Skip to content
n8nGHSA-r9xw-p7wj-w792

n8n Information Disclosure vulnerability

High7.5CVE-2023-27564 · Published May 10, 2023 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
n8n
npm
< 0.216.10.216.1
Details and references

More n8n advisories

All n8n
DateAdvisory
May 102023n8n Privilege Escalation vulnerability
CVE-2023-27563High8.8fixed in 0.216.1
May 102023n8n Directory Traversal vulnerability
CVE-2023-27562Medium6.5fixed in 0.216.1
Apr 282025n8n Vulnerable to Stored XSS through Attachments View Endpoint
CVE-2025-46343Medium5.0fixed in 1.90.0
Jun 272025n8n allows open redirects via the /signin endpoint
CVE-2025-49592Medium4.6fixed in 1.98.0
Jul 32025n8n Vulnerable to Denial of Service via Malformed Binary Data Requests
CVE-2025-49595Medium4.9fixed in 1.99.0
Jul 32025n8n is vulnerable to Improper Authorization through its `/stop` endpoint
CVE-2025-52554Medium4.3fixed in 1.99.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.