cbcvebase.

N8N-Io N8N vulnerabilities

173 known vulnerabilities affecting n8n-io/n8n.

Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72

Vulnerabilities

Page 2 of 9
CVE-2026-25055P2HIGHCVSS 8.1fixed in 1.123.12fixed in 2.4.02026-02-04
CVE-2026-25055 [HIGH] CWE-22 CVE-2026-25055: n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workf n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating their metadata the vulnerability can lead to files being written to unintended locations on those remote systems potentially leading to remote code execut
nvd
CVE-2026-72765P2CRITICALCVSS 9.9fixed in 2.32.1fixed in 2.31.52026-08-11
CVE-2026-72765 [CRITICAL] CWE-94 CVE-2026-72765: n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.
nvd
CVE-2026-85168P2HIGHCVSS 8.8fixed in 1.123.73fixed in 2.36.2+1 more2026-09-03
CVE-2026-85168 [HIGH] CWE-78 CVE-2026-85168: n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in th n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter and merge-driver key families. A repository with local configuration setting one of those keys together wi
nvd
CVE-2025-62726P2HIGHCVSS 8.8fixed in 1.113.02025-10-30
CVE-2025-62726 [HIGH] CWE-829 CVE-2025-62726: n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulner n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote repository containing a pre-commit hook, the subsequent use of the Commit operation in the Git Node can inadvertentl
nvd
CVE-2026-72764P2HIGHCVSS 8.8fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72764 [HIGH] CWE-668 CVE-2026-72764: n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability. Th
nvd
CVE-2026-33696P2HIGHCVSS 8.8fixed in 1.123.27v>= 2.0.0-rc.0, < 2.13.3+1 more2026-03-25
CVE-2026-33696 [HIGH] CWE-1321 CVE-2026-33696: n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. By supplying a crafted parameters as part of node configuration, an attacker could write attacker
nvd
CVE-2026-65595P2HIGHCVSS 8.8fixed in 2.30.1fixed in 2.29.82026-07-22
CVE-2026-65595 [HIGH] CWE-269 CVE-2026-65595: n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exch n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privileged user who can obtain a valid external JWT trusted by a configured issuer can use the resulting access token to in
nvd
CVE-2026-44789P2CRITICALCVSS 9.9fixed in 1.123.43v>= 2.0.0-rc.0, < 2.20.7+1 more2026-06-23
CVE-2026-44789 [CRITICAL] CWE-1321 CVE-2026-44789: n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authen n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance. This vulner
nvd
CVE-2026-42233P2CRITICALCVSS 9.8fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42233 [CRITICAL] CWE-89 CVE-2026-42233: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input
nvd
CVE-2026-54307P2CRITICALCVSS 9.6fixed in 1.123.55v>= 2.0.0-rc.0, < 2.25.7+1 more2026-06-23
CVE-2026-54307 [CRITICAL] CWE-863 CVE-2026-54307: n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member- n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced partially leading to cross-user credential access. This issue affects in
nvd
CVE-2026-77068P2HIGHCVSS 8.8≥ 2.34.0, < 2.34.1≥ 2.0.0, < 2.33.42026-08-20
CVE-2026-77068 [HIGH] CWE-22 CVE-2026-77068: n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without validating path-traversal sequences. An authenticated user with global:member p
nvd
CVE-2026-33660P2HIGHCVSS 8.8fixed in 1.123.27v>= 2.0.0-rc.0, < 2.13.3+1 more2026-03-25
CVE-2026-33660 [HIGH] CWE-94 CVE-2026-33660: n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n host and achieve remote code execution. The AlaSQL sandbox did not sufficiently restrict certain SQL statem
nvd
CVE-2026-42234P2HIGHCVSS 8.8fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42234 [HIGH] CWE-94 CVE-2026-42234: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This issue only affects instances where the Python Task Runner is
nvd
CVE-2026-42235P2CRITICALCVSS 9.6fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42235 [CRITICAL] CWE-79 CVE-2026-42235: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that access, a toast notification would render the injected
nvd
CVE-2026-103255P2CRITICALCVSS 9.0fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103255 [CRITICAL] CWE-73 CVE-2026-103255: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administr
nvd
CVE-2026-65591P2HIGHCVSS 8.8fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65591 [HIGH] CWE-917 CVE-2026-65591: n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member h n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions.
nvd
CVE-2026-72775P2HIGHCVSS 8.8fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72775 [HIGH] CWE-89 CVE-2026-72775: n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigge n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An authenticated user can inject arbitrary SQL executed against the connected PostgreSQL database with the
nvd
CVE-2026-65590P2CRITICALCVSS 9.8fixed in 2.30.1fixed in 2.29.82026-07-22
CVE-2026-65590 [CRITICAL] CWE-78 CVE-2026-65590: n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the co
nvd
CVE-2025-65964P3HIGHCVSS 8.8v>= 0.123.1, < 1.119.22025-12-09
CVE-2025-65964 [HIGH] CWE-829 CVE-2025-65964: n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have ade n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation allows workflows to set arbitrary Git configuration values, including core.hooksPath, which can point to a malicious Git hook that executes arbitrary comma
nvd
CVE-2026-65015P2HIGHCVSS 8.8fixed in 2.30.1fixed in 2.29.82026-07-22
CVE-2026-65015 [HIGH] CWE-863 CVE-2026-65015: n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature whe n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessing credential secrets without proper authorization ve
nvd
N8N-Io N8N vulnerabilities | cvebase