Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

N8n HIGH 8.8
CVE-2026-42231

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML re…

Fix: 1.123.32 / 2.17.4+
Fix from $1,950 2026-05-04
N8n HIGH 8.8
CVE-2026-42232

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create o…

Fix: 1.123.32 / 2.17.4+
Fix from $1,950 2026-05-04
N8n MEDIUM 6.1
CVE-2026-42230

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth c…

Fix: 1.123.32 / 2.17.4+
Fix from $1,600 2026-05-04
N8n HIGH 7.5
CVE-2026-42226

n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify wheth…

Fix: 1.123.33 / 2.17.5+
Fix from $1,950 2026-05-04
N8n MEDIUM 6.5
CVE-2026-42227

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped…

Fix: 1.123.32 / 2.17.4+
Fix from $1,600 2026-05-04
N8n MEDIUM 6.5
CVE-2026-42228

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Tri…

Fix: 1.123.32 / 2.17.4+
Fix from $1,600 2026-05-04
N8n CRITICAL 9.0
CVE-2026-33749

n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create o…

Fix: 1.123.27 / 2.13.3+
Fix from $2,300 2026-03-25
N8n HIGH 7.4
CVE-2026-33724

n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command…

Fix: 2.5.0+
Fix from $1,950 2026-03-25
N8n MEDIUM 5.3
CVE-2026-33722

n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external s…

Fix: 1.123.23 / 2.6.4+
Fix from $1,600 2026-03-25
N8n HIGH 8.8
CVE-2026-33660

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create o…

Fix: 1.123.27 / 2.13.3+
Fix from $1,950 2026-03-25
N8n HIGH 8.8
CVE-2026-33696

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create o…

Fix: 1.123.27 / 2.13.3+
Fix from $1,950 2026-03-25
N8n HIGH 8.8
CVE-2026-33713

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create o…

Fix: 1.123.26 / 2.13.3+
Fix from $1,950 2026-03-25
N8n HIGH 7.5
CVE-2026-33665

n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linke…

Fix: 1.121.0 / 2.4.0+
Fix from $1,950 2026-03-25
N8n MEDIUM 6.5
CVE-2026-33663

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` ro…

Fix: 1.123.27 / 2.13.3+
Fix from $1,600 2026-03-25
N8n MEDIUM 6.5
CVE-2026-27496

n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $1,600 2026-03-25
N8n CRITICAL 9.9
CVE-2026-27577EPSS 9%

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation o…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n HIGH 8.8
CVE-2026-27497

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $1,950 2026-02-25
N8n HIGH 8.8
CVE-2026-27498

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify wo…

Fix: 1.123.8 / 2.2.0+
Fix from $1,950 2026-02-25
N8n MEDIUM 5.4
CVE-2026-27578

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $1,600 2026-02-25
N8n CRITICAL 9.9
CVE-2026-27494

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.9
CVE-2026-27495

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.0
CVE-2026-27493

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability …

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n MEDIUM 6.5
CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validatio…

Fix: 1.121.0+
Fix from $1,600 2026-02-06
N8n HIGH 7.2
CVE-2026-21893

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s…

Fix: 1.120.3+
Fix from $1,950 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25052

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenti…

Fix: 1.123.18 / 2.5.0+
Fix from $2,300 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25053

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users…

Fix: 1.123.0 / 2.5.0+
Fix from $2,300 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25115

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to bre…

Fix: 2.4.8+
Fix from $2,300 2026-02-04
N8n HIGH 8.8
CVE-2026-25056

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed a…

Fix: 1.118.0 / 2.4.0+
Fix from $1,950 2026-02-04
N8n HIGH 8.1
CVE-2026-25055

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to …

Fix: 1.123.12 / 2.4.0f+
Fix from $1,950 2026-02-04
N8n MEDIUM 5.4
CVE-2026-25054

n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a mark…

Fix: 1.123.9 / 2.2.1+
Fix from $1,600 2026-02-04