Vulnerabilities
GHSA-jqwr-vx3p-r266
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
GHSA-652q-gvq3-74qv
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-9cmh-xcqm-5hqr
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
CVE-2026-65589
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
GHSA-fmvg-vhqq-r2mj
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
CVE-2026-65014
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
GHSA-5vfw-jc4p-fj39
Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
GHSA-h9fm-xcv2-qfw3
Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
GHSA-88c4-pcqm-3r9p
Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
CVE-2026-65596
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
CVE-2026-65594
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
CVE-2026-59253
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
GHSA-2qp2-6frj-p9pq
Duplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-3j7v-fhjg-6rh2
Duplicate Advisory: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
CVE-2026-59254
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
GHSA-xwx6-jjhv-84p8
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GHSA-pf2q-pxhf-hgmw
n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
CVE-2026-59257
n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
CVE-2026-58661
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
GHSA-hx4h-vr3m-45vh
n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
CVE-2026-59259
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
GHSA-q6mx-qvhp-fqmg
Duplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch
GHSA-gqcv-rfj6-r29g
Duplicate Advisory: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
CVE-2026-65590
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
GHSA-2vww-6p9h-5g8j
Duplicate Advisory: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
CVE-2026-65593
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
GHSA-38fj-36m5-783c
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
GHSA-2x35-3fw4-9jr4
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
CVE-2026-65016
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-8342-988q-86cr
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
CVE-2026-65595
n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
GHSA-64xh-79j6-r5v8
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-xmc9-4f2h-jf9c
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GHSA-6qc9-mqvw-jg7x
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-vhf8-cg2h-cg3p
n8n: SSRF Protection Bypass via MCP Client Node
GHSA-rcv6-pvrj-4xcg
n8n: Authenticated code execution in the n8n Git node
GHSA-mwq7-vcmc-cm4q
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
CVE-2026-59208
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
GHSA-wq64-hcrf-8m56
Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
CVE-2026-65591
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-cj9h-qx8g-pq2g
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
GHSA-gf29-4f56-r2jf
n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-gv7g-jm28-cr3m
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GHSA-m7jc-p4hf-xhwq
Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2026-59206
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVE-2026-59209
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-59207
n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
GHSA-mhvh-gwhr-76pw
Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header
CVE-2026-65599
n8n: Google Service Account Private Key Exposed in JWT Header
CVE-2026-65597
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65592
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-h5xr-fqvj-253p
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-65015
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-vhcw-f978-xjjg
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65598
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
GHSA-w46p-w7w2-fr9g
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-725q-c4vp-q4cg
Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
CVE-2026-56351
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
CVE-2026-56358
n8n has a Stored XSS Vulnerability in its Form Trigger
CVE-2026-54302
n8n: Stored XSS in Chat Trigger Node
CVE-2026-49465
n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-54306
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54308
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
CVE-2026-54305
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-54304
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2026-54301
n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-44791
n8n Has an XML Node Prototype Pollution Patch Bypass
CVE-2026-44789
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVE-2026-44792
n8n Has a Source Control Pull SQL Injection
CVE-2026-44790
n8n Has an Arbitrary File Read via Git Node
CVE-2026-56348
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
CVE-2026-45732
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVE-2026-54312
n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-49444
n8n: Python sandbox escape
CVE-2026-54313
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
CVE-2026-54310
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2026-54309
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2026-54311
n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-54303
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
CVE-2026-54314
n8n: Denial of Service via ZIP decompression in webhook workflow
CVE-2026-56357
n8n: Webhook Forgery on Github Webhook Trigger
CVE-2026-56353
n8n has an Authentication Bypass in its Chat Trigger Node
CVE-2026-56349
n8n has a Guardrail Node Bypass
CVE-2026-56352
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
CVE-2026-56354
n8n: Authenticated XSS and Open Redirect via Form Node
CVE-2026-56778
n8n: Public API Execution Retry Authorization Bypass
CVE-2026-56775
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-56776
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-56360
n8n has Webhook Forgery on Zendesk Trigger Node
CVE-2026-56359
n8n has XSS in its Credential Management Flow
CVE-2026-54307
n8n: Credential Exfiltration via Permission Bypass
CVE-2026-56777
n8n: Python Code Node AST Validator Bypass
CVE-2026-56356
n8n has XSS in Chat Trigger Node through Custom CSS
CVE-2026-56350
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
CVE-2025-71380
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
CVE-2026-42226
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
CVE-2026-42234
n8n has a Python Task Runner Sandbox Escape Vulnerability
CVE-2026-42229
n8n has SQL Injection in SeaTable Node
CVE-2026-42236
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
CVE-2026-42231
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
Ready to move
Start Securing
Free, no credit card | First findings in minutes