Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

n8n — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting n8n. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerability data specifically for the n8n vendor and its associated automation platform. It collects security advisories, bug reports, and exploit details, covering the period from 2019 to 2024. Here you can track the vendor’s published advisories, understand the prevalence of specific weakness classes, and review the product’s full vulnerability history. The dataset includes entries related to authentication flaws, injection issues, and configuration missteps that have affected n8n instances. You can filter results by severity, impact scope, or specific vulnerability types to refine your view. The records link directly to source reports and patch notes. This aggregation helps security teams quickly assess exposure without manually searching multiple registries. By consolidating these findings, the page simplifies the process of identifying patterns in how n8n handles common attack vectors. Users can compare historical incidents to understand recurring weaknesses in the product’s update cycle. The data remains unmodified from original sources, preserving authenticity. Overall, this collection serves as a centralized reference for anyone auditing n8n deployments. It supports compliance checks and risk modeling by providing a timeline of known issues. The interface allows users to sort entries by date or CVSS score, facilitating rapid triage. No marketing language is used; the content focuses strictly on factual reporting.

Found 22 results / 22 Clear Filters
Top products by n8n: n8n
CVE ID Title CVSS Severity Published
CVE-2026-59259 n8n - Permission Bypass via Expression Parser Mismatch in External Secrets — n8n CWE-639 - - 2026-07-15
CVE-2026-59254 n8n - External Secrets Disclosure via Workflow Node Expressions — n8n CWE-639 - - 2026-07-15
CVE-2026-56352 n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter — n8n CWE-22 6.4 Medium 2026-07-15
CVE-2026-56353 n8n - Authentication Bypass in Chat Trigger Node — n8n CWE-287 4.8 Medium 2026-07-15
CVE-2026-56349 n8n - Guardrail Node Bypass via Crafted Input — n8n CWE-20 - - 2026-07-15
CVE-2026-58661 n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint — n8n CWE-770 - - 2026-07-10
CVE-2026-56354 n8n - Cross-Site Scripting and Open Redirect in Form Node — n8n CWE-79 4.1 Medium 2026-07-10
CVE-2026-59257 n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation — n8n CWE-89 - - 2026-07-08
CVE-2026-59253 n8n - Improper Authorization in Workflow Assignment to Folders — n8n CWE-639 - - 2026-07-08
CVE-2026-56778 n8n - Authorization Bypass in Public API Execution Retry Endpoint — n8n CWE-863 6.4 Medium 2026-07-08
CVE-2026-56776 n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint — n8n CWE-863 7.4 High 2026-07-08
CVE-2026-56775 n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints — n8n CWE-863 5.4 Medium 2026-07-08
CVE-2026-56359 n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL — n8n CWE-79 5.4 Medium 2026-07-08
CVE-2026-56360 n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger — n8n CWE-290 4.0 Medium 2026-07-08
CVE-2025-71380 n8n - Arbitrary Command Execution via Execute Command Node — n8n CWE-284 8.8 High 2026-07-04
CVE-2026-56777 n8n - AST Validator Bypass in Python Code Node — n8n CWE-184 5.0 Medium 2026-06-30
CVE-2026-56350 n8n - SSO Enforcement Bypass via API — n8n CWE-285 6.3 Medium 2026-06-30
CVE-2026-56356 n8n - Stored Cross-Site Scripting in Chat Trigger Node Custom CSS Field — n8n CWE-79 5.4 Medium 2026-06-30
CVE-2026-56358 n8n - Stored Cross-Site Scripting in Form Trigger Node — n8n CWE-79 5.4 Medium 2026-06-24
CVE-2026-56351 n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes — n8n CWE-89 8.2 High 2026-06-24
CVE-2026-56357 n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook Trigger — n8n CWE-290 4.0 Medium 2026-06-22
CVE-2026-56348 n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dynamic Node Parameters Endpoint — n8n CWE-918 9.1 Critical 2026-06-22

This page lists every published CVE security advisory associated with n8n. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.