Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

n8n — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting n8n. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page details security vulnerabilities associated with n8n, focusing on weakness classes and specific product tags. It aggregates vulnerability data related to the n8n automation platform, covering incidents reported from January 1, 2022, through the present day. The collection includes various types of security flaws, ranging from cross-site scripting and injection attacks to more complex logic errors and access control issues that have been identified in the software’s ecosystem. Readers can use this resource to track a vendor's advisories and monitor how n8n responds to emerging security threats over time. By examining these entries, users can better understand a specific weakness class within the context of workflow automation tools. The page also allows you to look up a product's vulnerability history, providing a chronological view of past exploits and patches. This historical data is essential for assessing long-term security posture and identifying recurring patterns in code quality or design flaws. Security teams can leverage this information to prioritize remediation efforts and improve their internal risk management strategies. The content is structured to facilitate quick searches for specific components or error types, ensuring that developers and administrators can efficiently locate relevant details. This approach supports proactive security management by highlighting areas that may require immediate attention or deeper architectural review. Ultimately, the page serves as a centralized reference for anyone concerned with the safety and integrity of the n8n environment, offering clear insights into the current threat landscape without unnecessary clutter or redundant information.

Top products by n8n: n8n
CVE IDTitleCVSSSeverityPublished
CVE-2026-58661 n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint — n8nCWE-770--2026-07-10
CVE-2026-56354 n8n - Cross-Site Scripting and Open Redirect in Form Node — n8nCWE-79 4.1 Medium2026-07-10
CVE-2026-59257 n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation — n8nCWE-89--2026-07-08
CVE-2026-59253 n8n - Improper Authorization in Workflow Assignment to Folders — n8nCWE-639--2026-07-08
CVE-2026-56778 n8n - Authorization Bypass in Public API Execution Retry Endpoint — n8nCWE-863 6.4 Medium2026-07-08
CVE-2026-56776 n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint — n8nCWE-863 7.4 High2026-07-08
CVE-2026-56775 n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints — n8nCWE-863 5.4 Medium2026-07-08
CVE-2026-56360 n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger — n8nCWE-290 4.0 Medium2026-07-08
CVE-2026-56359 n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL — n8nCWE-79 5.4 Medium2026-07-08
CVE-2025-71380 n8n - Arbitrary Command Execution via Execute Command Node — n8nCWE-284 8.8 High2026-07-04
CVE-2026-56777 n8n - AST Validator Bypass in Python Code Node — n8nCWE-184 5.0 Medium2026-06-30
CVE-2026-56356 n8n - Stored Cross-Site Scripting in Chat Trigger Node Custom CSS Field — n8nCWE-79 5.4 Medium2026-06-30
CVE-2026-56350 n8n - SSO Enforcement Bypass via API — n8nCWE-285 6.3 Medium2026-06-30
CVE-2026-56358 n8n - Stored Cross-Site Scripting in Form Trigger Node — n8nCWE-79 5.4 Medium2026-06-24
CVE-2026-56351 n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes — n8nCWE-89 8.2 High2026-06-24
CVE-2026-56357 n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook Trigger — n8nCWE-290 4.0 Medium2026-06-22
CVE-2026-56348 n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dynamic Node Parameters Endpoint — n8nCWE-918 9.1 Critical2026-06-22

This page lists every published CVE security advisory associated with n8n. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.