Vulnerability index

Browse CVEs

115 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

N8n HIGH 7.5
CVE-2026-65598

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass …

Fix: 1.123.64 / 2.29.8+
Fix from $1,950 2026-07-22
N8n MEDIUM 6.5
CVE-2026-65599

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the …

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
N8n HIGH 8.8
CVE-2026-65591

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow creat…

Fix: 1.123.64 / 2.29.8+
Fix from $1,950 2026-07-22
N8n HIGH 8.8
CVE-2026-65595

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role.…

Fix: 2.29.8+
Fix from $1,950 2026-07-22
N8n HIGH 8.1
CVE-2026-65596

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic…

Fix: 1.123.64 / 2.29.8+
Fix from $1,950 2026-07-22
N8n MEDIUM 6.5
CVE-2026-65594

n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify …

Fix: 2.29.8+
Fix from $1,600 2026-07-22
N8n MEDIUM 5.4
CVE-2026-65592

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the …

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
N8n MEDIUM 5.4
CVE-2026-65593

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that la…

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
N8n MEDIUM 5.4
CVE-2026-65597

n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders …

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
N8n CRITICAL 9.8
CVE-2026-65590

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandbox…

Fix: 2.29.8+
Fix from $2,300 2026-07-22
N8n HIGH 8.8
CVE-2026-65015

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authoriza…

Fix: 2.29.8+
Fix from $1,950 2026-07-22
N8n HIGH 8.8
CVE-2026-65016

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provi…

Fix: 1.123.64 / 2.29.8+
Fix from $1,950 2026-07-22
N8n MEDIUM 6.5
CVE-2026-65589

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secr…

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
N8n MEDIUM 5.3
CVE-2026-65014

n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication midd…

Fix: 2.27.4+
Fix from $1,600 2026-07-22
N8n MEDIUM 6.5
CVE-2026-59259

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between…

Fix: 1.123.61 / 2.27.4+
Fix from $1,600 2026-07-15
N8n MEDIUM 5.4
CVE-2026-56354

n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form…

Fix: 1.123.24 / 2.10.4+
Fix from $1,600 2026-07-10
N8n MEDIUM 6.5
CVE-2026-59209

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a …

Fix: 1.123.61 / 2.27.4+
Fix from $1,600 2026-07-09
N8n HIGH 7.1
CVE-2026-59206

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create pe…

Fix: 1.123.61 / 2.27.4+
Fix from $1,950 2026-07-09
N8n MEDIUM 6.8
CVE-2026-59208

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trus…

Fix: 2.27.4+
Fix from $1,600 2026-07-09
N8n MEDIUM 6.5
CVE-2026-59207

n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domain…

Fix: 2.27.4+
Fix from $1,600 2026-07-09
N8n HIGH 8.8
CVE-2026-59257

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery op…

Fix: 1.123.61 / 2.27.4+
Fix from $1,950 2026-07-08
N8n MEDIUM 5.0
CVE-2026-59253

n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Att…

Fix: 2.28.0+
Fix from $1,600 2026-07-08
N8n HIGH 7.4
CVE-2026-56776

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes…

Fix: 1.123.55 / 2.25.7+
Fix from $1,950 2026-07-08
N8n MEDIUM 6.4
CVE-2026-56778

n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using…

Fix: 2.25.7 / 2.26.2+
Fix from $1,600 2026-07-08
N8n MEDIUM 5.4
CVE-2026-56775

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-…

Fix: 1.123.55 / 2.25.7+
Fix from $1,600 2026-07-08
N8n MEDIUM 5.4
CVE-2026-56359

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaS…

Fix: 2.6.4 / 2.8.0+
Fix from $1,600 2026-07-08
N8n MEDIUM 5.0
CVE-2026-56777

n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated…

Fix: 2.25.7 / 2.26.2+
Fix from $1,600 2026-06-30
N8n HIGH 7.7
CVE-2026-56350

n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attacke…

Fix: 2.8.0+
Fix from $1,950 2026-06-30
N8n MEDIUM 5.4
CVE-2026-56356

n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html l…

Fix: 1.123.27 / 2.13.3+
Fix from $1,600 2026-06-30
N8n CRITICAL 9.6
CVE-2026-56351

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inje…

Fix: 2.4.0+
Fix from $2,300 2026-06-24