N8N-Io N8N vulnerabilities
173 known vulnerabilities affecting n8n-io/n8n.
Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72
Vulnerabilities
Page 5 of 9
CVE-2026-33724P3HIGHCVSS 7.4fixed in 2.5.02026-03-25
CVE-2026-33724 [HIGH] CWE-639 CVE-2026-33724: n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control
n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command used for git operations explicitly disabled host key verification. A network attacker positioned between the n8n instance and the remote Git server could intercept the connection and present a fraudulent
nvd
CVE-2026-54311P3HIGHCVSS 7.7v>= 2.26.0, < 2.26.2fixed in 2.25.72026-06-23
CVE-2026-54311 [HIGH] CWE-488 CVE-2026-54311: n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated use
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox context was cached and reused across all workflow executions on the instance, prototype mutations introduced by one us
nvd
CVE-2026-72766P3HIGHCVSS 7.5fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72766 [HIGH] CWE-843 CVE-2026-72766: n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerabil
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a f
nvd
CVE-2026-86075P3HIGHCVSS 7.5fixed in 2.37.7v>= 2.38.0, < 2.38.22026-09-08
CVE-2026-86075 [HIGH] CWE-770 CVE-2026-86075: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Cl
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated remote caller could repeatedly persist oversized values in oauth_clients and exhaust database storage. The affected va
nvd
CVE-2026-54313P3HIGHCVSS 7.7fixed in 2.24.02026-06-23
CVE-2026-54313 [HIGH] CWE-89 CVE-2026-54313: n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with work
n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before being passed to MongoDB as a query filter, allowing unintended documents to be matched and overwritten with attack
nvd
CVE-2026-103246P3HIGHCVSS 7.7fixed in 2.39.6≥ 2.40.0, < 2.40.12026-10-01
CVE-2026-103246 [HIGH] CWE-639 CVE-2026-103246: n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inl
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.
nvd
CVE-2026-72769P3HIGHCVSS 8.1fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72769 [HIGH] CWE-1321 CVE-2026-72769: n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expre
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process (a sandbox escape), leading to a den
nvd
CVE-2025-61917P3HIGHCVSS 7.7v>= 1.65.0, < 1.114.32026-02-04
CVE-2025-61917 [HIGH] CWE-200 CVE-2025-61917: n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use o
n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buffers could contain residual data from within the same Node.js process (for example, data from prior req
nvd
CVE-2026-54314P3HIGHCVSS 7.5fixed in 2.24.02026-06-23
CVE-2026-54314 [HIGH] CWE-409 CVE-2026-54314: n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompre
n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated attacker could send a small compressed archive to a public webhook workflow using this node, causing the n8n process
nvd
CVE-2026-59206P3HIGHCVSS 7.1v>= 2.28.0, < 2.28.1v>= 2.0.0-rc.0, < 2.27.4+1 more2026-07-09
CVE-2026-59206 [HIGH] CWE-1321 CVE-2026-59206: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authe
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via the workflow API, allowing unauthenticated requests to be treated as a privileged user and exposing user
nvd
CVE-2026-54308P3HIGHCVSS 7.2v>= 2.26.0, < 2.26.2fixed in 2.25.72026-06-23
CVE-2026-54308 [HIGH] CWE-290 CVE-2026-54308: n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent36
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL could submit a forged payload and cause the workflow to execute with attacker-controlled data. This vulnerability
nvd
CVE-2026-72770P3MEDIUMCVSS 6.5fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72770 [MEDIUM] CWE-22 CVE-2026-72770: n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, a
n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated users to bypass repository-path containment checks. Attackers with workflow create/execute rights can point allowlisted remote configurations at local paths outside the sandbox to pull arbitrary git rep
nvd
CVE-2026-86073P3HIGHCVSS 7.6fixed in 2.37.7v>= 2.38.0, < 2.38.12026-09-08
CVE-2026-86073 [HIGH] CWE-863 CVE-2026-86073: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endp
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was registered, not that it matched the original grant. An OAuth client approved for
nvd
CVE-2026-85171P3MEDIUMCVSS 6.5fixed in 1.123.73fixed in 2.36.2+1 more2026-09-03
CVE-2026-85171 [MEDIUM] CWE-532 CVE-2026-85171: n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi,
n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper outside any error handling, causing the plaintext secret to be persisted in execution error data. Any authenticate
nvd
CVE-2026-21894P3MEDIUMCVSS 6.5v>= 0.150.0, < 2.2.22026-01-08
CVE-2026-21894 [MEDIUM] CWE-290 CVE-2026-21894: n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an aut
n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe webhook events. The Stripe Trigger creates and stores a Stripe webhook signing secret when registering the webhook
nvd
CVE-2026-77081P3HIGHCVSS 7.1fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77081 [HIGH] CWE-639 CVE-2026-77081: n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in t
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is treated as active; if two credentials of different types are attached, the node enforces the allowed-domains policy of
nvd
CVE-2026-103251P3HIGHCVSS 7.1fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103251 [HIGH] CWE-862 CVE-2026-103251: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a vali
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary np
nvd
CVE-2026-33663P3MEDIUMCVSS 6.5fixed in 1.123.27v>= 2.0.0-rc.0, < 2.13.3+1 more2026-03-25
CVE-2026-33663 [MEDIUM] CWE-639 CVE-2026-33663: n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27,
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit chained authorization flaws in n8n's credential pipeline to steal plaintext secrets from generic HTTP credentials (`httpBasicAuth`, `httpHeaderAuth`, `httpQueryAuth`) belonging to other
nvd
CVE-2026-59207P3MEDIUMCVSS 6.5v>= 2.28.0, < 2.28.1fixed in 2.27.42026-07-09
CVE-2026-59207 [MEDIUM] CWE-693 CVE-2026-59207: n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents featur
n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with use-only access to a shared credential to send its secret to an external serve
nvd
CVE-2026-65594P3MEDIUMCVSS 6.5fixed in 2.30.1fixed in 2.29.82026-07-22
CVE-2026-65594 [MEDIUM] CWE-863 CVE-2026-65594: n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and tok
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a me
nvd