VYPR

N8n

by N8n Io

npm: n8n

Source repositories

CVEs (183)

  • CVE-2026-25052CriFeb 4, 2026
    risk 0.57cvss 9.9epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host system. This can be exploited…

  • CVE-2026-25049CriFeb 4, 2026
    risk 0.57cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running…

  • CVE-2026-54307CriJun 23, 2026
    risk 0.55cvss 9.6epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced…

  • CVE-2026-49444HigJun 23, 2026
    risk 0.55cvss 8.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner…

  • CVE-2026-54312HigJun 23, 2026
    risk 0.55cvss 8.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as the table parameter. This pollutes…

  • CVE-2026-72768HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing…

  • CVE-2026-72769HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute…

  • CVE-2026-45732HigJun 23, 2026
    risk 0.53cvss 8.1epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-only access to a shared…

  • CVE-2026-33749CriMar 25, 2026
    risk 0.52cvss 9.0epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows could craft a workflow that produces an HTML binary data object without a filename. The `/rest/binary-data`…

  • CVE-2026-27493CriFeb 25, 2026
    risk 0.52cvss 9.0epss 0.01

    n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and evaluate arbitrary n8n expressions by…

  • CVE-2026-86083HigSep 8, 2026
    risk 0.50cvss 8.8epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating timezone data. An expression…

  • CVE-2026-86076HigSep 8, 2026
    risk 0.50cvss 8.8epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __sanitize could rebind the sanitizer and…

  • CVE-2026-85169HigSep 3, 2026
    risk 0.50cvss 8.8epss 0.00

    n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; against a primitive input value it returned a…

  • CVE-2026-85168HigSep 3, 2026
    risk 0.50cvss 8.8epss 0.00

    n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter and merge-driver key families.…

  • CVE-2026-72773HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.00

    n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the…

  • CVE-2026-49465HigJun 23, 2026
    risk 0.50cvss 7.7epss 0.01

    n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's Clone operation, or as the target…

  • CVE-2026-54313HigJun 23, 2026
    risk 0.50cvss 7.7epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before being passed to MongoDB as a query…

  • CVE-2026-54311HigJun 23, 2026
    risk 0.50cvss 7.7epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox context was cached and reused across all…

  • CVE-2026-33713HigMar 25, 2026
    risk 0.50cvss 8.8epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection vulnerability in the Data Table Get node. On default SQLite DB, single statements…

  • CVE-2026-33696HigMar 25, 2026
    risk 0.50cvss 8.8epss 0.01

    n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. By supplying a crafted…

Page 3 of 10