Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

n8n-io — Vulnerabilities & Security Advisories 113

Browse all 113 CVE security advisories affecting n8n-io. AI-powered Chinese analysis, POCs, and references for each vulnerability.

n8n-io is a fair-code workflow automation platform enabling users to connect various services and build complex integrations without extensive coding. Its architecture, which relies heavily on Node.js and external service connections, has historically exposed it to a significant number of security issues, currently totaling 58 recorded CVEs. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and improper access control, often stemming from insecure default configurations or insufficient input validation in its node execution engine. Notable incidents involve potential unauthorized access through exposed webhook endpoints and privilege escalation flaws within the user interface. The platform’s reliance on third-party libraries and dynamic workflow execution introduces inherent risks, requiring strict configuration management and regular updates to mitigate exploitation vectors. Users must implement robust network segmentation and monitor for suspicious activity to maintain security integrity.

Found 113 results / 113Clear Filters
Top products by n8n-io: n8n
CVE IDTitleCVSSSeverityPublished
CVE-2026-59209 n8n: Shared Credential Header Leak via HTTP Request Pagination Expression — n8nCWE-522--2026-07-09
CVE-2026-59206 n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration — n8nCWE-1321--2026-07-09
CVE-2026-59208 n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution — n8nCWE-287--2026-07-09
CVE-2026-59207 n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector — n8nCWE-693--2026-07-09
CVE-2026-44792 n8n: Source Control Pull SQL Injection — n8nCWE-89--2026-06-23
CVE-2026-44791 n8n: XML Node Prototype Pollution Patch Bypass — n8nCWE-1321--2026-06-23
CVE-2026-44790 n8n: Arbitrary File Read via Git Node — n8nCWE-88--2026-06-23
CVE-2026-44789 n8n: HTTP Request Node Pagination Prototype Pollution to RCE — n8nCWE-1321--2026-06-23
CVE-2026-45732 n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints — n8nCWE-639--2026-06-23
CVE-2026-49444 n8n: Python sandbox escape — n8nCWE-20--2026-06-23
CVE-2026-49465 n8n: Git Node Clone and Push Operations Bypass File Sandbox — n8nCWE-22--2026-06-23
CVE-2026-54304 n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host — n8nCWE-200--2026-06-23
CVE-2026-54307 n8n: Credential Exfiltration via Permission Bypass — n8nCWE-863--2026-06-23
CVE-2026-54302 n8n: Stored XSS in Chat Trigger Node — n8nCWE-79--2026-06-23
CVE-2026-54305 n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints — n8nCWE-200--2026-06-23
CVE-2026-54301 n8n: Same-Origin XSS in Respond to Webhook Node — n8nCWE-79--2026-06-23
CVE-2026-54306 n8n: Prototype Pollution enables confused-deputy execution via public webhooks — n8nCWE-1321--2026-06-23
CVE-2026-54308 n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node — n8nCWE-290--2026-06-23
CVE-2026-54311 n8n: Merge Node SQL Mode Prototype Pollution — n8nCWE-488--2026-06-23
CVE-2026-54310 n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes — n8nCWE-89--2026-06-23
CVE-2026-54309 n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions — n8nCWE-306--2026-06-23
CVE-2026-54314 n8n: Denial of Service via ZIP decompression in webhook workflow — n8nCWE-409--2026-06-23
CVE-2026-54312 n8n: Microsoft SQL Node Prototype Pollution — n8nCWE-1321--2026-06-23
CVE-2026-54303 n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints — n8nCWE-79--2026-06-23
CVE-2026-54313 n8n: NoSQL Injection in MongoDB Node Find And Replace Operation — n8nCWE-89--2026-06-23
CVE-2026-42237 n8n: SQL Injection in Snowflake and MySQL Nodes — n8nCWE-89 8.8 -2026-05-04
CVE-2026-42236 n8n: Unauthenticated Denial of Service via MCP Client Registration — n8nCWE-770 7.5 -2026-05-04
CVE-2026-42235 n8n: XSS via MCP OAuth client — n8nCWE-87 8.8 -2026-05-04
CVE-2026-42234 n8n: Python Task Runner Sandbox Escape — n8nCWE-94 9.9 -2026-05-04
CVE-2026-42233 n8n: SQL Injection in Oracle Database Node via Limit Field — n8nCWE-89 8.1 -2026-05-04

This page lists every published CVE security advisory associated with n8n-io. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.