VulnSea

n8n has 105 CVEs on record. Disclosure cadence is accelerating: 84 in the last 90 days against 20 in the 90 before. The busiest recent month was July 2026 with 53. The median CVSS is 7.3 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (15) and CWE-1321 (7). Most affected products: n8n (104), @n8n/computer-use (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.3
Publish → KEV
Last 90 days
84 prev 20

Products

  • n8n 104
  • @n8n/computer-use 1
105
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

n8n vulnerabilities

CVEs affecting n8n, newest first. Open any entry for full detail, references, and exploit status.

105 CVEsRSS

CVE-2026-86995Medium· 4.3
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration with…

Sunlitn8n · n8nEPSS 0.28%via NVD
CVE-2026-86994Medium· 4.3
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, de…

Sunlitn8n · n8nEPSS 0.20%via NVD
CVE-2026-86993Medium· 4.9
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership chec…

Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86085Medium· 4.9
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …

Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86084Medium· 5.5
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterpri…

Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86083High· 8.8
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and inter…

Twilightn8n · n8nEPSS 0.36%via NVD
CVE-2026-86082Medium· 6.5
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…

Sunlitn8n · n8nEPSS 0.24%via NVD
CVE-2026-86080Medium· 5.3
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow sta…

Sunlitn8n · n8nEPSS 0.16%via NVD
CVE-2026-86079Medium· 6.5
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An i…

Sunlitn8n · n8nEPSS 0.33%via NVD
CVE-2026-86078Medium· 6.5
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API…

Sunlitn8n · n8nEPSS 0.33%via NVD
CVE-2026-86077Medium· 6.5
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous f…

Sunlitn8n · n8nEPSS 0.25%via NVD
CVE-2026-86076High· 8.8
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __s…

Twilightn8n · n8nEPSS 0.43%via NVD
CVE-2026-86075High· 7.5
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated re…

Twilightn8n · n8nEPSS 0.34%via NVD
CVE-2026-86996Medium· 5.4
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a too…

Sunlitn8n · n8nEPSS 0.17%via NVD
CVE-2026-86073High· 7.6
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked on…

Twilightn8n · n8nEPSS 0.22%via NVD
CVE-2026-86074High· 7.1
1w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-co…

Twilightn8n · n8nEPSS 0.28%via NVD
CVE-2026-85173Medium· 4.3
2w ago

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects

n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attac…

Sunlitn8n · n8nEPSS 0.21%via NVD
CVE-2026-85172Medium· 6.4
2w ago

n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes

n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HT…

Sunlitn8n · n8nEPSS 0.15%via NVD
CVE-2026-85171Medium· 6.5
2w ago

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper…

Sunlitn8n · n8nEPSS 0.32%via NVD
CVE-2026-85170Medium· 6.5
2w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that res…

Sunlitn8n · n8nEPSS 0.23%via NVD
CVE-2026-85169High· 8.8
2w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; agai…

Twilightn8n · n8nEPSS 0.48%via NVD
CVE-2026-85168High· 8.8
2w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the cont…

Twilightn8n · n8nEPSS 0.46%via NVD
CVE-2026-85167Medium· 6.5
2w ago

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression value…

n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, which build their JSON query by interpolating expression value…

Sunlitn8n · n8nEPSS 0.23%via NVD
CVE-2026-85166Medium· 6.5
2w ago

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node)

n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any user creating/up…

Sunlitn8n · n8nEPSS 0.21%via NVD
CVE-2026-85165Critical· 9.9
2w ago

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-ed…

Midnightn8n · n8nEPSS 0.32%via NVD
CVE-2026-72772High· 8.8
1mo ago

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that t…

Twilightn8n · n8nEPSS 0.26%via NVD
CVE-2026-72774Medium· 6.5
1mo ago

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the crede…

Sunlitn8n · n8nEPSS 0.27%via NVD
CVE-2026-72769High· 8.1
1mo ago

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a …

Twilightn8n · n8nEPSS 0.28%via NVD
CVE-2026-72767High· 8.8
1mo ago

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that cau…

Twilightn8n · n8nEPSS 0.48%via NVD
CVE-2026-72764High· 8.8
1mo ago

n8n's JavaScript task runner shared a single module cache across all users' Code-node executions

n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter o…

Twilightn8n · n8nEPSS 0.45%via NVD
n8n vulnerabilities (CVEs) · VulnSea