n8n-io n8n

48 known vulnerabilities in n8n-io n8n, 3 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2025-68613 CVSS 8.8 high · actively exploited n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

Latest vulnerabilities

  • CVE-2026-103260 CVSS 6.3 medium n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within…
  • CVE-2026-103259 CVSS 8.5 high n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and…
  • CVE-2026-103258 CVSS 6.9 medium n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice…
  • CVE-2026-103257 CVSS 8.1 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n…
  • CVE-2026-103256 CVSS 7.1 high n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow…
  • CVE-2026-103255 CVSS 7.1 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the…
  • CVE-2026-103254 CVSS 7.0 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed…
  • CVE-2026-103253 CVSS 7.0 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle…
  • CVE-2026-103252 CVSS 7.1 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the…
  • CVE-2026-103251 CVSS 7.5 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the…
  • CVE-2026-103250 CVSS 7.0 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the…
  • CVE-2026-103249 CVSS 6.9 medium n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting…
  • CVE-2026-103248 CVSS 7.1 high n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the…
  • CVE-2026-103247 CVSS 5.8 medium n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper…
  • CVE-2026-103246 CVSS 8.3 high n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection…
  • CVE-2026-103245 CVSS 6.9 medium n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the…
  • CVE-2026-92588 CVSS 5.9 medium n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the…
  • CVE-2026-92587 CVSS 5.3 medium n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL…
  • CVE-2026-86996 CVSS 5.3 medium n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by…
  • CVE-2026-86995 CVSS 5.3 medium n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter…
  • CVE-2026-86994 CVSS 5.3 medium n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned…
  • CVE-2026-86993 CVSS 5.9 medium n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could…
  • CVE-2026-86085 CVSS 5.1 medium n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and…
  • CVE-2026-86084 CVSS 6.0 medium n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints…
  • CVE-2026-86083 CVSS 7.7 high n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source…
  • CVE-2026-86082 CVSS 7.1 high n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential…
  • CVE-2026-86081 CVSS 7.1 high n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an…
  • CVE-2026-86080 CVSS 6.3 medium n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret…
  • CVE-2026-86079 CVSS 6.3 medium n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes…
  • CVE-2026-86078 CVSS 6.0 medium n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and…