| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-58177 | n8n stored cross-site scripting in LangChain Chat Trigger node initialMessages parameter | n8n-io | n8n | Medium | 5.4 | 2025-09-15 16:49:07 | Deep Dive |
| CVE-2025-57749 | n8n has a symlink traversal vulnerability in "Read/Write File" node allows access to restricted files | n8n-io | n8n | Medium | 6.5 | 2025-08-20 21:46:40 | Deep Dive |
| CVE-2025-52478 | Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source | n8n-io | n8n | High | 8.7 | 2025-08-19 16:32:35 | Deep Dive |
| CVE-2025-52554 | n8n Improper Authorization in Workflow Execution Stop Endpoint Allows Terminating Other Users’ Workflows | n8n-io | n8n | - | - | 2025-07-03 20:08:54 | Deep Dive |
| CVE-2025-49595 | n8n Vulnerable to Denial of Service via Malformed Binary Data Requests | n8n-io | n8n | Medium | 4.9 | 2025-07-03 12:16:47 | Deep Dive |
| CVE-2025-49592 | n8n Login Flow has Open Redirect Vulnerability | n8n-io | n8n | Medium | 4.6 | 2025-06-26 19:45:28 | Deep Dive |
| CVE-2025-46343 | n8n Vulnerable to Stored XSS through Attachments View Endpoint | n8n-io | n8n | Medium | 5.0 | 2025-04-29 04:35:17 | Deep Dive |