← Browse

N8n Io

52 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-77068 HIGH 8.7 N8n — n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-… 2026-08-20 CVE-2026-77069 LOW 2.3 N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorizat… 2026-08-20 CVE-2026-77070 HIGH 7.1 N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, D… 2026-08-20 CVE-2026-77071 HIGH 7.1 N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase no… 2026-08-20 CVE-2026-77072 HIGH 8.4 N8n — n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node'… 2026-08-20 CVE-2026-77073 MEDIUM 5.3 N8n — n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool wh… 2026-08-20 CVE-2026-77074 MEDIUM 6 N8n — n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw… 2026-08-20 CVE-2026-77075 HIGH 8.4 N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability… 2026-08-20 CVE-2026-77076 HIGH 7.1 N8n — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQ… 2026-08-20 CVE-2026-77077 HIGH 7.2 N8n — n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runne… 2026-08-20 CVE-2026-77079 HIGH 7.4 N8n — n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignmen… 2026-08-20 CVE-2026-77080 HIGH 8.7 N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vuln… 2026-08-20 CVE-2026-77081 MEDIUM 5.1 N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL… 2026-08-20 CVE-2026-77082 MEDIUM 5.3 N8n — n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of servi… 2026-08-20 CVE-2026-77083 MEDIUM 6 N8n — n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code … 2026-08-20 CVE-2026-77084 HIGH 7.7 N8n — n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. … 2026-08-20 CVE-2026-77085 MEDIUM 6.3 N8n — n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The t… 2026-08-20 CVE-2026-71539 HIGH 8.9 N8n — n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone … 2026-08-18 CVE-2026-72749 HIGH 7.1 N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) … 2026-08-11 CVE-2026-72750 MEDIUM 5.3 N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute… 2026-08-11 CVE-2026-72762 HIGH 7.7 N8n — n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Ima… 2026-08-11 CVE-2026-72763 HIGH 7.2 N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials an… 2026-08-11 CVE-2026-72764 MEDIUM 5.8 N8n — n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected … 2026-08-11 CVE-2026-72765 HIGH 8.7 N8n — n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authen… 2026-08-11 CVE-2026-72766 HIGH 8.2 N8n — n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the… 2026-08-11 CVE-2026-72767 HIGH 8.7 N8n — n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability… 2026-08-11 CVE-2026-72768 MEDIUM 6.4 N8n — n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Cl… 2026-08-11 CVE-2026-72769 MEDIUM 6.1 N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engi… 2026-08-11 CVE-2026-72770 HIGH 7.1 N8n — n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-ta… 2026-08-11 CVE-2026-72771 HIGH 7.1 N8n — n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM n… 2026-08-11 CVE-2026-72772 HIGH 8.9 N8n — n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login fea… 2026-08-11 CVE-2026-72773 MEDIUM 4.9 N8n — n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-sea… 2026-08-11 CVE-2026-72774 HIGH 7.1 N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. A… 2026-08-11 CVE-2026-72775 MEDIUM 5.8 N8n — n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, wh… 2026-08-11 CVE-2026-65014 MEDIUM 6.3 N8n — n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/… 2026-07-22 CVE-2026-65015 HIGH 7.2 N8n — n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the nod… 2026-07-22 CVE-2026-65016 HIGH 7.7 N8n — n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SS… 2026-07-22 CVE-2026-65589 MEDIUM 5.1 N8n — n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution da… 2026-07-22 CVE-2026-65590 MEDIUM 5.5 N8n — n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in… 2026-07-22 CVE-2026-65591 HIGH 8.9 N8n — n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An… 2026-07-22 CVE-2026-65592 HIGH 8.4 N8n — n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resour… 2026-07-22 CVE-2026-65593 MEDIUM 6.3 N8n — n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dy… 2026-07-22 CVE-2026-65594 MEDIUM 5.1 N8n — n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuanc… 2026-07-22 CVE-2026-65595 HIGH 8.9 N8n — n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange modul… 2026-07-22 CVE-2026-65596 MEDIUM 5.1 N8n — n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTT… 2026-07-22 CVE-2026-65597 HIGH 8.2 N8n — n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerabil… 2026-07-22 CVE-2026-65598 HIGH 8.9 N8n — n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation tha… 2026-07-22 CVE-2026-65599 MEDIUM 5.1 N8n — n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured … 2026-07-22 CVE-2026-59206 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated u… 2026-07-09 CVE-2026-59207 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not … 2026-07-09 CVE-2026-59208 HIGH 7.6 N8n — n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n insta… 2026-07-09 CVE-2026-59209 HIGH 7.1 N8n — n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated m… 2026-07-09