← All vendors

n8n

73 known vulnerabilities affecting n8n products.

Products

n8n 73

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-27577 Medium 10.0% 9.9 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.…
CVE-2026-77068 Medium 0.6% 8.8 n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulne…
CVE-2026-65591 Medium 0.5% 8.8 n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator…
CVE-2026-65595 Medium 0.5% 8.8 n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued th…
CVE-2026-85168 Medium 0.5% 8.8 n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution…
CVE-2026-72765 Medium 0.4% 9.9 n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in ex…
CVE-2026-86076 Medium 0.4% 8.8 n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a…
CVE-2026-77084 Medium 0.4% 8.8 n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution v…
CVE-2026-72767 Medium 0.4% 8.8 n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remot…
CVE-2026-85169 Medium 0.4% 8.8 n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox e…
CVE-2026-72773 Medium 0.4% 7.7 n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in …
CVE-2026-72764 Medium 0.4% 8.8 n8n's JavaScript task runner shared a single module cache across all users' Code…
CVE-2026-86083 Medium 0.4% 8.8 n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a…
CVE-2026-86075 Medium 0.3% 7.5 n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, …
CVE-2026-77071 Medium 0.3% 9.8 n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vu…
CVE-2026-65015 Medium 0.3% 8.8 n8n versions before 2.30.1 contain a privilege escalation vulnerability in the A…
CVE-2026-65590 Medium 0.3% 9.8 n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restri…
CVE-2026-85165 Medium 0.3% 9.9 n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability wh…
CVE-2026-77077 Medium 0.3% 7.6 n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runne…
CVE-2026-77080 Medium 0.3% 8.8 n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbi…
CVE-2026-65016 Medium 0.3% 8.8 n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation …
CVE-2026-77070 Medium 0.3% 9.8 n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability…
CVE-2026-86074 Medium 0.3% 7.1 n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, …
CVE-2026-72766 Medium 0.3% 7.5 n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type …
CVE-2026-72750 Medium 0.3% 8.8 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability i…
CVE-2026-72775 Medium 0.3% 8.8 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability i…
CVE-2026-77075 Medium 0.3% 7.3 n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expr…
CVE-2026-72769 Medium 0.3% 8.1 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerabi…
CVE-2026-77079 Medium 0.2% 8.8 n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom proj…
CVE-2026-65598 Medium 0.2% 7.5 n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the …
CVE-2026-72772 Medium 0.2% 8.8 n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the …
CVE-2026-72768 Medium 0.2% 8.3 n8n versions before 2.32.1 contain a server-side request forgery protection bypa…
CVE-2026-86073 Medium 0.2% 7.6 n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, …
CVE-2026-77081 Medium 0.2% 7.1 n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed…
CVE-2026-65596 Medium 0.2% 8.1 n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Reque…
CVE-2026-72762 Medium 0.2% 8.8 n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write…
CVE-2026-77072 Medium 0.2% 7.6 n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting v…
CVE-2026-72770 Low 0.5% 6.5 n8n versions before 1.123.67 contain a path traversal vulnerability in the Git n…
CVE-2026-65589 Low 0.4% 6.5 n8n versions before 1.123.64 fail to properly mask custom HTTP header credential…
CVE-2026-65014 Low 0.3% 5.3 n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE …
CVE-2026-86079 Low 0.3% 6.5 n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a…
CVE-2026-86078 Low 0.3% 6.5 n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, …
CVE-2026-85171 Low 0.3% 6.5 n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerabi…
CVE-2026-72749 Low 0.3% 6.5 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerabi…
CVE-2026-72774 Low 0.3% 6.5 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypa…
CVE-2026-77076 Low 0.3% 6.5 n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosu…
CVE-2026-86995 Low 0.3% 4.3 n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a…
CVE-2026-77082 Low 0.3% 4.3 n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regu…
CVE-2026-65594 Low 0.3% 6.5 n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth…
CVE-2026-86993 Low 0.3% 4.9 n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a…
Page 1 of 2 Next →