Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

n8n — Vulnerabilities & Security Advisories 135

All 135 CVE vulnerabilities found in n8n, with AI-generated Chinese analysis, references, and POCs.

This page details known security vulnerabilities affecting the n8n automation platform, categorized under common weakness enumeration tags for structured analysis. It aggregates vulnerability data spanning multiple years to provide a comprehensive historical view of security incidents associated with this specific product. Readers can utilize this resource to track vendor advisories as they are released, gaining insight into the remediation pace and severity assessments for reported issues. Additionally, the page allows users to understand specific weakness classes by examining how different flaws impact the platform’s architecture and operational integrity. By exploring the vulnerability history, security professionals and developers can identify recurring patterns in bug reports, such as authentication bypasses, injection flaws, or improper access controls, which may indicate systemic design weaknesses. This aggregated view supports risk assessment activities by contextualizing individual security events within the broader timeline of product maintenance and patch deployment. The information presented here serves as a reference for evaluating the security posture of n8n deployments, enabling teams to prioritize updates and mitigate risks based on verified historical data rather than isolated incident reports.

Vendor: n8n-io

CVE IDTitleCVSSSeverityPublished
CVE-2026-33749 n8n Vulnerable to XSS via Binary Data Inline HTML Rendering CWE-79 4.6 -2026-03-25
CVE-2026-33724 n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no CWE-639 6.5 -2026-03-25
CVE-2026-33722 n8n Has External Secrets Authorization Bypass in Credential Saving CWE-863 5.3 -2026-03-25
CVE-2026-33720 n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK CWE-863 5.4 -2026-03-25
CVE-2026-33713 n8n Vulnerable to SQL Injection in Data Table Node via orderByColumn Expression CWE-89 8.8 -2026-03-25
CVE-2026-33696 n8n Vulnerable to Prototype Pollution in XML & GSuiteAdmin node parameters lead to RCE CWE-1321 8.8 -2026-03-25
CVE-2026-33665 n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover CWE-287 8.5 -2026-03-25
CVE-2026-33663 n8n Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition CWE-639 6.5 -2026-03-25
CVE-2026-33660 n8n Has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode CWE-94 8.8 -2026-03-25
CVE-2026-27496 n8n has In-Process Memory Disclosure in its Task Runner CWE-908 6.5 -2026-03-25
CVE-2026-27498 n8n has Arbitrary Command Execution via File Write and Git Operations CWE-94 8.8AIHighAI2026-02-25
CVE-2026-27578 n8n Vulnerable to Stored XSS via Various Nodes CWE-80 5.4AIMediumAI2026-02-25
CVE-2026-27577 n8n: Expression Sandbox Escape Leads to RCE CWE-94 9.4 Critical2026-02-25
CVE-2026-27497 n8n has Potential Remote Code Execution via Merge Node CWE-94 8.8AIHighAI2026-02-25
CVE-2026-27495 n8n has a Sandbox Escape in its JavaScript Task Runner CWE-94 8.5AIHighAI2026-02-25
CVE-2026-27494 n8n has Arbitrary File Read via Python Code Node Sandbox Escape CWE-497 9.9AICriticalAI2026-02-25
CVE-2026-27493 n8n has Unauthenticated Expression Evaluation via Form Node CWE-94 9.8AICriticalAI2026-02-25
CVE-2026-25631 Domain allowlist bypass enables credential exfiltration CWE-20 6.5AIMediumAI2026-02-06
CVE-2026-21893 n8n Vulnerable to Command Injection in Community Package Installation CWE-78 7.2AIHighAI2026-02-04
CVE-2026-25115 n8n is vulnerable to Python sandbox escape CWE-693 9.9AICriticalAI2026-02-04
CVE-2026-25056 n8n Arbitrary File Write leading to RCE in n8n Merge Node CWE-434 8.8AIHighAI2026-02-04
CVE-2026-25055 n8n Arbitrary File Write on Remote Systems via SSH Node CWE-22 10.0AICriticalAI2026-02-04
CVE-2026-25054 n8n is Vulnerable to Stored Cross-Site Scripting via Markdown Rendering in Workflow UI CWE-80 5.4AIMediumAI2026-02-04
CVE-2026-25053 n8n is Vulnerable to OS Command Injection in Git Node CWE-78 8.8AIHighAI2026-02-04
CVE-2026-25052 n8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Users CWE-367 8.8AIHighAI2026-02-04
CVE-2026-25051 n8n Improper CSP Enforcement in Webhook Responses May Allow Stored XSS CWE-79 5.4AIMediumAI2026-02-04
CVE-2025-61917 n8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner CWE-668 7.7 High2026-02-04
CVE-2026-25049 n8n Has an Expression Escape Vulnerability Leading to RCE CWE-913 9.9AICriticalAI2026-02-04
CVE-2025-68949 n8n has a Webhook Node IP Whitelist Bypass via Partial String Matching CWE-134 5.3 Medium2026-01-13
CVE-2026-21894 n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks CWE-290 6.5 Medium2026-01-08

All 135 known CVE vulnerabilities affecting n8n with full Chinese analysis, references, and POCs where available.