n8n
73 known vulnerabilities affecting n8n products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-86084 | Low | 0.3% | 5.5 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-86085 | Low | 0.3% | 4.9 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, … | |
| CVE-2026-86077 | Low | 0.3% | 6.5 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, … | |
| CVE-2026-86082 | Low | 0.2% | 6.5 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-85170 | Low | 0.2% | 6.5 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gma… | |
| CVE-2026-85167 | Low | 0.2% | 6.5 | n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerabili… | |
| CVE-2026-77083 | Low | 0.2% | 5.9 | n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, an… | |
| CVE-2026-65597 | Low | 0.2% | 5.4 | n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based c… | |
| CVE-2026-77074 | Low | 0.2% | 6.5 | n8n versions before 1.123.69 contain a server-side request forgery vulnerability… | |
| CVE-2026-77085 | Low | 0.2% | 6.5 | n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in… | |
| CVE-2026-72763 | Low | 0.2% | 6.5 | n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a n… | |
| CVE-2026-72771 | Low | 0.2% | 6.5 | n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allo… | |
| CVE-2026-85166 | Low | 0.2% | 6.5 | n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential referenc… | |
| CVE-2026-85173 | Low | 0.2% | 4.3 | n8n versions before 2.36.2 contain a missing per-project authorization vulnerabi… | |
| CVE-2026-77073 | Low | 0.2% | 4.3 | n8n versions before 2.34.1 contain a credential validation bypass in the MCP cre… | |
| CVE-2026-86994 | Low | 0.2% | 4.3 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-77069 | Low | 0.2% | 4.3 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in th… | |
| CVE-2026-65592 | Low | 0.2% | 5.4 | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripti… | |
| CVE-2026-86996 | Low | 0.2% | 5.4 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, … | |
| CVE-2026-86080 | Low | 0.2% | 5.3 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-85172 | Low | 0.2% | 6.4 | n8n versions before 2.34.1 contain a server-side request forgery vulnerability i… | |
| CVE-2026-65599 | Low | 0.2% | 6.5 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure v… | |
| CVE-2026-65593 | Low | 0.1% | 5.4 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request f… |
← Prev Page 2 of 2