VulnSea

n8n has 105 CVEs on record. Disclosure cadence is accelerating: 84 in the last 90 days against 20 in the 90 before. The busiest recent month was July 2026 with 53. The median CVSS is 7.3 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (15) and CWE-1321 (7). Most affected products: n8n (104), @n8n/computer-use (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.3
Publish → KEV
—
Last 90 days
84 prev 20

Products

  • n8n 104
  • @n8n/computer-use 1
105
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

n8n vulnerabilities

CVEs affecting n8n, newest first. Open any entry for full detail, references, and exploit status.

105 CVEsRSS

CVE-2026-54308Medium· 7.2
3mo ago

n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

▾ Sunlitn8n · n8nEPSS 0.30%via GHSA
CVE-2026-54301High· 7.6
3mo ago

n8n: Same-Origin XSS in Respond to Webhook Node

n8n: Same-Origin XSS in Respond to Webhook Node

▾ Twilightn8n · n8nEPSS 0.24%via GHSA
CVE-2026-54306Medium· 5.4
3mo ago

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

▾ Sunlitn8n · n8nEPSS 0.28%via GHSA
CVE-2026-54311Medium· 6.3
3mo ago

n8n: Merge Node SQL Mode Prototype Pollution

n8n: Merge Node SQL Mode Prototype Pollution

▾ Sunlitn8n · n8nEPSS 0.39%via GHSA
CVE-2026-54312High· 8.5
3mo ago

n8n: Microsoft SQL Node Prototype Pollution

n8n: Microsoft SQL Node Prototype Pollution

▾ Twilightn8n · n8nEPSS 0.40%via GHSA
CVE-2026-54303Medium· 7.6
3mo ago

n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints

n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints

▾ Sunlitn8n · n8nEPSS 0.23%via GHSA
CVE-2026-54302High· 7.6
3mo ago

n8n: Stored XSS in Chat Trigger Node

n8n: Stored XSS in Chat Trigger Node

▾ Twilightn8n · n8nEPSS 0.23%via GHSA
GHSA-jwm3-qcfw-c5ppMedium· 5.0
3mo ago

n8n: Python Code Node AST Validator Bypass

n8n: Python Code Node AST Validator Bypass

▾ Sunlitn8n · n8nvia GHSA
GHSA-h3jj-5f3v-3685Medium· 6.4
3mo ago

n8n: Public API Execution Retry Authorization Bypass

n8n: Public API Execution Retry Authorization Bypass

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-54314Medium· 5.9
3mo ago

n8n: Denial of Service via ZIP decompression in webhook workflow

n8n: Denial of Service via ZIP decompression in webhook workflow

▾ Sunlitn8n · n8nEPSS 0.55%via GHSA
CVE-2026-54307High· 9.6
3mo ago

n8n: Credential Exfiltration via Permission Bypass

n8n: Credential Exfiltration via Permission Bypass

▾ Twilightn8n · n8nEPSS 0.39%via GHSA
CVE-2026-54305High· 9.9
3mo ago

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

▾ Twilightn8n · n8nEPSS 0.37%via GHSA
CVE-2026-54309High· 10.0
3mo ago

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

▾ Twilightn8n · n8nEPSS 0.55%via GHSA
CVE-2026-54304High· 7.7
3mo ago

n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host

n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host

▾ Twilightn8n · n8nEPSS 0.38%via GHSA
CVE-2026-27577Critical· 9.9PoC
7mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…

▾ Abyssaln8n · n8nEPSS 1.0%via NVD
n8n vulnerabilities (CVEs) — page 4 · VulnSea