cbcvebase.

N8N-Io N8N vulnerabilities

173 known vulnerabilities affecting n8n-io/n8n.

Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72

Vulnerabilities

Page 7 of 9
CVE-2026-103249P3HIGHCVSS 7.6fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103249 [HIGH] CWE-79 CVE-2026-103249: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stor n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click t
nvd
CVE-2026-103258P3MEDIUMCVSS 6.8fixed in 2.39.6≥ 2.40.0, < 2.40.12026-10-01
CVE-2026-103258 [MEDIUM] CWE-943 CVE-2026-103258: n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vul n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass filters by breaking out of query literals. Attackers can exploit this by binding vulnerable node parameters to untrusted external input to widen single-record
nvd
CVE-2026-77076P3MEDIUMCVSS 6.5fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77076 [MEDIUM] CWE-209 CVE-2026-77076: n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the node re-throws the underlying HTTP client error unchanged instead of wrapping it in n8n's standard error type. That error contains the live request's headers, including a decry
nvd
CVE-2026-27496P3MEDIUMCVSS 6.5fixed in 1.123.22v>= 2.0.0-rc.0, < 2.9.3+1 more2026-03-25
CVE-2026-27496 [MEDIUM] CWE-908 CVE-2026-27496: n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, a n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory buffers. Uninitialized buffers may contain residual data from the same Node.js process — including data from prior
nvd
CVE-2026-72774P3MEDIUMCVSS 6.5fixed in 1.123.67fixed in 2.32.1+1 more2026-08-11
CVE-2026-72774 [MEDIUM] CWE-639 CVE-2026-72774: n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Reque n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type via an expression. Because the pre-execution permission check compares the unresolved expression instea
nvd
CVE-2026-59209P3MEDIUMCVSS 6.5v>= 2.28.0, < 2.28.1v>= 2.0.0-rc.0, < 2.27.4+1 more2026-07-09
CVE-2026-59209 [MEDIUM] CWE-200 CVE-2026-59209: n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authe n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTTP Request node's pagination expression and exfiltrate the secret through item data. This issue is fix
nvd
CVE-2026-65599P3MEDIUMCVSS 6.5fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65599 [MEDIUM] CWE-312 CVE-2026-65599: n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when c n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only for a key identifier). Because JWT headers are Base64-encoded rather than encrypted, the private key could be reco
nvd
CVE-2026-54306P3MEDIUMCVSS 6.4v>= 2.26.0, < 2.26.2fixed in 2.25.72026-06-23
CVE-2026-54306 [MEDIUM] CWE-1321 CVE-2026-54306: n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollutio n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object copying. These fields could be surfaced and consumed as normal values by downstream built-in nodes. Where a workfl
nvd
CVE-2026-77083P3MEDIUMCVSS 5.9fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77083 [MEDIUM] CWE-1321 CVE-2026-77083: n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaSc n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute workflows to pollute it from within a Code node execution and recover a reference to the host's globalT
nvd
CVE-2026-86078P3MEDIUMCVSS 6.5fixed in 2.37.7v>= 2.38.0, < 2.38.22026-09-08
CVE-2026-86078 [MEDIUM] CWE-1321 CVE-2026-86078: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI work n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contain __proto__ or constructor, causing nested writes to reach Object.prototype in the main n8n process
nvd
CVE-2026-85167P3MEDIUMCVSS 6.5fixed in 2.36.2fixed in 2.35.42026-09-03
CVE-2026-85167 [MEDIUM] CWE-943 CVE-2026-85167: n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsea n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression values directly into the query string before parsing. A value containing quote and brace characters can close the inten
nvd
CVE-2026-85170P3MEDIUMCVSS 6.5fixed in 1.123.73fixed in 2.36.2+1 more2026-09-03
CVE-2026-85170 [MEDIUM] CWE-20 CVE-2026-85170: n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo no n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that resolves to an object carrying a path or href property, causing the composer to read a local file accessible to the n8
nvd
CVE-2026-86077P3MEDIUMCVSS 6.5fixed in 2.37.7v>= 2.38.0, < 2.38.22026-09-08
CVE-2026-86077 [MEDIUM] CWE-862 CVE-2026-86077: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous form submitter who received that token could reuse it on the chat route to release a Send-and-Wait, non-chat HITL, o
nvd
CVE-2026-77072P3HIGHCVSS 7.6fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77072 [HIGH] CWE-79 CVE-2026-77072: n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page applied its sandboxing Content-Security-Policy only when respondWith was not set to 'redirect', but responseText was always rendered as raw HTML. An authenticated member could set respondWith to 'redirect'
nvd
CVE-2026-86074P3HIGHCVSS 7.1fixed in 2.37.7v>= 2.38.0, < 2.38.22026-09-08
CVE-2026-86074 [HIGH] CWE-918 CVE-2026-86074: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI cred n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticate
nvd
CVE-2026-86084P3MEDIUMCVSS 5.5v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86084 [MEDIUM] CWE-288 CVE-2026-86084: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the publi n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterprise administrator who had configured and later disabled an identity provider still exposed a working route that cou
nvd
CVE-2026-65593P3MEDIUMCVSS 5.4fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65593 [MEDIUM] CWE-918 CVE-2026-65593: n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targ
nvd
CVE-2026-42230P4MEDIUMCVSS 6.1fixed in 1.123.32v>= 2.17.0, < 2.17.4+1 more2026-05-04
CVE-2026-42230 [MEDIUM] CWE-601 CVE-2026-42230: n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. When a user denies the MCP OAuth consent dialog, the handleDeny handler redirects the user to the regi
nvd
CVE-2025-68697P4MEDIUMCVSS 5.4fixed in 2.0.02025-12-26
CVE-2025-68697 [MEDIUM] CWE-269 CVE-2025-68697: n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n insta n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can invoke internal helper functions from within the Code node. This allows a workflow editor to perform actions on t
nvd
CVE-2026-33722P4MEDIUMCVSS 5.3fixed in 1.123.23v>= 2.0.0-rc.0, < 2.6.42026-03-25
CVE-2026-33722 [MEDIUM] CWE-863 CVE-2026-33722: n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authent n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plaintext value when saving the credential. This bypassed the `externalSecret:list` permission check and allowed acc
nvd
N8N-Io N8N vulnerabilities | cvebase