VulnSea

n8n vulnerabilities

CVEs whose affected-version data names the n8n package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

107 CVEsRSS

CVE-2026-92587Medium· 5.0
6d ago

n8n is a workflow automation platform

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git …

Sunlitn8n-io · n8nEPSS 0.18%via NVD
CVE-2026-92588Medium· 4.4
6d ago

n8n is a workflow automation platform

n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead o…

Sunlitn8n-io · n8nEPSS 0.19%via NVD
CVE-2026-86995Medium· 4.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration with…

Sunlitn8n · n8nEPSS 0.28%via NVD
CVE-2026-86994Medium· 4.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, de…

Sunlitn8n · n8nEPSS 0.20%via NVD
CVE-2026-86993Medium· 4.9
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership chec…

Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86085Medium· 4.9
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …

Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86084Medium· 5.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterpri…

Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86083High· 8.8
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and inter…

Twilightn8n · n8nEPSS 0.36%via NVD
CVE-2026-86082Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…

Sunlitn8n · n8nEPSS 0.24%via NVD
CVE-2026-86081High· 7.1
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The p…

Twilightn8n-io · n8nEPSS 0.32%via NVD
CVE-2026-86080Medium· 5.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow sta…

Sunlitn8n · n8nEPSS 0.16%via NVD
CVE-2026-86079Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An i…

Sunlitn8n · n8nEPSS 0.33%via NVD
CVE-2026-86078Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API…

Sunlitn8n · n8nEPSS 0.33%via NVD
CVE-2026-86077Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous f…

Sunlitn8n · n8nEPSS 0.25%via NVD
CVE-2026-86076High· 8.8
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __s…

Twilightn8n · n8nEPSS 0.43%via NVD
CVE-2026-86075High· 7.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated re…

Twilightn8n · n8nEPSS 0.34%via NVD
CVE-2026-86996Medium· 5.4
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a too…

Sunlitn8n · n8nEPSS 0.17%via NVD
CVE-2026-86073High· 7.6
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked on…

Twilightn8n · n8nEPSS 0.22%via NVD
CVE-2026-86074High· 7.1
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-co…

Twilightn8n · n8nEPSS 0.28%via NVD
CVE-2026-85173Medium· 4.3
2w ago

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attac…

Sunlitn8n · n8nEPSS 0.21%via NVD
CVE-2026-85172Medium· 6.4
2w ago

n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes

n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HT…

Sunlitn8n · n8nEPSS 0.15%via NVD
CVE-2026-85171Medium· 6.5
2w ago

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper…

Sunlitn8n · n8nEPSS 0.32%via NVD
CVE-2026-85170Medium· 6.5
2w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that res…

Sunlitn8n · n8nEPSS 0.23%via NVD
CVE-2026-85169High· 8.8
2w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; agai…

Twilightn8n · n8nEPSS 0.48%via NVD
CVE-2026-85168High· 8.8
2w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the cont…

Twilightn8n · n8nEPSS 0.46%via NVD
CVE-2026-85167Medium· 6.5
2w ago

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression value…

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression value…

Sunlitn8n · n8nEPSS 0.23%via NVD
CVE-2026-85166Medium· 6.5
2w ago

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node)

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/up…

Sunlitn8n · n8nEPSS 0.21%via NVD
CVE-2026-85165Critical· 9.9
2w ago

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-ed…

Midnightn8n · n8nEPSS 0.32%via NVD
CVE-2026-72772High· 8.8
1mo ago

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that t…

Twilightn8n · n8nEPSS 0.26%via NVD
CVE-2026-72774Medium· 6.5
1mo ago

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the crede…

Sunlitn8n · n8nEPSS 0.27%via NVD
n8n vulnerabilities (CVEs) · VulnSea