n8n
npm140 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting n8npage 1 of 3
- CVE-2023-27562MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.216.12023-05-10
The n8n package 0.218.0 for Node.js allows Directory Traversal.
- CVE-2023-27563HIGHCVSS 8.8EG 8.8✓ Fixed in 0.216.12023-05-10
The n8n package 0.218.0 for Node.js allows Escalation of Privileges.
- CVE-2023-27564HIGHCVSS 7.5EG 7.5✓ Fixed in 0.216.12023-05-10
The n8n package 0.218.0 for Node.js allows Information Disclosure.
- CVE-2025-46343MEDIUMCVSS 5.0EG 5.0✓ Fixed in 1.90.02025-04-29
n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary files, which are accessible to authentic…
- CVE-2025-49592MEDIUMCVSS 4.6EG 4.6✓ Fixed in 1.98.02025-06-26
n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains after logging in, by crafting malicious …
- CVE-2025-49595MEDIUMCVSS 4.9EG 4.9✓ Fixed in 1.99.02025-07-03
n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or filesystem-v2://). This allows authenticated a…
- CVE-2025-52478HIGHCVSS 8.7EG 8.7✓ Fixed in 1.98.22025-08-19
n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifically in the Form Trigger node's HTML form element. An authenticated attacker can inject m…
- CVE-2025-52554MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.99.12025-07-03
n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow executions that they do not own or that…
- CVE-2025-57749MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.106.02025-08-20
n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly…
- CVE-2025-58177MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.107.02025-09-15
n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trig…
- CVE-2025-61914HIGHCVSS 7.3EG 7.3✓ Fixed in 1.114.02025-12-26
n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this node responds with HTML content contai…
- CVE-2025-61917HIGHCVSS 7.7EG 7.7✓ Fixed in 1.114.32026-02-04
n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninit…
- CVE-2025-62726HIGHCVSS 8.8EG 8.8✓ Fixed in 1.113.02025-10-30
n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote re…
- CVE-2025-65964HIGHCVSS 8.8EG 8.8✓ Fixed in 1.119.22025-12-09
n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation allows workflows to set arbitrary Git con…
- CVE-2025-68613CRITICALCVSS 9.9EG 9.9⚠ KEV✓ Fixed in 1.121.12025-12-19
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Unde…
- CVE-2025-68668CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.0.02025-12-26
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows ca…
- CVE-2025-68697HIGHCVSS 7.1EG 7.1✓ Fixed in 2.0.02025-12-26
n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can i…
- CVE-2025-68949MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.2.02026-01-13
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accep…
- CVE-2025-71380HIGHCVSS 8.8EG 8.82026-07-04
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially …
- CVE-2026-1470CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.5.12026-01-27
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not …
- CVE-2026-21858CRITICALCVSS 10.0EG 10.0✓ Fixed in 1.121.02026-01-08
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could …
- CVE-2026-21877CRITICALCVSS 9.9EG 9.9✓ Fixed in 1.121.32026-01-08
n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted …
- CVE-2026-21893HIGHCVSS 7.2EG 7.2✓ Fixed in 1.120.32026-02-04
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users wit…
- CVE-2026-21894MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.2.22026-01-08
n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe we…
- CVE-2026-25049CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.5.22026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended syst…
- CVE-2026-25051MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.122.52026-02-04
n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP endpoints. Under certain conditions, the Con…
- CVE-2026-25052CRITICALCVSS 9.9EG 9.9✓ Fixed in 1.123.182026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the…
- CVE-2026-25053CRITICALCVSS 9.9EG 9.9✓ Fixed in 1.123.102026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or rea…
- CVE-2026-25054MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.123.92026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface, including workflow sticky notes and othe…
- CVE-2026-25055HIGHCVSS 8.1EG 8.1✓ Fixed in 1.123.122026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating their metadata the vulnerability can le…
- CVE-2026-25056HIGHCVSS 8.8EG 8.8✓ Fixed in 2.4.02026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files …
- CVE-2026-25115CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.4.82026-02-04
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security bo…
- CVE-2026-25631MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.121.02026-02-06
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domain…
- CVE-2026-27493CRITICALCVSS 9.0EG 9.0✓ Fixed in 2.10.12026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and eva…
- CVE-2026-27494CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.10.12026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could use the Python Code node to escape the sandbox. The sandbox did no…
- CVE-2026-27495CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.10.12026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in the JavaScript Task Runner sandbox to e…
- CVE-2026-27496MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.9.32026-03-25
n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory bu…
- CVE-2026-27497HIGHCVSS 8.8EG 8.8✓ Fixed in 2.10.12026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code…
- CVE-2026-27498HIGHCVSS 8.8EG 8.8✓ Fixed in 2.2.02026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk node with git operations to achieve rem…
- CVE-2026-27577CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.10.12026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user wit…
- CVE-2026-27578MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.10.12026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could inject arbitrary scripts into pages rendered by the n8n applicatio…
- CVE-2026-33660HIGHCVSS 8.8EG 8.8✓ Fixed in 1.123.272026-03-25
vulnerable: 2.14.0
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on…
- CVE-2026-33663MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.13.32026-03-25
vulnerable: 2.14.0
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit chained authorization flaws in n8n's credential pipeline to steal plainte…
- CVE-2026-33665HIGHCVSS 7.5EG 7.5✓ Fixed in 1.121.02026-03-25
n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if the LDAP email attribute matched the lo…
- CVE-2026-33696HIGHCVSS 8.8EG 8.8✓ Fixed in 1.123.272026-03-25
vulnerable: 2.14.0
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GS…
- CVE-2026-33713HIGHCVSS 8.8EG 8.8✓ Fixed in 2.13.32026-03-25
vulnerable: 2.14.0
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection vulnerability in the Data Table Get node.…
- CVE-2026-33720MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2.8.02026-03-25
n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` environment variable is set to `true`, the OAuth callback handler skips ownership verification of the OAuth state parame…
- CVE-2026-33722MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.6.42026-03-25
n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plai…
- CVE-2026-33724HIGHCVSS 7.4EG 7.4✓ Fixed in 2.5.02026-03-25
n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command used for git operations explicitly disabled host key verification. A network attacker pos…
- CVE-2026-33749CRITICALCVSS 9.0EG 9.0✓ Fixed in 2.13.32026-03-25
vulnerable: 2.14.0
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows could craft a workflow that produces an HTML binary data object without…
Check whether n8n is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for n8n CVEs against the assets you own.
Start Free Scan →