N8n Io
52 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-77068
HIGH 8.7
N8n — n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-…
2026-08-20
CVE-2026-77069
LOW 2.3
N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorizat…
2026-08-20
CVE-2026-77070
HIGH 7.1
N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, D…
2026-08-20
CVE-2026-77071
HIGH 7.1
N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase no…
2026-08-20
CVE-2026-77072
HIGH 8.4
N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node'…
2026-08-20
CVE-2026-77073
MEDIUM 5.3
N8n — n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool wh…
2026-08-20
CVE-2026-77074
MEDIUM 6
N8n — n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw…
2026-08-20
CVE-2026-77075
HIGH 8.4
N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability…
2026-08-20
CVE-2026-77076
HIGH 7.1
N8n — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQ…
2026-08-20
CVE-2026-77077
HIGH 7.2
N8n — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runne…
2026-08-20
CVE-2026-77079
HIGH 7.4
N8n — n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignmen…
2026-08-20
CVE-2026-77080
HIGH 8.7
N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vuln…
2026-08-20
CVE-2026-77081
MEDIUM 5.1
N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL…
2026-08-20
CVE-2026-77082
MEDIUM 5.3
N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of servi…
2026-08-20
CVE-2026-77083
MEDIUM 6
N8n — n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code …
2026-08-20
CVE-2026-77084
HIGH 7.7
N8n — n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. …
2026-08-20
CVE-2026-77085
MEDIUM 6.3
N8n — n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The t…
2026-08-20
CVE-2026-71539
HIGH 8.9
N8n — n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone …
2026-08-18
CVE-2026-72749
HIGH 7.1
N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) …
2026-08-11
CVE-2026-72750
MEDIUM 5.3
N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute…
2026-08-11
CVE-2026-72762
HIGH 7.7
N8n — n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Ima…
2026-08-11
CVE-2026-72763
HIGH 7.2
N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials an…
2026-08-11
CVE-2026-72764
MEDIUM 5.8
N8n — n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected …
2026-08-11
CVE-2026-72765
HIGH 8.7
N8n — n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authen…
2026-08-11
CVE-2026-72766
HIGH 8.2
N8n — n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the…
2026-08-11
CVE-2026-72767
HIGH 8.7
N8n — n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability…
2026-08-11
CVE-2026-72768
MEDIUM 6.4
N8n — n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Cl…
2026-08-11
CVE-2026-72769
MEDIUM 6.1
N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engi…
2026-08-11
CVE-2026-72770
HIGH 7.1
N8n — n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-ta…
2026-08-11
CVE-2026-72771
HIGH 7.1
N8n — n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM n…
2026-08-11
CVE-2026-72772
HIGH 8.9
N8n — n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login fea…
2026-08-11
CVE-2026-72773
MEDIUM 4.9
N8n — n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-sea…
2026-08-11
CVE-2026-72774
HIGH 7.1
N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. A…
2026-08-11
CVE-2026-72775
MEDIUM 5.8
N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, wh…
2026-08-11
CVE-2026-65014
MEDIUM 6.3
N8n — n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/…
2026-07-22
CVE-2026-65015
HIGH 7.2
N8n — n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the nod…
2026-07-22
CVE-2026-65016
HIGH 7.7
N8n — n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SS…
2026-07-22
CVE-2026-65589
MEDIUM 5.1
N8n — n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution da…
2026-07-22
CVE-2026-65590
MEDIUM 5.5
N8n — n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in…
2026-07-22
CVE-2026-65591
HIGH 8.9
N8n — n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An…
2026-07-22
CVE-2026-65592
HIGH 8.4
N8n — n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resour…
2026-07-22
CVE-2026-65593
MEDIUM 6.3
N8n — n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dy…
2026-07-22
CVE-2026-65594
MEDIUM 5.1
N8n — n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuanc…
2026-07-22
CVE-2026-65595
HIGH 8.9
N8n — n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange modul…
2026-07-22
CVE-2026-65596
MEDIUM 5.1
N8n — n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTT…
2026-07-22
CVE-2026-65597
HIGH 8.2
N8n — n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerabil…
2026-07-22
CVE-2026-65598
HIGH 8.9
N8n — n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation tha…
2026-07-22
CVE-2026-65599
MEDIUM 5.1
N8n — n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured …
2026-07-22
CVE-2026-59206
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated u…
2026-07-09
CVE-2026-59207
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not …
2026-07-09
CVE-2026-59208
HIGH 7.6
N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n insta…
2026-07-09
CVE-2026-59209
HIGH 7.1
N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated m…
2026-07-09