n8n
npm140 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting n8npage 2 of 3
- CVE-2026-33751MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2.13.32026-03-25
vulnerable: 2.14.0
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacharacters to pass through unescaped when user-controlled input was interpol…
- CVE-2026-42226HIGHCVSS 7.5EG 7.5✓ Fixed in 1.123.332026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An auth…
- CVE-2026-42227MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projects they are not a member of by supplying…
- CVE-2026-42228MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized …
- CVE-2026-42229HIGHCVSS 8.8EG 8.8✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query st…
- CVE-2026-42230MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be r…
- CVE-2026-42231HIGHCVSS 8.8EG 8.8✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payloa…
- CVE-2026-42232HIGHCVSS 8.8EG 8.8✓ Fixed in 1.123.322026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RC…
- CVE-2026-42233CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be inter…
- CVE-2026-42234HIGHCVSS 8.8EG 8.8✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbi…
- CVE-2026-42235CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth c…
- CVE-2026-42236HIGHCVSS 7.5EG 7.5✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An …
- CVE-2026-42237HIGHCVSS 8.8EG 8.8✓ Fixed in 2.17.42026-05-04
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly …
- CVE-2026-44789CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.20.72026-06-23
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter…
- CVE-2026-44790HIGHCVSS 8.8EG 8.8✓ Fixed in 2.20.72026-06-23
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to …
- CVE-2026-44791CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.20.72026-06-23
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with ot…
- CVE-2026-44792CRITICALCVSS 9.0EG 9.0✓ Fixed in 2.20.72026-06-23
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file c…
- CVE-2026-45732HIGHCVSS 8.1EG 8.1✓ Fixed in 2.20.72026-06-23
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user wi…
- CVE-2026-49444HIGHCVSS 8.5EG 8.5✓ Fixed in 2.21.82026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary cod…
- CVE-2026-49465HIGHCVSS 7.7EG 7.7✓ Fixed in 2.21.82026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's …
- CVE-2026-54301MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Conten…
- CVE-2026-54302MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webh…
- CVE-2026-54303MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabl…
- CVE-2026-54304HIGHCVSS 7.7EG 7.7✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could …
- CVE-2026-54305CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope…
- CVE-2026-54306MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object cop…
- CVE-2026-54307CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credentia…
- CVE-2026-54308HIGHCVSS 7.2EG 7.2✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL …
- CVE-2026-54309CRITICALCVSS 10.0EG 10.0✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. A…
- CVE-2026-54310CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allow…
- CVE-2026-54311HIGHCVSS 7.7EG 7.7✓ Fixed in 2.25.72026-06-16
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox cont…
- CVE-2026-54312HIGHCVSS 8.5EG 8.5✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as th…
- CVE-2026-54313HIGHCVSS 7.7EG 7.7✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before…
- CVE-2026-54314HIGHCVSS 7.5EG 7.5✓ Fixed in 2.24.02026-06-16
n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated att…
- CVE-2026-56348CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.20.02026-05-19
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential ac…
- CVE-2026-56349MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.10.02026-07-15
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and comprom…
- CVE-2026-56350HIGHCVSS 7.7EG 7.7✓ Fixed in 2.8.02026-07-01
n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizationa…
- CVE-2026-56351CRITICALCVSS 9.6EG 9.6✓ Fixed in 2.4.02026-02-26
n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Att…
- CVE-2026-56352MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2.19.32026-07-15
n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the file-access checks enforced by other file-reading nodes. Although hidd…
- CVE-2026-56353MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2.10.12026-07-15
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication chec…
- CVE-2026-56354MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.123.242026-07-10
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox poli…
- CVE-2026-56356MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.13.32026-07-01
vulnerable: 2.14.0
n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.…
- CVE-2026-56357MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.5.02026-02-26
n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to tri…
- CVE-2026-56358MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.123.252026-03-27
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious s…
- CVE-2026-56359MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.6.42026-07-08
n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious …
- CVE-2026-56360MEDIUMCVSS 4.0EG 4.0✓ Fixed in 2.6.22026-07-08
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious …
- CVE-2026-56775MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.25.72026-07-08
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:…
- CVE-2026-56776HIGHCVSS 7.4EG 7.4✓ Fixed in 2.25.72026-07-08
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user w…
- CVE-2026-56777MEDIUMCVSS 5.0EG 5.0✓ Fixed in 2.25.72026-07-01
n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypa…
- CVE-2026-56778MEDIUMCVSS 6.4EG 6.4✓ Fixed in 2.25.72026-07-08
n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only…
Check whether n8n is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for n8n CVEs against the assets you own.
Start Free Scan →