Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

n8n — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting n8n. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates Common Weakness Enumeration (CWE) vulnerabilities associated with n8n, an open-source workflow automation tool. It compiles security findings reported for n8n instances, focusing on weaknesses that may affect deployment, configuration, or usage of the automation platform. The database includes vulnerabilities identified over the past several years, providing a historical perspective on the product's security posture as it has evolved. Readers can use this resource to track n8n security advisories, monitor how specific weakness classes have impacted the software, and review the vulnerability history of various n8n versions. By centralizing this information, the page allows security professionals, developers, and system administrators to assess risks related to n8n deployments in their environments. The data reflects publicly disclosed weaknesses, including those reported by users, researchers, and official vendor notices. This approach supports informed decision-making regarding updates, patches, and architectural choices. The content is organized to facilitate easy searching by weakness type, product version, and disclosure date. Whether you are conducting a risk assessment, performing compliance checks, or simply staying informed about n8n security updates, this page serves as a comprehensive reference point. The information presented here is intended to aid in understanding the nature and scope of known vulnerabilities without endorsing any specific mitigation strategy, which should be determined based on individual organizational requirements and risk tolerance.

Top products by n8n: n8n
CVE IDTitleCVSSSeverityPublished
CVE-2026-59259 n8n - Permission Bypass via Expression Parser Mismatch in External Secrets — n8nCWE-639--2026-07-15
CVE-2026-59254 n8n - External Secrets Disclosure via Workflow Node Expressions — n8nCWE-639--2026-07-15
CVE-2026-56352 n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter — n8nCWE-22 6.4 Medium2026-07-15
CVE-2026-56353 n8n - Authentication Bypass in Chat Trigger Node — n8nCWE-287 4.8 Medium2026-07-15
CVE-2026-56349 n8n - Guardrail Node Bypass via Crafted Input — n8nCWE-20--2026-07-15
CVE-2026-58661 n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint — n8nCWE-770--2026-07-10
CVE-2026-56354 n8n - Cross-Site Scripting and Open Redirect in Form Node — n8nCWE-79 4.1 Medium2026-07-10
CVE-2026-59257 n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation — n8nCWE-89--2026-07-08
CVE-2026-59253 n8n - Improper Authorization in Workflow Assignment to Folders — n8nCWE-639--2026-07-08
CVE-2026-56778 n8n - Authorization Bypass in Public API Execution Retry Endpoint — n8nCWE-863 6.4 Medium2026-07-08
CVE-2026-56776 n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint — n8nCWE-863 7.4 High2026-07-08
CVE-2026-56775 n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints — n8nCWE-863 5.4 Medium2026-07-08
CVE-2026-56359 n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL — n8nCWE-79 5.4 Medium2026-07-08
CVE-2026-56360 n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger — n8nCWE-290 4.0 Medium2026-07-08
CVE-2025-71380 n8n - Arbitrary Command Execution via Execute Command Node — n8nCWE-284 8.8 High2026-07-04
CVE-2026-56777 n8n - AST Validator Bypass in Python Code Node — n8nCWE-184 5.0 Medium2026-06-30
CVE-2026-56350 n8n - SSO Enforcement Bypass via API — n8nCWE-285 6.3 Medium2026-06-30
CVE-2026-56356 n8n - Stored Cross-Site Scripting in Chat Trigger Node Custom CSS Field — n8nCWE-79 5.4 Medium2026-06-30
CVE-2026-56358 n8n - Stored Cross-Site Scripting in Form Trigger Node — n8nCWE-79 5.4 Medium2026-06-24
CVE-2026-56351 n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes — n8nCWE-89 8.2 High2026-06-24
CVE-2026-56357 n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook Trigger — n8nCWE-290 4.0 Medium2026-06-22
CVE-2026-56348 n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dynamic Node Parameters Endpoint — n8nCWE-918 9.1 Critical2026-06-22

This page lists every published CVE security advisory associated with n8n. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.