N8N-Io N8N vulnerabilities
173 known vulnerabilities affecting n8n-io/n8n.
Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72
Vulnerabilities
Page 3 of 9
CVE-2026-44790P2HIGHCVSS 8.8fixed in 1.123.43v>= 2.0.0-rc.0, < 2.20.7+1 more2026-06-23
CVE-2026-44790 [HIGH] CWE-88 CVE-2026-44790: n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authen
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitrary files from the n8n server potentially leading to full compromise. This vulnerability is fixed in 1.1
nvd
CVE-2026-77080P3HIGHCVSS 8.8fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77080 [HIGH] CWE-78 CVE-2026-77080: n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials c
nvd
CVE-2026-49444P3HIGHCVSS 8.5fixed in 1.123.48v>= 2.0.0-rc.0, < 2.21.8+1 more2026-06-23
CVE-2026-49444 [HIGH] CWE-20 CVE-2026-49444: n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authen
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This vulnerability is fixed in 1.123.48, 2.21.8, and 2.22.4.
nvd
CVE-2026-77084P3HIGHCVSS 8.8fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77084 [HIGH] CWE-78 CVE-2026-77084: n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the
n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reach
nvd
CVE-2026-72762P3HIGHCVSS 8.8fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72762 [HIGH] CWE-434 CVE-2026-72762: n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in th
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory o
nvd
CVE-2026-33713P3HIGHCVSS 8.8fixed in 1.123.26v>= 2.0.0-rc.0, < 2.13.3+1 more2026-03-25
CVE-2026-33713 [HIGH] CWE-89 CVE-2026-33713: n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26,
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection vulnerability in the Data Table Get node. On default SQLite DB, single statements can be manipulated and the attack surface is practically limited. On Postgr
nvd
CVE-2026-42232P3HIGHCVSS 8.8fixed in 1.123.43v>= 2.0.0-rc.0, < 2.20.7+1 more2026-05-04
CVE-2026-42232 [HIGH] CWE-1321 CVE-2026-42232: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1,
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pollution. This issue has been patched in versions 1.123
nvd
CVE-2026-65016P3HIGHCVSS 8.8fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65016 [HIGH] CWE-639 CVE-2026-65016: n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Ent
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role (unlike the token-exchange identity path, which rejects it). An SSO-authenticate
nvd
CVE-2026-77070P3CRITICALCVSS 9.8fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77070 [CRITICAL] CWE-943 CVE-2026-77070: n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence the resolved query (e.g., via externally-controlled data) can inject o
nvd
CVE-2026-44792P3CRITICALCVSS 9.0fixed in 1.123.43v>= 2.0.0-rc.0, < 2.20.7+1 more2026-06-23
CVE-2026-44792 [CRITICAL] CWE-89 CVE-2026-44792: n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attack
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file a
nvd
CVE-2026-42229P3HIGHCVSS 8.8fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42229 [HIGH] CWE-89 CVE-2026-42229: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1,
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query strings without escaping or parameterization. In workflows where external user input is passed via expressions into th
nvd
CVE-2026-77079P3HIGHCVSS 8.8≥ 2.34.0, < 2.34.1≥ 2.0.0, < 2.33.42026-08-20
CVE-2026-77079 [HIGH] CWE-639 CVE-2026-77079: n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (r
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:managePr
nvd
CVE-2026-42237P3HIGHCVSS 8.8fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42237 [HIGH] CWE-89 CVE-2026-42237: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1,
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and update keys into query strings without identifier escap
nvd
CVE-2026-103253P3HIGHCVSS 8.7fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103253 [HIGH] CWE-89 CVE-2026-103253: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with
nvd
CVE-2026-45732P3HIGHCVSS 8.1fixed in 1.123.43v>= 2.0.0-rc.0, < 2.20.7+1 more2026-06-23
CVE-2026-45732 [HIGH] CWE-639 CVE-2026-45732: n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-only access to a shared credential could initiate an OAuth reconnect flow and overwrite the stored token m
nvd
CVE-2026-85165P3CRITICALCVSS 9.9fixed in 2.36.2fixed in 2.35.42026-09-03
CVE-2026-85165 [CRITICAL] CWE-95 CVE-2026-85165: n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until r
nvd
CVE-2026-86076P3HIGHCVSS 8.8v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86076 [HIGH] CWE-94 CVE-2026-86076: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expre
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __sanitize could rebind the sanitizer and reach the Function constructor, enabling backend code execution and editor-pre
nvd
CVE-2026-72750P3HIGHCVSS 8.8fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72750 [HIGH] CWE-89 CVE-2026-72750: n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL inject
nvd
CVE-2026-72772P3HIGHCVSS 8.8fixed in 2.32.1fixed in 2.31.52026-08-11
CVE-2026-72772 [HIGH] CWE-640 CVE-2026-72772: n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the trusted key's permitted role ceiling covered that account. As a result, an
nvd
CVE-2026-21893P3HIGHCVSS 7.2v>= 0.187.0, < 1.120.32026-02-04
CVE-2026-21893 [HIGH] CWE-20 CVE-2026-21893: n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a comman
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute arbitrary system commands on the n8n host under specific conditions. This iss
nvd