n8n has 105 CVEs on record. Disclosure cadence is accelerating: 84 in the last 90 days against 20 in the 90 before. The busiest recent month was July 2026 with 53. The median CVSS is 7.3 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (15) and CWE-1321 (7). Most affected products: n8n (104), @n8n/computer-use (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 84 prev 20
Weakness classes
Products
- n8n 104
- @n8n/computer-use 1
Worst active — by depth score
CVE-2026-27577Critical· 9.9n8n is an open source workflow automation platform67CVE-2026-85165Critical· 9.9n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals55CVE-2026-54310Medium· 9.9n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes55CVE-2026-54309High· 10.0n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions55CVE-2026-54305High· 9.9n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints55
n8n vulnerabilities
CVEs affecting n8n, newest first. Open any entry for full detail, references, and exploit status.
105 CVEsRSS
CVE-2026-54308Medium· 7.2n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-54306Medium· 5.4n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54311Medium· 6.3n8n: Merge Node SQL Mode Prototype Pollution
n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-54312High· 8.5n8n: Microsoft SQL Node Prototype Pollution
n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-54303Medium· 7.6n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
CVE-2026-54302High· 7.6n8n: Stored XSS in Chat Trigger Node
n8n: Stored XSS in Chat Trigger Node
GHSA-jwm3-qcfw-c5ppMedium· 5.0n8n: Python Code Node AST Validator Bypass
n8n: Python Code Node AST Validator Bypass
GHSA-h3jj-5f3v-3685Medium· 6.4n8n: Public API Execution Retry Authorization Bypass
n8n: Public API Execution Retry Authorization Bypass
CVE-2026-54314Medium· 5.9n8n: Denial of Service via ZIP decompression in webhook workflow
n8n: Denial of Service via ZIP decompression in webhook workflow
CVE-2026-54307High· 9.6n8n: Credential Exfiltration via Permission Bypass
n8n: Credential Exfiltration via Permission Bypass
CVE-2026-54305High· 9.9n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-54309High· 10.0n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2026-54304High· 7.7n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2026-27577Critical· 9.9PoCn8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user w…