VYPR

N8n

by N8n Io

npm: n8n

Source repositories

CVEs (137)

  • CVE-2026-27496MedMar 25, 2026
    risk 0.35cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory buffers. Uninitialized buffers may contain…

  • CVE-2026-25631MedFeb 6, 2026
    risk 0.35cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node's credential domain validation allowed an authenticated attacker to send requests with credentials to unintended domains, potentially leading to credential…

  • CVE-2026-21894MedJan 8, 2026
    risk 0.35cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe webhook events. The Stripe Trigger creates…

  • CVE-2025-57749MedAug 20, 2025
    risk 0.35cvss 6.5epss 0.00

    n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly account for symbolic links (symlinks).…

  • CVE-2026-72750MedAug 11, 2026
    risk 0.34cvss epss 0.00

    n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data…

  • CVE-2026-72773MedAug 11, 2026
    risk 0.32cvss epss 0.00

    n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the…

  • CVE-2026-54302MedJun 23, 2026
    risk 0.28cvss 5.4epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webhookId. When a logged-in user visited the…

  • CVE-2026-27578MedFeb 25, 2026
    risk 0.28cvss 5.4epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could inject arbitrary scripts into pages rendered by the n8n application using different techniques on various…

  • CVE-2026-25054MedFeb 4, 2026
    risk 0.28cvss 5.4epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface, including workflow sticky notes and other areas that support markdown content.…

  • CVE-2026-25051MedFeb 4, 2026
    risk 0.28cvss 5.4epss 0.00

    n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP endpoints. Under certain conditions, the Content Security Policy (CSP) sandbox…

  • CVE-2025-58177MedSep 15, 2025
    risk 0.28cvss 5.4epss 0.00

    n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in…

  • CVE-2026-65014MedJul 22, 2026
    risk 0.27cvss 5.3epss 0.00

    n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test…

  • CVE-2026-33722MedMar 25, 2026
    risk 0.27cvss 5.3epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plaintext value when saving the credential.…

  • CVE-2025-68949MedJan 13, 2026
    risk 0.27cvss 5.3epss 0.00

    n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely…

  • CVE-2025-46343MedApr 29, 2025
    risk 0.26cvss 5.0epss 0.00

    n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary files, which are accessible to authenticated users. However, there is no…

  • CVE-2025-49595MedJul 3, 2025
    risk 0.25cvss 4.9epss 0.00

    n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or filesystem-v2://). This allows authenticated attackers to cause service unavailability…

  • CVE-2026-33751MedMar 25, 2026
    risk 0.24cvss 4.8epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacharacters to pass through unescaped when user-controlled input was interpolated into LDAP search filters. In…

  • CVE-2025-49592MedJun 26, 2025
    risk 0.23cvss 4.6epss 0.00

    n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to untrusted, attacker-controlled domains after logging in, by crafting malicious URLs with a misleading redirect query…

  • CVE-2025-52554MedJul 3, 2025
    risk 0.21cvss 4.3epss 0.00

    n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /rest/executions/:id/stop endpoint of n8n. An authenticated user can stop workflow executions that they do not own or that have not been shared with them, leading…

  • CVE-2026-33720MedMar 25, 2026
    risk 0.20cvss 4.2epss 0.00

    n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` environment variable is set to `true`, the OAuth callback handler skips ownership verification of the OAuth state parameter. This allows an attacker to trick a…

Page 5 of 7