← Browse

N8n

47 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-56349 MEDIUM 6.3 N8n — n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attacke… 2026-07-15 CVE-2026-56352 MEDIUM 5.3 N8n — n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile sourc… 2026-07-15 CVE-2026-56353 MEDIUM 6.3 N8n — n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-defau… 2026-07-15 CVE-2026-59254 MEDIUM 6.3 N8n — n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly reso… 2026-07-15 CVE-2026-59259 MEDIUM 6 N8n — n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secret… 2026-07-15 CVE-2026-56354 MEDIUM 5.1 N8n — n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and op… 2026-07-10 CVE-2026-58661 MEDIUM 5.3 N8n — n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in th… 2026-07-10 CVE-2026-59206 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated u… 2026-07-09 CVE-2026-59207 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not … 2026-07-09 CVE-2026-59208 HIGH 7.6 N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n insta… 2026-07-09 CVE-2026-59209 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated m… 2026-07-09 CVE-2026-56359 MEDIUM 4.8 N8n — n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authent… 2026-07-08 CVE-2026-56360 MEDIUM 6.3 N8n — n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the Zende… 2026-07-08 CVE-2026-56775 MEDIUM 5.3 N8n — n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation t… 2026-07-08 CVE-2026-56776 MEDIUM 5.3 N8n — n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/t… 2026-07-08 CVE-2026-56778 MEDIUM 5.3 N8n — n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry … 2026-07-08 CVE-2026-59253 MEDIUM 5.3 N8n — n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign work… 2026-07-08 CVE-2026-59257 MEDIUM 5.3 N8n — n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the… 2026-07-08 CVE-2025-71380 HIGH 8.7 N8n — The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system wh… 2026-07-04 CVE-2026-56350 MEDIUM 6 N8n — n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable S… 2026-06-30 CVE-2026-56356 MEDIUM 5.1 N8n — n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a … 2026-06-30 CVE-2026-56777 MEDIUM 5.3 N8n — n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in… 2026-06-30 CVE-2026-56351 MEDIUM 5.3 N8n — n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes … 2026-06-24 CVE-2026-56358 MEDIUM 5.1 N8n — n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cro… 2026-06-24 CVE-2026-44789 CRITICAL 9.4 N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated us… 2026-06-23 CVE-2026-44790 CRITICAL 9.4 N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated us… 2026-06-23 CVE-2026-44791 CRITICAL 9.4 N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated us… 2026-06-23 CVE-2026-44792 HIGH 8.9 N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with wr… 2026-06-23 CVE-2026-45732 HIGH 8.3 N8n — n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAut… 2026-06-23 CVE-2026-49444 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated us… 2026-06-23 CVE-2026-49465 MEDIUM 6 N8n — n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated us… 2026-06-23 CVE-2026-54301 HIGH 7 N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated us… 2026-06-23 CVE-2026-54302 HIGH 7 N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated us… 2026-06-23 CVE-2026-54303 MEDIUM 6.8 N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Tea… 2026-06-23 CVE-2026-54304 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated us… 2026-06-23 CVE-2026-54305 HIGH 8.9 N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints … 2026-06-23 CVE-2026-54306 MEDIUM 6.3 N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerab… 2026-06-23 CVE-2026-54307 HIGH 8.5 N8n — n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user… 2026-06-23 CVE-2026-54308 MEDIUM 6.3 N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger a… 2026-06-23 CVE-2026-54309 HIGH 8.8 N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run i… 2026-06-23 CVE-2026-54310 MEDIUM 6.5 N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with per… 2026-06-23 CVE-2026-54311 MEDIUM 6 N8n — n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with per… 2026-06-23 CVE-2026-54312 HIGH 7.2 N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to … 2026-06-23 CVE-2026-54313 MEDIUM 6.5 N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit … 2026-06-23 CVE-2026-54314 MEDIUM 6.3 N8n — n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operati… 2026-06-23 CVE-2026-56348 MEDIUM 5.3 N8n — n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/o… 2026-06-22 CVE-2026-56357 MEDIUM 6.3 N8n — n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that… 2026-06-22