cbcvebase.

N8N-Io N8N vulnerabilities

173 known vulnerabilities affecting n8n-io/n8n.

Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72

Vulnerabilities

Page 8 of 9
CVE-2026-65014P4MEDIUMCVSS 5.3fixed in 2.28.0fixed in 2.27.42026-07-22
CVE-2026-65014 [MEDIUM] CWE-306 CVE-2026-65014: n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/tes n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration. The impact is limited to disrupting in-progress test se
nvd
CVE-2026-27578P4MEDIUMCVSS 5.4fixed in 1.123.22v>= 2.0.0, < 2.9.3+1 more2026-02-25
CVE-2026-27578 [MEDIUM] CWE-79 CVE-2026-27578: n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could inject arbitrary scripts into pages rendered by the n8n application using different techniques on various nodes (Form Trigger node, Chat Trigger node, Send & Wait node, Webhook No
nvd
CVE-2026-86996P4MEDIUMCVSS 5.4fixed in 2.37.7v>= 2.38.0, < 2.38.22026-09-08
CVE-2026-86996 [MEDIUM] CWE-862 CVE-2026-86996: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted workflow and read its returned data. The affected path
nvd
CVE-2025-68949P4MEDIUMCVSS 5.3v>= 1.36.0, < 2.2.02026-01-13
CVE-2025-68949 [MEDIUM] CWE-134 CVE-2025-68949: n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely contained the configured whitelist entry as a substring. This issue affected in
nvd
CVE-2026-103245P4MEDIUMCVSS 5.3fixed in 1.123.80≥ 2.0.0, < 2.39.6+1 more2026-10-01
CVE-2026-103245 [MEDIUM] CWE-347 CVE-2026-103245: n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook handler. Unauthenticated attackers can send forged webhook requests with attacker-controlled payloads to trigger workflows and manipulate downstream actions like record creation or AP
nvd
CVE-2026-92587P4MEDIUMCVSS 5.0fixed in 1.123.76fixed in 2.38.2+1 more2026-09-16
CVE-2026-92587 [MEDIUM] CWE-426 CVE-2026-92587: n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated
nvd
CVE-2026-54302P4MEDIUMCVSS 5.4fixed in 1.123.55v>= 2.0.0-rc.0, < 2.25.7+1 more2026-06-23
CVE-2026-54302 [MEDIUM] CWE-79 CVE-2026-54302: n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authen n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webhookId. When a logged-in user visited the chat URL, the injected code executed in the n8n origin with that user's
nvd
CVE-2026-85173P4MEDIUMCVSS 4.3fixed in 2.36.2fixed in 2.35.42026-09-03
CVE-2026-85173 [MEDIUM] CWE-639 CVE-2026-85173: n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from project
nvd
CVE-2026-54301P4MEDIUMCVSS 5.4fixed in 1.123.55v>= 2.0.0-rc.0, < 2.25.7+1 more2026-06-23
CVE-2026-54301 [MEDIUM] CWE-79 CVE-2026-54301: n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authen n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Content-Type. The binary response path bypassed the central Content-Security-Policy sandbox header, allowing a public w
nvd
CVE-2026-86080P4MEDIUMCVSS 5.3v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86080 [MEDIUM] CWE-347 CVE-2026-86080: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHu n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow static data then retained webhookId without webhookSecret, and X-Hub-Signature-256 verification accepted deliveries w
nvd
CVE-2026-86993P4MEDIUMCVSS 4.9v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86993 [MEDIUM] CWE-862 CVE-2026-86993: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Str n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership check. A user with a custom global role carrying Log Streaming scopes could select a credential belonging to another p
nvd
CVE-2025-52478P4MEDIUMCVSS 5.4v>= 1.77.0, < 1.98.22025-08-19
CVE-2025-52478 [MEDIUM] CWE-79 CVE-2025-52478: n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting ( n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifically in the Form Trigger node's HTML form element. An authenticated attacker can inject malicious HTML via an with a srcdoc payload that includes arbitrary JavaScript execution. The attacker can also in
nvd
CVE-2026-65597P4MEDIUMCVSS 5.4fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65597 [MEDIUM] CWE-79 CVE-2026-65597: n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute same-origin as the editor. When a victim opens the preview, the script can call a
nvd
CVE-2025-46343P4MEDIUMCVSS 5.4fixed in 1.90.02025-04-29
CVE-2025-46343 [MEDIUM] CWE-79 CVE-2025-46343: n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-si n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary files, which are accessible to authenticated users. However, there is no restriction on the MIME type of uploaded files, and the MIME type could be contr
nvd
CVE-2025-61914P4MEDIUMCVSS 5.4fixed in 1.114.02025-12-26
CVE-2025-61914 [MEDIUM] CWE-79 CVE-2025-61914: n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Sc n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this node responds with HTML content containing executable scripts, the payload may execute directly in the top-level window, rather than within the expected sa
nvd
CVE-2026-25054P4MEDIUMCVSS 5.4fixed in 1.123.9fixed in 2.2.12026-02-04
CVE-2026-25054 [MEDIUM] CWE-79 CVE-2026-25054: n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Sit n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface, including workflow sticky notes and other areas that support markdown content. An authenticated user with permission to create or modify workflows could
nvd
CVE-2026-86085P4MEDIUMCVSS 4.9fixed in 2.37.7v>= 2.38.0, < 2.38.22026-09-08
CVE-2026-86085 [MEDIUM] CWE-862 CVE-2026-86085: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slu n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A caller with role:manageProject could name a project the caller could not list and obtain member names and email
nvd
CVE-2026-33751P4MEDIUMCVSS 4.8fixed in 1.123.27v>= 2.0.0-rc.0, < 2.13.3+1 more2026-03-25
CVE-2026-33751 [MEDIUM] CWE-90 CVE-2026-33751: n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacharacters to pass through unescaped when user-controlled input was interpolated into LDAP search filters. In workflows where external user input is passed via expressions into the LDAP node
nvd
CVE-2026-25051P4MEDIUMCVSS 5.4fixed in 1.123.22026-02-04
CVE-2026-25051 [MEDIUM] CWE-79 CVE-2026-25051: n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP endpoints. Under certain conditions, the Content Security Policy (CSP) sandbox protection intended to isolate HTML responses may not be applied correctly. An
nvd
CVE-2026-65592P4MEDIUMCVSS 5.4fixed in 1.123.64fixed in 2.30.1+1 more2026-07-22
CVE-2026-65592 [MEDIUM] CWE-79 CVE-2026-65592: n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) sch
nvd
N8N-Io N8N vulnerabilities | cvebase