N8N-Io N8N vulnerabilities
173 known vulnerabilities affecting n8n-io/n8n.
Total CVEs
173
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL26HIGH75MEDIUM72
Vulnerabilities
Page 9 of 9
CVE-2025-58177P4MEDIUMCVSS 5.4v>= 1.24.0, < 1.107.02025-09-15
CVE-2025-58177 [MEDIUM] CWE-79 CVE-2025-58177: n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored
n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in the initialMessages field and enable public access so that the payload is e
nvd
CVE-2025-49592P4MEDIUMCVSS 5.4fixed in 1.98.02025-06-26
CVE-2025-49592 [MEDIUM] CWE-601 CVE-2025-49592: n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability
n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains after logging in, by crafting malicious URLs with a misleading redirect query parameter. This may lead to phishing attacks by impersonating the n8n UI on
nvd
CVE-2026-54303P4MEDIUMCVSS 5.4fixed in 2.24.02026-06-23
CVE-2026-54303 [MEDIUM] CWE-79 CVE-2026-54303: n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Mic
n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabling reflected XSS in the n8n origin when a logged-in user visits a crafted URL. This vulnerability is fixed in 2.
nvd
CVE-2026-92588P4MEDIUMCVSS 4.4fixed in 1.123.76fixed in 2.38.2+1 more2026-09-16
CVE-2026-92588 [MEDIUM] CWE-639 CVE-2026-92588: n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the sour
n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of from the server-side status computed for the requesting user. An authenticated project-scoped user (e.g., a proj
nvd
CVE-2026-77069P4MEDIUMCVSS 4.3fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77069 [MEDIUM] CWE-918 CVE-2026-77069: n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential
n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-access-token exchange. While OAuth2 discovery and dynamic-client-registration requests use n8n's SSRF-protected HTTP client, the token exchange uses a separate client with no SSRF guard. A user with credential-creation permissions
nvd
CVE-2026-86995P4MEDIUMCVSS 4.3v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86995 [MEDIUM] CWE-22 CVE-2026-86995: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git n
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. A later fetch or pull resolved the remote from that configuration instead of the checked paramet
nvd
CVE-2026-77073P4MEDIUMCVSS 4.3≥ 2.34.0, < 2.34.1≥ 2.0.0, < 2.33.42026-08-20
CVE-2026-77073 [MEDIUM] CWE-639 CVE-2026-77073: n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_co
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects.
nvd
CVE-2026-77082P4MEDIUMCVSS 4.3fixed in 1.123.69≥ 2.34.0, < 2.34.1+1 more2026-08-20
CVE-2026-77082 [MEDIUM] CWE-1333 CVE-2026-77082: n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denia
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synchronously on the worker thread without complexity validation or execution timeout. A crafted regex pa
nvd
CVE-2026-86994P4MEDIUMCVSS 4.3v>= 2.38.0, < 2.38.2v>= 2.0.0, < 2.37.7+1 more2026-09-08
CVE-2026-86994 [MEDIUM] CWE-862 CVE-2026-86994: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, deactivation, and publication push events were also broadcast to clients that could not access the affected workflow
nvd
CVE-2025-49595P4MEDIUMCVSS 4.9fixed in 1.99.02025-07-03
CVE-2025-49595 [MEDIUM] CWE-400 CVE-2025-49595: n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnera
n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or filesystem-v2://). This allows authenticated attackers to cause service unavailability through malformed filesystem URI requests, effecting the /rest/binary-d
nvd
CVE-2025-52554P4MEDIUMCVSS 4.3fixed in 1.99.12025-07-03
CVE-2025-52554 [MEDIUM] CWE-862 CVE-2025-52554: n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was d
n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow executions that they do not own or that have not been shared with them, leading to potential business disruption. This issue has been patched in versio
nvd
CVE-2026-103260P4MEDIUMCVSS 4.0fixed in 2.39.6≥ 2.40.0, < 2.40.12026-10-01
CVE-2026-103260 [MEDIUM] CWE-862 CVE-2026-103260: n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can submit resume requests without verification of the requester's identity or approval permissions, allowing unauthenticated users to advance waiting executions and trigger guarded actions.
nvd
CVE-2026-33720P4MEDIUMCVSS 4.2fixed in 2.8.02026-03-25
CVE-2026-33720 [MEDIUM] CWE-863 CVE-2026-33720: n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_
n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` environment variable is set to `true`, the OAuth callback handler skips ownership verification of the OAuth state parameter. This allows an attacker to trick a victim into completing an OAuth flow against a credential object the att
nvd
← Previous9 / 9