Catalog / n8n

n8n security advisories

All 161 advisories n8n has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
16185 carry a CVE
critical
22
high
68
medium
69
low
2
Fix in the archive
63of 161 matched to a release
Oldest
28 Apr 20251.3 years ago

98 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
GHSA-jqwr-vx3p-r266medium

PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

CVE-2026-72774high

Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`

GHSA-6qc9-mqvw-jg7xFixed in 2.31.5
CVE-2026-71539high

Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

GHSA-g3r5-9h93-4j2cFixed in 2.29.8
CVE-2026-59206high

Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration

GHSA-75qm-gp28-rcq9Fixed in 2.27.4
GHSA-2xgm-wc4g-5jvgmedium

Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

Fixed in 2.28.0, not held here
GHSA-w867-jm58-p9pvmedium

Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

Fixed in 2.28.0, not held here
GHSA-h3jj-5f3v-3685medium

Public API Execution Retry Authorization Bypass

Fixed in 2.26.2, not held here
GHSA-jwm3-qcfw-c5ppmedium

Python Code Node AST Validator Bypass

Fixed in 2.26.2, not held here
CVE-2026-54302high

Stored XSS in Chat Trigger Node

GHSA-42h7-m79w-wvg5Fixed in 1.123.55, not held here
CVE-2026-54303medium

Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints

GHSA-h86q-fx34-gfjrFixed in 2.24.0, not held here
CVE-2026-54312high

Microsoft SQL Node Prototype Pollution

GHSA-x6p3-m6h9-fx7rFixed in 2.24.0, not held here
CVE-2026-54311medium

Merge Node SQL Mode Prototype Pollution

GHSA-9c38-2mcm-q7f7Fixed in 2.26.2, not held here
CVE-2026-54306medium

Prototype Pollution enables confused-deputy execution via public webhooks

GHSA-2vff-hj5x-8gq7Fixed in 2.26.2, not held here
CVE-2026-54301high

Same-Origin XSS in Respond to Webhook Node

GHSA-v733-mwr6-fgcmFixed in 1.123.55, not held here
CVE-2026-54308medium

Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

GHSA-jvc7-762p-3743Fixed in 2.26.2, not held here
GHSA-hv7x-3x78-gx53medium

Wrong OAuth Scope On Evaluations Test Run Creation Endpoint

Fixed in 1.123.55, not held here
CVE-2026-54313medium

NoSQL Injection in MongoDB Node Find And Replace Operation

GHSA-jpq7-226w-6cxxFixed in 2.24.0, not held here
CVE-2026-54310medium

SQL Injection in Postgres v1/TimesclaeDB Nodes

GHSA-c37g-w77q-m4vpFixed in 2.26.2, not held here
CVE-2026-54304high

SecurityScorecard Node Leaks API Token to User-Controlled Host

GHSA-rm2v-h48j-895mFixed in 1.123.55, not held here
CVE-2026-54309high

n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

GHSA-qrx8-25qr-5r7vFixed in 2.26.2, not held here
CVE-2026-54305high

Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

GHSA-2j5h-858j-5mpfFixed in 1.123.55, not held here
CVE-2026-54307high

Credential Exfiltration via Permission Bypass

GHSA-pmqw-72cg-wx85Fixed in 1.123.55, not held here
GHSA-664h-gpgq-h6xxmedium

Wrong OAuth Scope on Evaluation Test Runs Endpoints

Fixed in 1.123.55, not held here
CVE-2026-54314medium

Denial of Service via ZIP decompression in webhook workflow

GHSA-jqpw-qww5-cj4cFixed in 2.24.0, not held here
CVE-2026-49465medium

Git Node Clone and Push Operations Bypass File Sandbox

GHSA-5xp3-2w67-427vFixed in 1.123.48, not held here
CVE-2026-49444high

Python sandbox escape

GHSA-9pq8-m8gp-4p53Fixed in 1.123.48, not held here
GHSA-2vx9-7wpg-88jqmedium

Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

Fixed in 2.20.0, not held here
GHSA-3875-8gcx-7v46medium

Credential exfiltration via Allowed HTTP Request Domains Bypass

Fixed in 2.20.0, not held here
CVE-2026-44790critical

Arbitrary File Read via Git Node

GHSA-57g9-58c2-xjg3Fixed in 1.123.43, not held here
CVE-2026-44789critical

HTTP Request Node Pagination Prototype Pollution to RCE

GHSA-c8xv-5998-g76hFixed in 1.123.43, not held here
CVE-2026-45732high

Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints

GHSA-6h4j-wcr9-2vg7Fixed in 1.123.43, not held here
CVE-2026-44792high

Source Control Pull SQL Injection

GHSA-mhrx-qhrj-673wFixed in 1.123.43, not held here
CVE-2026-44791critical

XML Node Prototype Pollution Patch Bypass

GHSA-wrwr-h859-xh2rFixed in 1.123.43, not held here
CVE-2026-42230medium

Open Redirect in MCP OAuth Consent Flow

GHSA-f6x8-65q6-j9m9Fixed in 1.123.32, not held here
CVE-2026-42234high

Python Task Runner Sandbox Escape

GHSA-44v6-jhgm-p3m4Fixed in 1.123.32, not held here
CVE-2026-42233medium

SQL Injection in Oracle Database Node via Limit Field

GHSA-r6jc-mpqw-m755Fixed in 1.123.32, not held here
CVE-2026-42227medium

Public API Variables IDOR Allows Cross-Project Secret Disclosure

GHSA-756q-gq9h-fp22Fixed in 1.123.32, not held here
CVE-2026-42237medium

SQL Injection in Snowflake and MySQL Nodes

GHSA-hp3c-vfpm-q4f7Fixed in 1.123.32, not held here
CVE-2026-42236high

Unauthenticated Denial of Service via MCP Client Registration

GHSA-49m9-pgww-9vq6Fixed in 1.123.32, not held here
CVE-2026-42229medium

SQL Injection in SeaTable Node

GHSA-mp4j-h6gh-f6mpFixed in 1.123.32, not held here
CVE-2026-42226high

Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay

GHSA-r4v6-9fqc-w5jrFixed in 2.18.0, not held here
CVE-2026-42228medium

Hijacking of Unauthenticated Chat Execution

GHSA-f77h-j2v7-g6mwFixed in 1.123.32, not held here
CVE-2026-42235high

XSS via MCP OAuth client

GHSA-537j-gqpc-p7fqFixed in 1.123.32, not held here
CVE-2026-42231critical

Prototype Pollution in XML Webhook Body Parser Leads to RCE

GHSA-q5f4-99jv-pgg5Fixed in 1.123.32, not held here
CVE-2026-42232critical

XML Node Prototype Pollution to RCE

GHSA-hqr4-h3xv-9m3rFixed in 2.18.1, not held here
CVE-2026-33665high

LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover

GHSA-c545-x2rh-82fcFixed in 2.4.0, not held here
CVE-2026-33724medium

MITM Vulnerability for Source Control with SSH

GHSA-43v7-fp2v-68f6Fixed in 2.5.0, not held here
CVE-2026-33720medium

Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK

GHSA-vpgc-2f6g-7w7xFixed in 2.8.0, not held here
GHSA-w673-8fjw-457cmedium

XSS and Open Redirect in Form Node

Fixed in 2.12.0, not held here
GHSA-364x-8g5j-x2prmedium

XSS in Credential Management Flow

Fixed in 2.8.0, not held here
CVE-2026-33722high

External Secrets Authorization Bypass in Credential Saving

GHSA-fxcw-h3qj-8m8pFixed in 1.123.23, not held here
CVE-2026-27496high

In-Process Memory Disclosure in Task Runner

GHSA-xvh5-5qg4-x9qpFixed in 1.123.22, not held here
CVE-2026-33751medium

LDAP Filter Injection in LDAP Node

GHSA-w83q-mcmx-mh42Fixed in 1.123.27, not held here
CVE-2026-33713high

SQL Injection in Data Table Node via orderByColumn Expression

GHSA-98c2-4cr3-4jc3Fixed in 1.123.26, not held here
GHSA-3c7f-5hgj-h279medium

XSS in Chat Trigger Node via Custom CSS

Fixed in 1.123.27, not held here
CVE-2026-33696critical

Prototype Pollution in GSuiteAdmin node parameters leads to RCE

GHSA-mxrg-77hm-89hvFixed in 2.14.1, not held here
CVE-2026-33749medium

XSS via Binary Data Inline HTML Rendering

GHSA-qfc3-hm4j-7q77Fixed in 1.123.27, not held here
CVE-2026-33663high

Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition

GHSA-m63j-689w-3j35Fixed in 1.123.27, not held here
CVE-2026-33660critical

RCE via SQL Mode of Merge Node

GHSA-58qr-rcgv-642vFixed in 2.14.1, not held here
CVE-2026-27494critical

Python Code Node Sandbox Escape

GHSA-mmgg-m5j7-f83hFixed in 2.10.1, not held here
CVE-2026-27498critical

Arbitrary Command Execution via File Write and Git Operations

GHSA-x2mw-7j39-93xqFixed in 2.2.0, not held here
GHSA-mqpr-49jj-32rcmedium

Webhook Forgery on Github Webhook Trigger

Fixed in 2.5.0, not held here
GHSA-38c7-23hj-2wgqmedium

Webhook Forgery on Zendesk Trigger

Fixed in 2.6.2, not held here
CVE-2026-27495critical

Sandbox Escape in JavaScript Task Runner

GHSA-jjpj-p2wh-qf23Fixed in 2.10.1, not held here
CVE-2026-27493high

Unauthenticated Expression Evaluation via Form Node

GHSA-75g8-rv7v-32f7Fixed in 2.10.1, not held here
GHSA-jh8h-6c9q-7gmwmedium

Authentication Bypass in Chat Trigger Node

Fixed in 2.10.1, not held here
CVE-2026-27578high

Stored XSS via Various Nodes

GHSA-2p9h-rqjw-gm92Fixed in 2.10.1, not held here
CVE-2026-27577critical

Expression Sandbox Escape Leading to RCE

GHSA-vpcf-gvg4-6qwrFixed in 2.10.1, not held here
CVE-2026-27497critical

Remote Code Execution via Merge Node

GHSA-wxx7-mcgf-j869Fixed in 2.10.1, not held here
GHSA-f3f2-mcxc-pwjxmedium

SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes

Fixed in 2.4.0, not held here
CVE-2025-61917high

Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

GHSA-49mx-fj45-q3p6Fixed in 1.114.3, not held here
CVE-2026-25115critical

Python sandbox escape

GHSA-8398-gmmx-564hFixed in 2.4.8, not held here
CVE-2026-25631medium

Domain allowlist bypass enables credential exfiltration

GHSA-2xcx-75h9-vr9hFixed in 1.121.0, not held here
CVE-2026-25051high

Improper CSP Enforcement in Webhook Responses May Allow Stored XSS

GHSA-825q-w924-xhgxFixed in 1.123.2, not held here
CVE-2026-25052critical

Improper File Access Controls Allow Arbitrary File Read by Authenticated Users

GHSA-gfvg-qv54-r4pcFixed in 2.5.0, not held here
CVE-2026-25053critical

OS Command Injection in Git Node

GHSA-9g95-qf3f-ggrwFixed in 2.5.0, not held here
CVE-2026-21893low

Command Injection in Community Package Installation

GHSA-7c4h-vh2m-743mFixed in 1.120.3, not held here
CVE-2026-25049critical

Expression Escape Vulnerability Leading to RCE

GHSA-6cqr-8cfr-67f8Fixed in 1.123.17, not held here
CVE-2026-25054high

Stored Cross-Site Scripting via Markdown Rendering in Workflow UI

GHSA-qpq4-pw7f-pp8wFixed in 2.2.1, not held here
CVE-2026-25055high

Arbitrary File Write on Remote Systems via SSH Node

GHSA-m82q-59gv-mcr9Fixed in 2.4.0, not held here
CVE-2026-25056critical

Arbitrary File Write leading to RCE in n8n Merge Node

GHSA-hv53-3329-vmrmFixed in 2.4.0, not held here
CVE-2025-68949medium

IP Whitelist Bypass via Partial String Matching

GHSA-w96v-gf22-crwpFixed in 2.2.0, not held here
CVE-2026-21858critical

Unauthenticated File Access via Improper Webhook Request Handling

GHSA-v4pr-fm98-w9pgFixed in 1.121.0, not held here
CVE-2026-21894medium

Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

GHSA-jf52-3f2h-h9j5Fixed in 2.2.2, not held here
CVE-2026-21877critical

RCE via Arbitrary File Write

GHSA-v364-rw7m-3263Fixed in 1.121.3, not held here
CVE-2025-61914high

Possible Stored XSS in “Respond to Webhook” Node May Execute Outside Sandbox

GHSA-58jc-rcg5-95f3Fixed in 1.114.0, not held here
CVE-2025-68668critical

Arbitrary Command Execution in Pyodide based Python Code Node

GHSA-62r4-hw23-cc8vFixed in 2.0.0, not held here
CVE-2025-68697high

Legacy Code node enables file read/write in self-hosted n8n

GHSA-j4p8-h8mh-rh8qFixed in 2.0.0, not held here
CVE-2025-68613critical

n8n Remote Code Execution via Expression Injection

GHSA-v98v-ff95-f3cpFixed in 1.122.0, not held here
CVE-2025-65964critical

Remote Code Execution via Git Node Custom Pre-Commit Hook

GHSA-wpqc-h9wp-chmqFixed in 1.119.2, not held here
CVE-2025-62726high

Remote Code Execution via Git Node Pre-Commit Hook

GHSA-xgp7-7qjq-vg47Fixed in 1.113.0, not held here
GHSA-365g-vjw2-grx8high

Execute Command Node in n8n Allows Authenticated Users to Run Arbitrary Commands on Host

CVE-2025-58177medium

Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter

GHSA-mvh4-2cm2-6hpgFixed in 1.107.0, not held here
CVE-2025-57749medium

Symlink traversal vulnerability in "Read/Write File" node allows access to restricted files

GHSA-ggjm-f3g4-rwmmFixed in 1.106.0, not held here
CVE-2025-52478high

Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source

GHSA-hfmv-hhh3-43f2Fixed in 1.98.2, not held here
CVE-2025-49595medium

Denial of Service via Malformed Binary Data Requests

GHSA-pr9r-gxgp-9rm8Fixed in 1.99.0, not held here
CVE-2025-52554medium

Improper Authorization in Workflow Execution Stop Endpoint Allows Terminating Other Users’ Workflows

GHSA-gq57-v332-7666Fixed in 1.99.1, not held here
CVE-2025-49592medium

Open Redirect Vulnerability in n8n Login Flow

GHSA-5vj6-wjr7-5v9fFixed in 1.98.0, not held here
CVE-2025-46343medium

Stored XSS through Attachments View Endpoint

GHSA-c8hm-hr8h-5xjwFixed in 1.90.0, not held here