Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

n8n — Vulnerabilities & Security Advisories 100

All 100 CVE vulnerabilities found in n8n, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses affecting the open-source workflow automation tool n8n. It aggregates data related to various Common Weakness Enumeration (CWE) categories, including injection flaws, cross-site scripting, and insecure direct object references that may impact the integrity or confidentiality of automated workflows. The collection covers vulnerabilities identified and reported between early 2021 and late 2024, capturing the historical security posture of the product as it evolved through multiple major releases. By consolidating these records, the page serves as a centralized repository for tracking the specific advisories issued by the n8n development team and the community. Users can utilize this resource to understand the nature and severity of weakness classes inherent to the software’s architecture or to look up the complete vulnerability history of specific n8n versions. This enables security professionals and system administrators to assess risk exposure, verify patch applicability, and make informed decisions about upgrading or mitigating identified threats without relying on fragmented sources. The information is intended to provide clarity on past incidents and support ongoing security monitoring efforts for organizations deploying n8n in production environments.

Vendor: n8n-io

CVE IDTitleCVSSSeverityPublished
CVE-2026-58661 n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint CWE-770--2026-07-10
CVE-2026-56354 n8n - Cross-Site Scripting and Open Redirect in Form Node CWE-79 4.1 Medium2026-07-10
CVE-2026-59209 n8n: Shared Credential Header Leak via HTTP Request Pagination Expression CWE-522--2026-07-09
CVE-2026-59206 n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration CWE-1321--2026-07-09
CVE-2026-59208 n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution CWE-287--2026-07-09
CVE-2026-59207 n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector CWE-693--2026-07-09
CVE-2026-59257 n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation CWE-89--2026-07-08
CVE-2026-59253 n8n - Improper Authorization in Workflow Assignment to Folders CWE-639--2026-07-08
CVE-2026-56778 n8n - Authorization Bypass in Public API Execution Retry Endpoint CWE-863 6.4 Medium2026-07-08
CVE-2026-56776 n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint CWE-863 7.4 High2026-07-08
CVE-2026-56775 n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints CWE-863 5.4 Medium2026-07-08
CVE-2026-56359 n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL CWE-79 5.4 Medium2026-07-08
CVE-2026-56360 n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger CWE-290 4.0 Medium2026-07-08
CVE-2025-71380 n8n - Arbitrary Command Execution via Execute Command Node CWE-284 8.8 High2026-07-04
CVE-2026-56777 n8n - AST Validator Bypass in Python Code Node CWE-184 5.0 Medium2026-06-30
CVE-2026-56350 n8n - SSO Enforcement Bypass via API CWE-285 6.3 Medium2026-06-30
CVE-2026-56356 n8n - Stored Cross-Site Scripting in Chat Trigger Node Custom CSS Field CWE-79 5.4 Medium2026-06-30
CVE-2026-56358 n8n - Stored Cross-Site Scripting in Form Trigger Node CWE-79 5.4 Medium2026-06-24
CVE-2026-56351 n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes CWE-89 8.2 High2026-06-24
CVE-2026-44792 n8n: Source Control Pull SQL Injection CWE-89--2026-06-23
CVE-2026-44791 n8n: XML Node Prototype Pollution Patch Bypass CWE-1321--2026-06-23
CVE-2026-44790 n8n: Arbitrary File Read via Git Node CWE-88--2026-06-23
CVE-2026-44789 n8n: HTTP Request Node Pagination Prototype Pollution to RCE CWE-1321--2026-06-23
CVE-2026-45732 n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints CWE-639--2026-06-23
CVE-2026-49444 n8n: Python sandbox escape CWE-20--2026-06-23
CVE-2026-49465 n8n: Git Node Clone and Push Operations Bypass File Sandbox CWE-22--2026-06-23
CVE-2026-54304 n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host CWE-200--2026-06-23
CVE-2026-54307 n8n: Credential Exfiltration via Permission Bypass CWE-863--2026-06-23
CVE-2026-54302 n8n: Stored XSS in Chat Trigger Node CWE-79--2026-06-23
CVE-2026-54305 n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints CWE-200--2026-06-23

All 100 known CVE vulnerabilities affecting n8n with full Chinese analysis, references, and POCs where available.