N8N-Io N8N vulnerabilities
173 known vulnerabilities affecting n8n-io/n8n.
Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72
Vulnerabilities
Page 4 of 9
CVE-2026-33749P3CRITICALCVSS 9.0fixed in 1.123.27v>= 2.0.0-rc.0, < 2.13.3+1 more2026-03-25
CVE-2026-33749 [CRITICAL] CWE-79 CVE-2026-33749: n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1,
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows could craft a workflow that produces an HTML binary data object without a filename. The `/rest/binary-data` endpoint served such responses inline on the n8n origin without `Content-Di
nvd
CVE-2026-103248P3CRITICALCVSS 9.0fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103248 [CRITICAL] CWE-89 CVE-2026-103248: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filt
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single
nvd
CVE-2026-86083P3HIGHCVSS 8.8v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86083 [HIGH] CWE-94 CVE-2026-86083: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legac
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating timezone data. An expression could replace JSON.stringify and cause later generated source to contain execut
nvd
CVE-2026-71539P3HIGHCVSS 8.9fixed in 1.123.64v>= 2.0.0-rc.0, < 2.29.8+1 more2026-08-18
CVE-2026-71539 [HIGH] CWE-367 CVE-2026-71539: n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git n
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitra
nvd
CVE-2026-33665P3HIGHCVSS 7.5fixed in 1.121.0v>= 2.0.0-rc.0, < 2.4.02026-03-25
CVE-2026-33665 [HIGH] CWE-287 CVE-2026-33665: n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP a
n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if the LDAP email attribute matched the local account's email. An authenticated LDAP user who could control their own LDAP email attribute could set it to m
nvd
CVE-2026-77071P3CRITICALCVSS 9.8fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77071 [CRITICAL] CWE-89 CVE-2026-77071: n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the S
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a condition that widened the filter to match every row, turning an intende
nvd
CVE-2026-103247P3HIGHCVSS 8.5fixed in 1.123.802026-10-01
CVE-2026-103247 [HIGH] CWE-639 CVE-2026-103247: n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs b
n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.
nvd
CVE-2026-72768P3HIGHCVSS 8.3fixed in 2.32.1fixed in 2.31.52026-08-11
CVE-2026-72768 [HIGH] CWE-918 CVE-2026-72768: n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing through SSRF protection, exposing internal services and reading responses back t
nvd
CVE-2026-65596P3HIGHCVSS 8.1fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65596 [HIGH] CWE-863 CVE-2026-65596: n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restrict
n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate re
nvd
CVE-2026-103250P3HIGHCVSS 8.1fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103250 [HIGH] CWE-943 CVE-2026-103250: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQ
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId parameter. Unauthenticated attackers can supply MongoDB query operators in the sessionId field to access conversation histories from other users and perform
nvd
CVE-2026-103257P3HIGHCVSS 7.7fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103257 [HIGH] CWE-22 CVE-2026-103257: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can craft malicious resource IDs to redirect API calls to unintended resources, allowing unauthorized access to workflows, executions, and credential secret
nvd
CVE-2026-77077P3HIGHCVSS 7.6fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77077 [HIGH] CWE-94 CVE-2026-77077: n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape.
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constructors such as EventEmitter, allowing an authenticated user with Code node access to exploit prototype pollution to execute arbitrary commands within the r
nvd
CVE-2026-49465P3HIGHCVSS 7.7fixed in 1.123.48v>= 2.0.0-rc.0, < 2.21.8+1 more2026-06-23
CVE-2026-49465 [HIGH] CWE-22 CVE-2026-49465: n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authen
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's Clone operation, or as the target repository in the Push operation, bypassing the N8N_RESTRICT_FILE_ACCESS_TO file
nvd
CVE-2026-103252P3HIGHCVSS 7.7fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103252 [HIGH] CWE-639 CVE-2026-103252: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an aut
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credenti
nvd
CVE-2026-42236P3HIGHCVSS 7.5fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42236 [HIGH] CWE-770 CVE-2026-42236: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1,
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory resources by sending large registration payloads, rende
nvd
CVE-2026-65598P3HIGHCVSS 7.5fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65598 [HIGH] CWE-367 CVE-2026-65598: n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone ope
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n l
nvd
CVE-2026-54312P3HIGHCVSS 8.5fixed in 2.24.02026-06-23
CVE-2026-54312 [HIGH] CWE-1321 CVE-2026-54312: n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with perm
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as the table parameter. This pollutes Object.prototype process-wide for the lifetime of the n8n server process, causin
nvd
CVE-2026-72773P3HIGHCVSS 7.7fixed in 2.32.1fixed in 2.31.52026-08-11
CVE-2026-72773 [HIGH] CWE-22 CVE-2026-72773: n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-us
n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the tool to return the names and contents of arbitrary local files readable by t
nvd
CVE-2026-54304P3HIGHCVSS 7.7fixed in 1.123.55v>= 2.26.0, < 2.26.1+1 more2026-06-23
CVE-2026-54304 [HIGH] CWE-200 CVE-2026-54304: n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authen
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure the SecurityScorecard node's report download operation to target an attacker-controlled URL. The node at
nvd
CVE-2026-42226P3HIGHCVSS 7.5fixed in 1.123.33v>= 2.17.0, < 2.17.52026-05-04
CVE-2026-42226 [HIGH] CWE-862 CVE-2026-42226: n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynam
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An authenticated user with access to a shared workflow could supply a foreign credential ID in the request body, causing
nvd