Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

N8n CRITICAL 9.9
CVE-2026-25049

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify w…

Fix: 1.123.17 / 2.5.2+
Fix from $2,300 2026-02-04
N8n MEDIUM 5.4
CVE-2026-25051

n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the h…

Fix: 1.123.2+
Fix from $1,600 2026-02-04
N8n HIGH 7.7
CVE-2025-61917

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow…

Fix: 1.114.3+
Fix from $1,950 2026-02-04
N8n CRITICAL 9.9
CVE-2026-1470EPSS 19%

n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated…

Fix: 1.123.17 / 2.4.5+
Fix from $2,300 2026-01-27
N8n CRITICAL 9.9
CVE-2026-0863EPSS 9%

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted…

Fix: after 2.4.2
Fix from $2,300 2026-01-18
N8n MEDIUM 5.3
CVE-2025-68949

n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string …

Fix: 2.2.0+
Fix from $1,600 2026-01-13
N8n MEDIUM 6.5
CVE-2026-21894

n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Tr…

Fix: 2.2.2+
Fix from $1,600 2026-01-08
N8n CRITICAL 9.9
CVE-2026-21877EPSS 5%

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us…

Fix: 1.121.3+
Fix from $2,300 2026-01-08
N8n CRITICAL 10.0
CVE-2026-21858EPSS 73%

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underly…

Fix: 1.121.0+
Fix from $2,300 2026-01-08
N8n CRITICAL 9.9
CVE-2025-68668EPSS 13%

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node…

Fix: 2.0.0+
Fix from $2,300 2025-12-26
N8n MEDIUM 5.4
CVE-2025-68697

n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task…

Fix: 2.0.0+
Fix from $1,600 2025-12-26
N8n MEDIUM 5.4
CVE-2025-61914

n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when…

Fix: 1.114.0+
Fix from $1,600 2025-12-26
N8n HIGH 8.8
CVE-2025-68613 KEVEPSS 98%

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remo…

Fix: 1.120.4+
Fix from $1,950 2025-12-19
N8n HIGH 8.8
CVE-2025-65964

n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the proj…

Fix: 1.119.2+
Fix from $1,950 2025-12-09
N8n HIGH 8.8
CVE-2025-62726

n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component availabl…

Fix: 1.113.0+
Fix from $1,950 2025-10-30
N8n MEDIUM 5.4
CVE-2025-58177

n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n…

Fix: 1.107.0+
Fix from $1,600 2025-09-15
N8n HIGH 8.8
CVE-2025-56265

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary cod…

No fix yet
Fix from $1,950 2025-09-08
Fastapi CRITICAL 9.1
CVE-2025-55526

n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py

No fix yet
Fix from $2,300 2025-08-26
N8n MEDIUM 6.5
CVE-2025-57749

n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the…

Fix: 1.106.0+
Fix from $1,600 2025-08-20
N8n MEDIUM 5.4
CVE-2025-52478

n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifi…

Fix: 1.98.2+
Fix from $1,600 2025-08-19
N8n MEDIUM 5.4
CVE-2025-49592

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be red…

Fix: 1.98.0+
Fix from $1,600 2025-06-26
N8n MEDIUM 5.4
CVE-2025-46343

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view e…

Fix: 1.90.0+
Fix from $1,600 2025-04-29
N8n HIGH 8.8
CVE-2023-27563

The n8n package 0.218.0 for Node.js allows Escalation of Privileges.

No fix yet
Fix from $1,950 2023-05-10
N8n HIGH 7.5
CVE-2023-27564

The n8n package 0.218.0 for Node.js allows Information Disclosure.

No fix yet
Fix from $1,950 2023-05-10
N8n MEDIUM 6.5
CVE-2023-27562

The n8n package 0.218.0 for Node.js allows Directory Traversal.

No fix yet
Fix from $1,600 2023-05-10