Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

n8n-io — Vulnerabilities & Security Advisories 113

Browse all 113 CVE security advisories affecting n8n-io. AI-powered Chinese analysis, POCs, and references for each vulnerability.

n8n-io is a fair-code workflow automation platform enabling users to connect various services and build complex integrations without extensive coding. Its architecture, which relies heavily on Node.js and external service connections, has historically exposed it to a significant number of security issues, currently totaling 58 recorded CVEs. Common vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and improper access control, often stemming from insecure default configurations or insufficient input validation in its node execution engine. Notable incidents involve potential unauthorized access through exposed webhook endpoints and privilege escalation flaws within the user interface. The platform’s reliance on third-party libraries and dynamic workflow execution introduces inherent risks, requiring strict configuration management and regular updates to mitigate exploitation vectors. Users must implement robust network segmentation and monitor for suspicious activity to maintain security integrity.

Found 113 results / 113Clear Filters
Top products by n8n-io: n8n
CVE IDTitleCVSSSeverityPublished
CVE-2026-72774 n8n before 1.123.67 Authentication Bypass via HTTP Request Node — n8nCWE-639 7.1 High2026-08-11
CVE-2026-72775 n8n before 1.123.67 SQL Injection via PostgresTrigger Node — n8nCWE-89 5.8 Medium2026-08-11
CVE-2026-72773 n8n before 2.32.1 Path Traversal via computer-use search_files — n8nCWE-22 4.9 Medium2026-08-11
CVE-2026-72771 n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes — n8nCWE-863 7.1 High2026-08-11
CVE-2026-72772 n8n before 2.32.1 Authentication Bypass via Token Exchange — n8nCWE-640 8.9 High2026-08-11
CVE-2026-72770 n8n before 1.123.67 Path Traversal via Git Node Operations — n8nCWE-22 7.1 High2026-08-11
CVE-2026-72769 n8n before 1.123.67 Prototype Pollution via VM Expression Engine — n8nCWE-1321 6.1 Medium2026-08-11
CVE-2026-72768 n8n before 2.32.1 SSRF Protection Bypass via MCP Client — n8nCWE-918 6.4 Medium2026-08-11
CVE-2026-72767 n8n before 1.123.67 Remote Code Execution via Git node — n8nCWE-78 8.7 High2026-08-11
CVE-2026-72766 n8n before 1.123.67 Arbitrary File Read via Send Email Node — n8nCWE-843 8.2 High2026-08-11
CVE-2026-72765 n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape — n8nCWE-94 8.7 High2026-08-11
CVE-2026-72764 n8n before 1.123.67 Module Cache Poisoning via Code Node — n8nCWE-668 5.8 Medium2026-08-11
CVE-2026-72763 n8n before 1.123.67 Credential Exfiltration via Sub-Workflow — n8nCWE-639 7.2 High2026-08-11
CVE-2026-72762 n8n before 1.123.67 Arbitrary File Write via Edit Image Node — n8nCWE-434 7.7 High2026-08-11
CVE-2026-72749 n8n before 1.123.67 Prototype Pollution via Edit Fields — n8nCWE-1321 7.1 High2026-08-11
CVE-2026-72750 n8n before 1.123.67 SQL Injection via executeQuery Operation — n8nCWE-89 5.3 Medium2026-08-11
CVE-2026-65599 n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header — n8nCWE-312 5.1 Medium2026-07-22
CVE-2026-65598 n8n before 1.123.64 Remote Code Execution via Git Clone — n8nCWE-367--2026-07-22
CVE-2026-65597 n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe — n8nCWE-79--2026-07-22
CVE-2026-65596 n8n before 1.123.64 Credential Exfiltration via GraphQL Node — n8nCWE-863--2026-07-22
CVE-2026-65594 n8n before 2.30.1 Missing OAuth Authorization Check — n8nCWE-863 5.1 Medium2026-07-22
CVE-2026-65595 n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange — n8nCWE-269 8.9 High2026-07-22
CVE-2026-65593 n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters — n8nCWE-918 6.3 Medium2026-07-22
CVE-2026-65592 n8n before 1.123.64 Stored DOM XSS via cachedResultUrl — n8nCWE-79--2026-07-22
CVE-2026-65591 n8n before 1.123.64 Sanitizer Bypass Remote Code Execution — n8nCWE-917--2026-07-22
CVE-2026-65590 n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows — n8nCWE-78--2026-07-22
CVE-2026-65016 n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance-Role — n8nCWE-639 7.7 High2026-07-22
CVE-2026-65589 n8n before 1.123.64 Credential Exposure via LLM Node Execution Data — n8nCWE-532 5.1 Medium2026-07-22
CVE-2026-65015 n8n before 2.30.1 Privilege Escalation via run_node_tool — n8nCWE-863--2026-07-22
CVE-2026-65014 n8n before 2.28.0 Authentication Bypass via test-webhook — n8nCWE-306--2026-07-22

This page lists every published CVE security advisory associated with n8n-io. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.