N8n
47 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-56349
MEDIUM 6.3
N8n — n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attacke…
2026-07-15
CVE-2026-56352
MEDIUM 5.3
N8n — n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile sourc…
2026-07-15
CVE-2026-56353
MEDIUM 6.3
N8n — n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-defau…
2026-07-15
CVE-2026-59254
MEDIUM 6.3
N8n — n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly reso…
2026-07-15
CVE-2026-59259
MEDIUM 6
N8n — n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secret…
2026-07-15
CVE-2026-56354
MEDIUM 5.1
N8n — n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and op…
2026-07-10
CVE-2026-58661
MEDIUM 5.3
N8n — n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in th…
2026-07-10
CVE-2026-59206
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated u…
2026-07-09
CVE-2026-59207
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not …
2026-07-09
CVE-2026-59208
HIGH 7.6
N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n insta…
2026-07-09
CVE-2026-59209
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated m…
2026-07-09
CVE-2026-56359
MEDIUM 4.8
N8n — n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authent…
2026-07-08
CVE-2026-56360
MEDIUM 6.3
N8n — n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the Zende…
2026-07-08
CVE-2026-56775
MEDIUM 5.3
N8n — n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation t…
2026-07-08
CVE-2026-56776
MEDIUM 5.3
N8n — n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/t…
2026-07-08
CVE-2026-56778
MEDIUM 5.3
N8n — n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry …
2026-07-08
CVE-2026-59253
MEDIUM 5.3
N8n — n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign work…
2026-07-08
CVE-2026-59257
MEDIUM 5.3
N8n — n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the…
2026-07-08
CVE-2025-71380
HIGH 8.7
N8n — The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system wh…
2026-07-04
CVE-2026-56350
MEDIUM 6
N8n — n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable S…
2026-06-30
CVE-2026-56356
MEDIUM 5.1
N8n — n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a …
2026-06-30
CVE-2026-56777
MEDIUM 5.3
N8n — n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in…
2026-06-30
CVE-2026-56351
MEDIUM 5.3
N8n — n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes …
2026-06-24
CVE-2026-56358
MEDIUM 5.1
N8n — n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cro…
2026-06-24
CVE-2026-44789
CRITICAL 9.4
N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated us…
2026-06-23
CVE-2026-44790
CRITICAL 9.4
N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated us…
2026-06-23
CVE-2026-44791
CRITICAL 9.4
N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated us…
2026-06-23
CVE-2026-44792
HIGH 8.9
N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with wr…
2026-06-23
CVE-2026-45732
HIGH 8.3
N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAut…
2026-06-23
CVE-2026-49444
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated us…
2026-06-23
CVE-2026-49465
MEDIUM 6
N8n — n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated us…
2026-06-23
CVE-2026-54301
HIGH 7
N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated us…
2026-06-23
CVE-2026-54302
HIGH 7
N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated us…
2026-06-23
CVE-2026-54303
MEDIUM 6.8
N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Tea…
2026-06-23
CVE-2026-54304
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated us…
2026-06-23
CVE-2026-54305
HIGH 8.9
N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints …
2026-06-23
CVE-2026-54306
MEDIUM 6.3
N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerab…
2026-06-23
CVE-2026-54307
HIGH 8.5
N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user…
2026-06-23
CVE-2026-54308
MEDIUM 6.3
N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger a…
2026-06-23
CVE-2026-54309
HIGH 8.8
N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run i…
2026-06-23
CVE-2026-54310
MEDIUM 6.5
N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with per…
2026-06-23
CVE-2026-54311
MEDIUM 6
N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with per…
2026-06-23
CVE-2026-54312
HIGH 7.2
N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to …
2026-06-23
CVE-2026-54313
MEDIUM 6.5
N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit …
2026-06-23
CVE-2026-54314
MEDIUM 6.3
N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operati…
2026-06-23
CVE-2026-56348
MEDIUM 5.3
N8n — n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/o…
2026-06-22
CVE-2026-56357
MEDIUM 6.3
N8n — n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that…
2026-06-22