| Sep 10 | n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution CVE-2026-86073Mediumfixed in 2.37.7, 2.38.1 | Medium | 2.37.7, 2.38.1 |
| Sep 10 | n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content CVE-2026-86074Mediumfixed in 2.37.7, 2.38.2 | Medium | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read CVE-2026-86995Mediumfixed in 1.123.76, 2.37.7, 2.38.2 | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints CVE-2026-86085Mediumfixed in 2.37.7, 2.38.2 | Medium | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check CVE-2026-86993Mediumfixed in 1.123.76, 2.37.7, 2.38.2 | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions CVE-2026-86084Mediumfixed in 1.123.76, 2.37.7, 2.38.2 | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open CVE-2026-86080Mediumfixed in 1.123.76, 2.37.7, 2.38.2 | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers CVE-2026-86079Mediumfixed in 1.123.76, 2.37.7, 2.38.2 | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service CVE-2026-86078Mediumfixed in 2.37.7, 2.38.2 | Medium | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter CVE-2026-86994Mediumfixed in 1.123.76, 2.37.7, 2.38.2 | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution CVE-2026-86083Highfixed in 1.123.76, 2.37.7, 2.38.2 | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket CVE-2026-86077Mediumfixed in 2.37.7, 2.38.2 | Medium | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node CVE-2026-86082Highfixed in 1.123.76, 2.37.7, 2.38.2 | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path CVE-2026-86081Highfixed in 1.123.76, 2.37.7, 2.38.2 | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint CVE-2026-86075Highfixed in 2.37.7, 2.38.2 | High | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution CVE-2026-86076Highfixed in 1.123.76, 2.37.7, 2.38.2 | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 8 | n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy CVE-2026-86996Mediumfixed in 2.37.7, 2.38.2 | Medium | 2.37.7, 2.38.2 |
| Jul 22 | n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation CVE-2026-72750Mediumfixed in 1.123.67, 2.31.5, 2.32.1 | Medium | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances CVE-2026-72775Mediumfixed in 1.123.67, 2.31.5, 2.32.1 | Medium | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner CVE-2026-72764Mediumfixed in 1.123.67, 2.31.5, 2.32.1 | Medium | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data CVE-2026-65589Mediumfixed in 1.123.64, 2.29.8, 2.30.1 | Medium | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook CVE-2026-65014Mediumfixed in 2.27.4 | Medium | 2.27.4 |
| Jul 22 | n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction CVE-2026-65596Mediumfixed in 1.123.64, 2.29.8, 2.30.1 | Medium | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check CVE-2026-65594Mediumfixed in 2.29.8, 2.30.1 | Medium | 2.29.8, 2.30.1 |
| Jul 22 | n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows CVE-2026-65590Mediumfixed in 2.29.8, 2.30.1 | Medium | 2.29.8, 2.30.1 |
| Jul 22 | n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads CVE-2026-58661Mediumfixed in 1.123.58, 2.28.0 | Medium | 1.123.58, 2.28.0 |
| Jul 22 | n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects CVE-2026-59253Mediumfixed in 2.28.0 | Medium | 2.28.0 |
| Jul 22 | n8n: External Secrets Accessible via Workflow Expressions Outside Credentials CVE-2026-59254Mediumfixed in 2.27.4, 2.28.1 | Medium | 2.27.4, 2.28.1 |
| Jul 22 | n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation CVE-2026-59257Mediumfixed in 1.123.61, 2.27.4, 2.28.1 | Medium | 1.123.61, 2.27.4, 2.28.1 |
| Jul 22 | n8n: External Secrets Permission Bypass via Expression Parser Mismatch CVE-2026-59259Mediumfixed in 1.123.61, 2.27.4, 2.28.1 | Medium | 1.123.61, 2.27.4, 2.28.1 |
| Jul 22 | n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory CVE-2026-72773Mediumfixed in 2.31.5, 2.32.1 | Medium | 2.31.5, 2.32.1 |
| Jul 22 | n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service CVE-2026-72769Mediumfixed in 1.123.67, 2.31.5, 2.32.1 | Medium | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service CVE-2026-72749Highfixed in 1.123.67, 2.31.5, 2.32.1 | High | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Edit Image Node Format Injection Allows Arbitrary File Write CVE-2026-72762Highfixed in 1.123.67, 2.31.5, 2.32.1 | High | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON CVE-2026-72763Highfixed in 1.123.67, 2.31.5, 2.32.1 | High | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType` CVE-2026-72774Highfixed in 1.123.67, 2.31.5, 2.32.1 | High | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Expression sandbox escape via arrow-function bodies enabling command execution CVE-2026-72765Highfixed in 2.31.5, 2.32.1 | High | 2.31.5, 2.32.1 |
| Jul 22 | n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion CVE-2026-72766Highfixed in 1.123.67, 2.31.5, 2.32.1 | High | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Authenticated code execution in the n8n Git node CVE-2026-72767Highfixed in 1.123.67, 2.31.5, 2.32.1 | High | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: SSRF Protection Bypass via MCP Client Node CVE-2026-72768Mediumfixed in 2.31.5, 2.32.1 | Medium | 2.31.5, 2.32.1 |
| Jul 22 | n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction CVE-2026-72770Highfixed in 1.123.67, 2.31.5, 2.32.1 | High | 1.123.67, 2.31.5, 2.32.1 |
| Jul 22 | n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes CVE-2026-72771Highfixed in 2.31.5, 2.32.1 | High | 2.31.5, 2.32.1 |
| Jul 22 | n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login CVE-2026-72772Highfixed in 2.31.5, 2.32.1 | High | 2.31.5, 2.32.1 |
| Jul 22 | n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner CVE-2026-65016Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution CVE-2026-65591Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access CVE-2026-65593Mediumfixed in 1.123.64, 2.29.8, 2.30.1 | Medium | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs CVE-2026-65595Highfixed in 2.29.8, 2.30.1 | High | 2.29.8, 2.30.1 |
| Jul 22 | n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution CVE-2026-59208Highfixed in 2.27.4, 2.28.1 | High | 2.27.4, 2.28.1 |
| Jul 22 | n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector CVE-2026-59207Highfixed in 2.27.4, 2.28.1 | High | 2.27.4, 2.28.1 |
| Jul 22 | n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration CVE-2026-59206Highfixed in 1.123.61, 2.27.4, 2.28.1 | High | 1.123.61, 2.27.4, 2.28.1 |
| Jul 22 | n8n: Shared Credential Header Leak via HTTP Request Pagination Expression CVE-2026-59209Highfixed in 1.123.61, 2.27.4, 2.28.1 | High | 1.123.61, 2.27.4, 2.28.1 |
| Jul 22 | n8n: Google Service Account Private Key Exposed in JWT Header CVE-2026-65599Mediumfixed in 1.123.64, 2.29.8, 2.30.1 | Medium | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Stored DOM XSS via Resource Locator `cachedResultUrl` CVE-2026-65592Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview CVE-2026-65597Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution CVE-2026-65598Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool CVE-2026-65015Highfixed in 2.29.8, 2.30.1 | High | 2.29.8, 2.30.1 |
| Jun 17 | n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints CVE-2026-56775Medium5.4fixed in 1.123.55, 2.25.7, 2.26.2 | Medium5.4 | 1.123.55, 2.25.7, 2.26.2 |
| Jun 16 | n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host CVE-2026-54304High7.7fixed in 1.123.55, 2.25.7, 2.26.1 | High7.7 | 1.123.55, 2.25.7, 2.26.1 |
| Jun 16 | n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions CVE-2026-54309High10.0fixed in 2.25.7, 2.26.2 | High10.0 | 2.25.7, 2.26.2 |
| Jun 16 | n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints CVE-2026-54305High9.9fixed in 1.123.55, 2.25.7, 2.26.2 | High9.9 | 1.123.55, 2.25.7, 2.26.2 |