n8n
npm157 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting n8npage 4 of 4
- CVE-2026-86083HIGHCVSS 8.8EG 8.8✓ Fixed in 1.123.762026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpo…
- CVE-2026-86084MEDIUMCVSS 5.5EG 5.5✓ Fixed in 1.123.762026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise…
- CVE-2026-86085MEDIUMCVSS 4.9EG 4.9✓ Fixed in 2.38.22026-09-08
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A …
- CVE-2026-86993MEDIUMCVSS 4.9EG 4.9✓ Fixed in 1.123.762026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check.…
- CVE-2026-86994MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.123.762026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deac…
- CVE-2026-86995MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.123.762026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration withou…
- CVE-2026-86996MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.38.22026-09-08
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool.…
Check whether n8n is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for n8n CVEs against the assets you own.
Start Free Scan →