VYPR

N8n

by N8n Io

npm: n8n

Source repositories

CVEs (183)

  • CVE-2026-65015HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing…

  • CVE-2026-59259MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check and the runtime expression engine. An authenticated user with credential create or update permissions…

  • CVE-2026-59254MedJul 15, 2026
    risk 0.00cvss —epss 0.00

    n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenticated project editors can read plaintext external secret values by referencing them in node…

  • CVE-2026-56353MedJul 15, 2026
    risk 0.00cvss 4.8epss 0.00

    n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint…

  • CVE-2026-56352MedJul 15, 2026
    risk 0.00cvss 6.4epss 0.00

    n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files from disk without the file-access checks enforced by other file-reading nodes. Although hidden from the UI since v1.2, it remains…

  • CVE-2026-56349MedJul 15, 2026
    risk 0.00cvss —epss 0.00

    n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity.

  • CVE-2026-58661MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota check does not account for files already written to the shared temporary directory, allowing an authenticated…

  • CVE-2026-56354MedJul 10, 2026
    risk 0.00cvss 4.1epss 0.00

    n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow…

  • CVE-2026-59209MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the $request object inside an HTTP Request node's pagination…

  • CVE-2026-59208MedJul 9, 2026
    risk 0.00cvss 6.8epss 0.03

    n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim,…

  • CVE-2026-59207MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains restriction configured on credentials when an MCP tool was pointed at an arbitrary URL, allowing a member-level user with…

  • CVE-2026-59206HigJul 9, 2026
    risk 0.00cvss 7.1epss 0.01

    n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via the workflow API, allowing…

  • CVE-2026-59257HigJul 8, 2026
    risk 0.00cvss 8.8epss 0.01

    n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ ... }} expression values directly into the raw SQL string without…

  • CVE-2026-59253MedJul 8, 2026
    risk 0.00cvss 5.0epss 0.00

    n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folders in other projects. Attackers can bypass project and folder authorization boundaries by supplying crafted request payloads during workflow creation,…

  • CVE-2026-56778MedJul 8, 2026
    risk 0.00cvss 6.4epss 0.00

    n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only access to a shared workflow can use the…

  • CVE-2026-56776HigJul 8, 2026
    risk 0.00cvss 7.4epss 0.00

    n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new endpoint, which authorizes access using the workflow:read scope instead of workflow:execute. An authenticated user with read-only access to a workflow can…

  • CVE-2026-56775MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead of the action-appropriate workflow:execute scope. On instances using…

  • CVE-2026-56360MedJul 8, 2026
    risk 0.00cvss 4.0epss 0.00

    n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.

  • CVE-2026-56359MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into…

  • CVE-2025-71380HigJul 4, 2026
    risk 0.00cvss 8.8epss 0.01

    The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service…

Page 9 of 10