Skip to content

n8n security advisories

156 advisories · 79 critical or high in 12 months · latest Sep 10

60 of 156 advisories

DateAdvisory
Sep 10n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
CVE-2026-86073Mediumfixed in 2.37.7, 2.38.1
Sep 10n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
CVE-2026-86074Mediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
CVE-2026-86995Mediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
CVE-2026-86085Mediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
CVE-2026-86993Mediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
CVE-2026-86084Mediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
CVE-2026-86080Mediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
CVE-2026-86079Mediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
CVE-2026-86078Mediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
CVE-2026-86994Mediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
CVE-2026-86083Highfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
CVE-2026-86077Mediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
CVE-2026-86082Highfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
CVE-2026-86081Highfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
CVE-2026-86075Highfixed in 2.37.7, 2.38.2
Sep 10n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
CVE-2026-86076Highfixed in 1.123.76, 2.37.7, 2.38.2
Sep 8n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
CVE-2026-86996Mediumfixed in 2.37.7, 2.38.2
Jul 22n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
CVE-2026-72750Mediumfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
CVE-2026-72775Mediumfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
CVE-2026-72764Mediumfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
CVE-2026-65589Mediumfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
CVE-2026-65014Mediumfixed in 2.27.4
Jul 22n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
CVE-2026-65596Mediumfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
CVE-2026-65594Mediumfixed in 2.29.8, 2.30.1
Jul 22n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
CVE-2026-65590Mediumfixed in 2.29.8, 2.30.1
Jul 22n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
CVE-2026-58661Mediumfixed in 1.123.58, 2.28.0
Jul 22n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
CVE-2026-59253Mediumfixed in 2.28.0
Jul 22n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
CVE-2026-59254Mediumfixed in 2.27.4, 2.28.1
Jul 22n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
CVE-2026-59257Mediumfixed in 1.123.61, 2.27.4, 2.28.1
Jul 22n8n: External Secrets Permission Bypass via Expression Parser Mismatch
CVE-2026-59259Mediumfixed in 1.123.61, 2.27.4, 2.28.1
Jul 22n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
CVE-2026-72773Mediumfixed in 2.31.5, 2.32.1
Jul 22n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
CVE-2026-72769Mediumfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
CVE-2026-72749Highfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Edit Image Node Format Injection Allows Arbitrary File Write
CVE-2026-72762Highfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
CVE-2026-72763Highfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
CVE-2026-72774Highfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Expression sandbox escape via arrow-function bodies enabling command execution
CVE-2026-72765Highfixed in 2.31.5, 2.32.1
Jul 22n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
CVE-2026-72766Highfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Authenticated code execution in the n8n Git node
CVE-2026-72767Highfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: SSRF Protection Bypass via MCP Client Node
CVE-2026-72768Mediumfixed in 2.31.5, 2.32.1
Jul 22n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
CVE-2026-72770Highfixed in 1.123.67, 2.31.5, 2.32.1
Jul 22n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
CVE-2026-72771Highfixed in 2.31.5, 2.32.1
Jul 22n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
CVE-2026-72772Highfixed in 2.31.5, 2.32.1
Jul 22n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
CVE-2026-65016Highfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2026-65591Highfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65593Mediumfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
CVE-2026-65595Highfixed in 2.29.8, 2.30.1
Jul 22n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVE-2026-59208Highfixed in 2.27.4, 2.28.1
Jul 22n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
CVE-2026-59207Highfixed in 2.27.4, 2.28.1
Jul 22n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVE-2026-59206Highfixed in 1.123.61, 2.27.4, 2.28.1
Jul 22n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-59209Highfixed in 1.123.61, 2.27.4, 2.28.1
Jul 22n8n: Google Service Account Private Key Exposed in JWT Header
CVE-2026-65599Mediumfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-65592Highfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65597Highfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
CVE-2026-65598Highfixed in 1.123.64, 2.29.8, 2.30.1
Jul 22n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
CVE-2026-65015Highfixed in 2.29.8, 2.30.1
Jun 17n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-56775Medium5.4fixed in 1.123.55, 2.25.7, 2.26.2
Jun 16n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2026-54304High7.7fixed in 1.123.55, 2.25.7, 2.26.1
Jun 16n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
CVE-2026-54309High10.0fixed in 2.25.7, 2.26.2
Jun 16n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-54305High9.9fixed in 1.123.55, 2.25.7, 2.26.2
About n8n

Workflow automation with AI agents.

Packages watched: n8n (npm).

n8n elsewhere on fru.dev: Releases · Repos

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.