n8n
73 known vulnerabilities affecting n8n products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-27577 | Medium | 10.0% | 9.9 | n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.… | |
| CVE-2026-77068 | Medium | 0.6% | 8.8 | n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulne… | |
| CVE-2026-65591 | Medium | 0.5% | 8.8 | n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator… | |
| CVE-2026-65595 | Medium | 0.5% | 8.8 | n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued th… | |
| CVE-2026-85168 | Medium | 0.5% | 8.8 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution… | |
| CVE-2026-72765 | Medium | 0.4% | 9.9 | n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in ex… | |
| CVE-2026-86076 | Medium | 0.4% | 8.8 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-77084 | Medium | 0.4% | 8.8 | n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution v… | |
| CVE-2026-72767 | Medium | 0.4% | 8.8 | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remot… | |
| CVE-2026-85169 | Medium | 0.4% | 8.8 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox e… | |
| CVE-2026-72773 | Medium | 0.4% | 7.7 | n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in … | |
| CVE-2026-72764 | Medium | 0.4% | 8.8 | n8n's JavaScript task runner shared a single module cache across all users' Code… | |
| CVE-2026-86083 | Medium | 0.4% | 8.8 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-86075 | Medium | 0.3% | 7.5 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, … | |
| CVE-2026-77071 | Medium | 0.3% | 9.8 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vu… | |
| CVE-2026-65015 | Medium | 0.3% | 8.8 | n8n versions before 2.30.1 contain a privilege escalation vulnerability in the A… | |
| CVE-2026-65590 | Medium | 0.3% | 9.8 | n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restri… | |
| CVE-2026-85165 | Medium | 0.3% | 9.9 | n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability wh… | |
| CVE-2026-77077 | Medium | 0.3% | 7.6 | n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runne… | |
| CVE-2026-77080 | Medium | 0.3% | 8.8 | n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbi… | |
| CVE-2026-65016 | Medium | 0.3% | 8.8 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation … | |
| CVE-2026-77070 | Medium | 0.3% | 9.8 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability… | |
| CVE-2026-86074 | Medium | 0.3% | 7.1 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, … | |
| CVE-2026-72766 | Medium | 0.3% | 7.5 | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type … | |
| CVE-2026-72750 | Medium | 0.3% | 8.8 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability i… | |
| CVE-2026-72775 | Medium | 0.3% | 8.8 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability i… | |
| CVE-2026-77075 | Medium | 0.3% | 7.3 | n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expr… | |
| CVE-2026-72769 | Medium | 0.3% | 8.1 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerabi… | |
| CVE-2026-77079 | Medium | 0.2% | 8.8 | n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom proj… | |
| CVE-2026-65598 | Medium | 0.2% | 7.5 | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the … | |
| CVE-2026-72772 | Medium | 0.2% | 8.8 | n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the … | |
| CVE-2026-72768 | Medium | 0.2% | 8.3 | n8n versions before 2.32.1 contain a server-side request forgery protection bypa… | |
| CVE-2026-86073 | Medium | 0.2% | 7.6 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, … | |
| CVE-2026-77081 | Medium | 0.2% | 7.1 | n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed… | |
| CVE-2026-65596 | Medium | 0.2% | 8.1 | n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Reque… | |
| CVE-2026-72762 | Medium | 0.2% | 8.8 | n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write… | |
| CVE-2026-77072 | Medium | 0.2% | 7.6 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting v… | |
| CVE-2026-72770 | Low | 0.5% | 6.5 | n8n versions before 1.123.67 contain a path traversal vulnerability in the Git n… | |
| CVE-2026-65589 | Low | 0.4% | 6.5 | n8n versions before 1.123.64 fail to properly mask custom HTTP header credential… | |
| CVE-2026-65014 | Low | 0.3% | 5.3 | n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE … | |
| CVE-2026-86079 | Low | 0.3% | 6.5 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-86078 | Low | 0.3% | 6.5 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, … | |
| CVE-2026-85171 | Low | 0.3% | 6.5 | n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerabi… | |
| CVE-2026-72749 | Low | 0.3% | 6.5 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerabi… | |
| CVE-2026-72774 | Low | 0.3% | 6.5 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypa… | |
| CVE-2026-77076 | Low | 0.3% | 6.5 | n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosu… | |
| CVE-2026-86995 | Low | 0.3% | 4.3 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… | |
| CVE-2026-77082 | Low | 0.3% | 4.3 | n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regu… | |
| CVE-2026-65594 | Low | 0.3% | 6.5 | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth… | |
| CVE-2026-86993 | Low | 0.3% | 4.9 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, a… |
Page 1 of 2
Next →