n8n vulnerabilities
CVEs whose affected-version data names the n8n package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
107 CVEsRSS
CVE-2026-54313Medium· 7.7n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
GHSA-hv7x-3x78-gx53Medium· 7.4n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-54308Medium· 7.2n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-54306Medium· 5.4n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54311Medium· 6.3n8n: Merge Node SQL Mode Prototype Pollution
n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-54312High· 8.5n8n: Microsoft SQL Node Prototype Pollution
n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-54303Medium· 7.6n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
CVE-2026-54302High· 7.6n8n: Stored XSS in Chat Trigger Node
n8n: Stored XSS in Chat Trigger Node
GHSA-jwm3-qcfw-c5ppMedium· 5.0n8n: Python Code Node AST Validator Bypass
n8n: Python Code Node AST Validator Bypass
GHSA-h3jj-5f3v-3685Medium· 6.4n8n: Public API Execution Retry Authorization Bypass
n8n: Public API Execution Retry Authorization Bypass
CVE-2026-54314Medium· 5.9n8n: Denial of Service via ZIP decompression in webhook workflow
n8n: Denial of Service via ZIP decompression in webhook workflow
CVE-2026-54307High· 9.6n8n: Credential Exfiltration via Permission Bypass
n8n: Credential Exfiltration via Permission Bypass
CVE-2026-54305High· 9.9n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-54309High· 10.0n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2026-54304High· 7.7n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2026-27577Critical· 9.9PoCn8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…