n8n has 105 CVEs on record. Disclosure cadence is accelerating: 84 in the last 90 days against 20 in the 90 before. The busiest recent month was July 2026 with 53. The median CVSS is 7.3 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (15) and CWE-1321 (7). Most affected products: n8n (104), @n8n/computer-use (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 84 prev 20
Weakness classes
Products
- n8n 104
- @n8n/computer-use 1
Worst active — by depth score
CVE-2026-27577Critical· 9.9n8n is an open source workflow automation platform67CVE-2026-85165Critical· 9.9n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals55CVE-2026-54310Medium· 9.9n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes55CVE-2026-54309High· 10.0n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions55CVE-2026-54305High· 9.9n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints55
n8n vulnerabilities
CVEs affecting n8n, newest first. Open any entry for full detail, references, and exploit status.
105 CVEsRSS
GHSA-m7jc-p4hf-xhwqHighDuplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-wq64-hcrf-8m56HighDuplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
GHSA-mwq7-vcmc-cm4qHighDuplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-38fj-36m5-783cMediumDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-59209Highn8n: Shared Credential Header Leak via HTTP Request Pagination Expression
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-59206Highn8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVE-2026-59207Highn8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
CVE-2026-59208Highn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVE-2026-65595Highn8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
CVE-2026-65593Mediumn8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65591HighPoCn8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2026-65016Highn8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-8342-988q-86crHighn8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-64xh-79j6-r5v8Highn8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-w46p-w7w2-fr9gHighDuplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-h5xr-fqvj-253pHighDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-vhcw-f978-xjjgHighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GHSA-725q-c4vp-q4cgHighDuplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
GHSA-mhvh-gwhr-76pwMediumDuplicate Advisory: Google Service Account Private Key Exposed in JWT Header
Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header
CVE-2026-65015Highn8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
CVE-2026-65598Highn8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
CVE-2026-65597Highn8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65592Highn8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-65599Mediumn8n: Google Service Account Private Key Exposed in JWT Header
n8n: Google Service Account Private Key Exposed in JWT Header
GHSA-664h-gpgq-h6xxMedium· 5.4n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-49444High· 8.5n8n: Python sandbox escape
n8n: Python sandbox escape
CVE-2026-49465Medium· 7.7n8n: Git Node Clone and Push Operations Bypass File Sandbox
n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-54310Medium· 9.9n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2026-54313Medium· 7.7n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
GHSA-hv7x-3x78-gx53Medium· 7.4n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint