02026-07-01
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizationa…
- CVE-2026-56351CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.4.02026-02-26
n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Att…
- CVE-2026-56352MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2.19.32026-07-15
n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the file-access checks enforced by other file-reading nodes. Although hidd…
- CVE-2026-56353MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2.10.12026-07-15
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication chec…
- CVE-2026-56354MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.123.242026-07-10
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox poli…
- CVE-2026-56356MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.13.32026-07-01
n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.…
- CVE-2026-56357MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.5.02026-02-26
n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to tri…
- CVE-2026-56358MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.123.252026-03-27
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious s…
- CVE-2026-56359MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.6.42026-07-08
n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious …
- CVE-2026-56360MEDIUMCVSS 4.0EG 4.0✓ Fixed in 2.6.22026-07-08
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious …
- CVE-2026-56775MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.25.72026-07-08
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:…
- CVE-2026-56776HIGHCVSS 7.4EG 7.4✓ Fixed in 2.25.72026-07-08
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user w…
- CVE-2026-56777MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2.25.72026-07-01
n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypa…
- CVE-2026-56778MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2.25.72026-07-08
n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only…
- CVE-2026-58661MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.123.582026-07-10
n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota check does not account for files already written to the shared temporary…
- CVE-2026-59206HIGHCVSS 7.1EG 7.1✓ Fixed in 2.27.42026-07-09
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or impo…
- CVE-2026-59207MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.27.42026-07-09
n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, …
- CVE-2026-59208MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2.27.42026-07-09
n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JW…
- CVE-2026-59209MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.27.42026-07-09
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object in…
- CVE-2026-59253MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2.28.02026-07-08
n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request…
- CVE-2026-59254MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.27.42026-07-15
n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret val…
- CVE-2026-59257HIGHCVSS 8.8EG 8.8✓ Fixed in 2.27.42026-07-08
n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the…
- CVE-2026-59259MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.27.42026-07-15
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with…
- CVE-2026-65014MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.27.42026-07-22
n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to …
- CVE-2026-65015HIGHCVSS 7.2EG 7.2✓ Fixed in 2.29.82026-07-22
n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that …
- CVE-2026-65016HIGHCVSS 7.7EG 7.7✓ Fixed in 2.29.82026-07-22
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent as…
- CVE-2026-65589MEDIUMCVSS 5.1EG 5.1✓ Fixed in 2.29.82026-07-22
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can r…
- CVE-2026-65590MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.29.82026-07-22
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesy…
- CVE-2026-65591HIGHCVSS 8.9EG 8.9✓ Fixed in 2.29.82026-07-22
n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achie…
- CVE-2026-65592HIGHCVSS 8.4EG 8.4✓ Fixed in 2.29.82026-07-22
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. A…
- CVE-2026-65593MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.29.82026-07-22
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing confi…
- CVE-2026-65594MEDIUMCVSS 5.1EG 5.1✓ Fixed in 2.29.82026-07-22
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. O…
Check whether n8n is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for n8n CVEs against the assets you own.
Start Free Scan →