Vulnerabilities
CVE-2026-56354
n8n: Authenticated XSS and Open Redirect via Form Node
CVE-2026-56778
n8n: Public API Execution Retry Authorization Bypass
CVE-2026-56775
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-56776
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-56360
n8n has Webhook Forgery on Zendesk Trigger Node
CVE-2026-56359
n8n has XSS in its Credential Management Flow
CVE-2026-54307
n8n: Credential Exfiltration via Permission Bypass
CVE-2026-56777
n8n: Python Code Node AST Validator Bypass
CVE-2026-56356
n8n has XSS in Chat Trigger Node through Custom CSS
CVE-2026-56350
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
CVE-2025-71380
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
CVE-2026-56351
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
CVE-2026-56358
n8n has a Stored XSS Vulnerability in its Form Trigger
CVE-2026-56357
n8n: Webhook Forgery on Github Webhook Trigger
CVE-2026-56348
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
CVE-2026-54305
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-54304
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2026-54309
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2026-54314
n8n: Denial of Service via ZIP decompression in webhook workflow
CVE-2026-54312
n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-54303
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
CVE-2026-54302
n8n: Stored XSS in Chat Trigger Node
CVE-2026-54306
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54301
n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-54311
n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-54308
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
CVE-2026-54313
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
CVE-2026-54310
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2026-49444
n8n: Python sandbox escape
CVE-2026-49465
n8n: Git Node Clone and Push Operations Bypass File Sandbox
GHSA-2vx9-7wpg-88jq
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
CVE-2026-44791
n8n Has an XML Node Prototype Pollution Patch Bypass
CVE-2026-44789
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVE-2026-44792
n8n Has a Source Control Pull SQL Injection
CVE-2026-45732
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVE-2026-44790
n8n Has an Arbitrary File Read via Git Node
CVE-2026-42226
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
CVE-2026-42234
n8n has a Python Task Runner Sandbox Escape Vulnerability
CVE-2026-42229
n8n has SQL Injection in SeaTable Node
CVE-2026-42236
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
CVE-2026-42231
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
CVE-2026-42232
n8n has XML Node Prototype Pollution that to RCE
CVE-2026-42237
n8n has SQL Injection in Snowflake and MySQL Nodes
CVE-2026-42233
n8n has SQL Injection in Oracle Database Node via Limit Field
CVE-2026-42227
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
CVE-2026-42230
n8n has Open Redirect in MCP OAuth Consent Flow
CVE-2026-42228
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
CVE-2026-42235
n8n Vulnerable to XSS via MCP OAuth client
CVE-2026-33660
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
CVE-2026-27496
n8n has In-Process Memory Disclosure in its Task Runner
CVE-2026-33751
n8n Vulnerable to LDAP Filter Injection in LDAP Node
CVE-2026-33749
n8n Vulnerable to XSS via Binary Data Inline HTML Rendering
CVE-2026-33696
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
CVE-2026-33713
n8n has SQL Injection in Data Table Node via orderByColumn Expression
CVE-2026-33722
n8n Has External Secrets Authorization Bypass in Credential Saving
CVE-2026-33724
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no
CVE-2026-33720
n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK
CVE-2026-33665
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
CVE-2026-33663
n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
CVE-2026-25115
n8n has a Python sandbox escape
CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
CVE-2026-27577
n8n: Expression Sandbox Escape Leads to RCE
CVE-2026-27494
n8n has Arbitrary File Read via Python Code Node Sandbox Escape
CVE-2026-27498
n8n has Arbitrary Command Execution via File Write and Git Operations
CVE-2026-27578
n8n Vulnerable to Stored XSS via Various Nodes
CVE-2026-27495
n8n has a Sandbox Escape in its JavaScript Task Runner
CVE-2026-27497
n8n has Potential Remote Code Execution via Merge Node
CVE-2026-27493
n8n has Unauthenticated Expression Evaluation via Form Node
GHSA-jh8h-6c9q-7gmw
n8n has an Authentication Bypass in its Chat Trigger Node
GHSA-fvfv-ppw4-7h2w
n8n has a Guardrail Node Bypass
CVE-2026-25631
n8n's domain allowlist bypass enables credential exfiltration
CVE-2026-25052
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
CVE-2026-25053
n8n has OS Command Injection in Git Node
CVE-2026-25056
n8n Merge Node has Arbitrary File Write leading to RCE
CVE-2026-25054
n8n Has Stored Cross-site Scripting via Markdown Rendering in Workflow UI
CVE-2026-25055
n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node
CVE-2025-61917
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
CVE-2026-25051
n8n's Improper CSP Enforcement in Webhook Responses May Allow Stored XSS
CVE-2026-25049
n8n Has Expression Escape Vulnerability Leading to RCE
CVE-2026-21893
n8n Vulnerable to Command Injection in Community Package Installation
CVE-2026-21877
n8n Vulnerable to RCE via Arbitrary File Write
CVE-2026-21894
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
CVE-2025-68668
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
CVE-2026-1470
n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
CVE-2026-21858
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
CVE-2025-68949
n8n: Webhook Node IP Whitelist Bypass via Partial String Matching
CVE-2025-68697
Self-hosted n8n has Legacy Code node that enables arbitrary file read/write
CVE-2025-61914
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox
CVE-2025-65964
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
CVE-2025-62726
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
CVE-2025-58177
Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter
CVE-2025-57749
n8n symlink traversal vulnerability in "Read/Write File" node allows access to restricted files
CVE-2025-52478
Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source
CVE-2025-52554
n8n is vulnerable to Improper Authorization through its `/stop` endpoint
CVE-2025-49595
n8n Vulnerable to Denial of Service via Malformed Binary Data Requests
CVE-2025-49592
n8n allows open redirects via the /signin endpoint
CVE-2025-46343
n8n Vulnerable to Stored XSS through Attachments View Endpoint
CVE-2023-27564
n8n Information Disclosure vulnerability
CVE-2023-27563
n8n Privilege Escalation vulnerability
CVE-2023-27562
n8n Directory Traversal vulnerability
Ready to move
Start Securing
Free, no credit card | First findings in minutes