cbcvebase.

N8N-Io N8N vulnerabilities

173 known vulnerabilities affecting n8n-io/n8n.

Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72

Vulnerabilities

Page 6 of 9
CVE-2026-42227P3MEDIUMCVSS 6.5fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42227 [MEDIUM] CWE-639 CVE-2026-42227: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projects they are not a member of by supplying an arbitrary projectId query parameter to the public API variables endpoint. The handler queried the variables r
nvd
CVE-2026-86081P3HIGHCVSS 7.1v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86081 [HIGH] CWE-1333 CVE-2026-86081: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git n n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern ^(./).git(/.)$ allowed catastrophic backtracking and ran synchronously in the main n8n process. An authentic
nvd
CVE-2026-65589P3MEDIUMCVSS 6.5fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65589 [MEDIUM] CWE-532 CVE-2026-65589: n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node ex n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
nvd
CVE-2026-42228P3MEDIUMCVSS 6.5fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42228 [MEDIUM] CWE-862 CVE-2026-42228: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated remote attacker who could identify a valid execution ID
nvd
CVE-2026-77075P3HIGHCVSS 7.3fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77075 [HIGH] CWE-94 CVE-2026-77075: n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vul n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the field's stored value directly into the node type's URL template without checking for expression syntax. An authenticated member can store a malicious value so that when a
nvd
CVE-2026-103256P3HIGHCVSS 7.1fixed in 2.39.6≥ 2.40.0, < 2.40.12026-10-01
CVE-2026-103256 [HIGH] CWE-522 CVE-2026-103256: n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validati
nvd
CVE-2026-86079P3MEDIUMCVSS 6.5v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86079 [MEDIUM] CWE-22 CVE-2026-86079: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elast n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An identifier containing path separators or dot segments could select another index or a cluster administration endpoin
nvd
CVE-2026-25631P3MEDIUMCVSS 6.5fixed in 1.121.02026-02-06
CVE-2026-25631 [MEDIUM] CWE-20 CVE-2026-25631: n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in th n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domains, potentially leading to credential exfiltration. This only might affect user who have credentials that use wild
nvd
CVE-2026-77085P3MEDIUMCVSS 6.5≥ 2.34.0, < 2.34.1≥ 2.0.0, < 2.33.42026-08-20
CVE-2026-77085 [MEDIUM] CWE-918 CVE-2026-77085: n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent t n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API URL using a raw HTTP client that did not route through n8n's centralized SSRF protection. On instances with N8N_SSRF_PROTECTION_ENABLED=true, an authenticated user with permission to create SearXNG
nvd
CVE-2026-72763P3MEDIUMCVSS 6.5fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72763 [MEDIUM] CWE-639 CVE-2026-72763: n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level cred n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with Editor access to a shared workflow (when workflow sharing is enabled) who knows a target credential's ID can reference that credential
nvd
CVE-2026-72771P3MEDIUMCVSS 6.5fixed in 2.32.1fixed in 2.31.52026-08-11
CVE-2026-72771 [MEDIUM] CWE-863 CVE-2026-72771: n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against u
nvd
CVE-2026-103259P3HIGHCVSS 7.6fixed in 2.39.6≥ 2.40.0, < 2.40.12026-10-01
CVE-2026-103259 [HIGH] CWE-863 CVE-2026-103259: n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, en
nvd
CVE-2026-59208P3MEDIUMCVSS 6.8v>= 2.28.0, < 2.28.1fixed in 2.27.42026-07-09
CVE-2026-59208 [MEDIUM] CWE-287 CVE-2026-59208: n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub
nvd
CVE-2026-72749P3MEDIUMCVSS 6.5fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72749 [MEDIUM] CWE-1321 CVE-2026-72749: n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fie n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated user to name a field after an inherited built-in method path and corrupt a shared global in the main Node.js p
nvd
CVE-2025-57749P3MEDIUMCVSS 6.5fixed in 1.106.02025-08-20
CVE-2025-57749 [MEDIUM] CWE-59 CVE-2025-57749: n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discove n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly account for symbolic links (symlinks). An attacker with the ability to create symlinks—such as by using the Exec
nvd
CVE-2026-86082P3MEDIUMCVSS 6.5v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86082 [MEDIUM] CWE-918 CVE-2026-86082: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenA n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an arbitrary host and make the searchModels path send the openAiApi credential the
nvd
CVE-2026-77074P3MEDIUMCVSS 6.5fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77074 [MEDIUM] CWE-94 CVE-2026-77074: n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image n n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound HTTP requests to arbitrary addresses or access local files.
nvd
CVE-2026-85166P3MEDIUMCVSS 6.5fixed in 2.36.2fixed in 2.35.42026-09-03
CVE-2026-85166 [MEDIUM] CWE-863 CVE-2026-85166: n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline wor n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/updating a workflow via the REST API, Public API, or MCP, can persist a node referencing a credential they do not ow
nvd
CVE-2026-85172P3MEDIUMCVSS 6.4fixed in 2.34.1fixed in 2.33.42026-09-03
CVE-2026-85172 [MEDIUM] CWE-918 CVE-2026-85172: n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP client uses the url property when both are present, allowing attackers to bypass validation by supplying a safe
nvd
CVE-2026-103254P3MEDIUMCVSS 6.3fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103254 [MEDIUM] CWE-22 CVE-2026-103254: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals. Attackers with workflow creation permissions can mint valid approval URLs for gates in projects they cannot access by exploiting unresolved traversal sequences in c
nvd
N8N-Io N8N vulnerabilities | cvebase