Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across Projects
n8n security advisories
All 161 advisories n8n has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 16185 carry a CVE
- critical
- 22
- high
- 68
- medium
- 69
- low
- 2
- Fix in the archive
- 63of 161 matched to a release
- Oldest
- 28 Apr 20251.3 years ago
98 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productLegacy Request Helper SSRF Check Validates uri While Axios Dispatches url
Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error Data
Gmail and Brevo nodes accept non-string content, enabling local file read and SSRF
Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCE
Git Node Remote Code Execution via Incomplete Repository-Local Configuration Neutralization
Query Injection in Elasticsearch and Google Cloud Firestore Nodes via Unescaped Expression Interpolation
Shared-Workflow Editor Can Exfiltrate Credentials via Workflow Tool Node Inline Sub-Workflow
Expression Sandbox SpreadElement Bypass Enables Persistent Cross-Evaluation Native Object Mutation
SSRF Protection Bypass via SearXNG Tool Allows Member Users to Read Internal Service Responses
Code execution in the n8n Git node via unchecked repository-local git configuration
Sandbox Escape in JavaScript Code Node via Prototype Pollution
ReDoS in Filter and Switch Node Regex Matching Allows Worker Denial of Service
GraphQL Node Allowed-Domains Bypass Permits Restricted Credential Exfiltration
Snowflake Node Arbitrary File Read and Write via Client-Side Commands
Custom-role deletion's reassignment path bypasses project-scoped authorization
JavaScript Task Runner VM Sandbox Escape via EventEmitter Prototype Pollution Leads to Remote Code Execution
GraphQL Node Raw Error Re-throw Leaks Decrypted Credential Headers into Persisted Execution Data
Resource Locator Link Preview Expression Injection Allows Cross-User Script Execution
Edit Image Node Injection Enables Blind SSRF
MCP create_workflow_from_code Accepts Cross-Project Credentials When Auth Type Is an Expression
Form Node Completion Page Sandbox CSP Bypass Leads to Stored XSS
Supabase Node PostgREST Filter Injection in Row Get Many, Delete, and Update Operations
MongoDB Node NoSQL Injection in Find, Delete, and Aggregate Operations via Unescaped Expression Interpolation
SSRF Protection Bypass via OAuth2 Credential Token Exchange Reflects Internal Response Body
RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading
PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
Account Takeover via Unverified Email Claim in Token Exchange Embed Login
Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Code Execution
SSRF Protection Bypass via MCP Client Node
Authenticated code execution in the n8n Git node
Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
Expression sandbox escape via arrow-function bodies enabling command execution
Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
Edit Image Node Format Injection Allows Arbitrary File Write
Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
Google Service Account Private Key Exposed in JWT Header
Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Stored DOM XSS via Resource Locator `cachedResultUrl`
Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
computer-use Shell Sandbox Not Enforced on Linux and Windows
Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
AI Agents Project Viewer Privilege Escalation via run_node_tool
Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
Shared Credential Header Leak via HTTP Request Pagination Expression
External Secrets Permission Bypass via Expression Parser Mismatch
Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
"Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
External Secrets Accessible via Workflow Expressions Outside Credentials
Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
Public API Execution Retry Authorization Bypass
Python Code Node AST Validator Bypass
Stored XSS in Chat Trigger Node
Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
Microsoft SQL Node Prototype Pollution
Merge Node SQL Mode Prototype Pollution
Prototype Pollution enables confused-deputy execution via public webhooks
Same-Origin XSS in Respond to Webhook Node
Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
NoSQL Injection in MongoDB Node Find And Replace Operation
SQL Injection in Postgres v1/TimesclaeDB Nodes
SecurityScorecard Node Leaks API Token to User-Controlled Host
n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
Credential Exfiltration via Permission Bypass
Wrong OAuth Scope on Evaluation Test Runs Endpoints
Denial of Service via ZIP decompression in webhook workflow
Git Node Clone and Push Operations Bypass File Sandbox
Python sandbox escape
Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
Credential exfiltration via Allowed HTTP Request Domains Bypass
Arbitrary File Read via Git Node
HTTP Request Node Pagination Prototype Pollution to RCE
Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
Source Control Pull SQL Injection
XML Node Prototype Pollution Patch Bypass
Open Redirect in MCP OAuth Consent Flow
Python Task Runner Sandbox Escape
SQL Injection in Oracle Database Node via Limit Field
Public API Variables IDOR Allows Cross-Project Secret Disclosure
SQL Injection in Snowflake and MySQL Nodes
Unauthenticated Denial of Service via MCP Client Registration
SQL Injection in SeaTable Node
Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
Hijacking of Unauthenticated Chat Execution
XSS via MCP OAuth client
Prototype Pollution in XML Webhook Body Parser Leads to RCE
XML Node Prototype Pollution to RCE
LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
MITM Vulnerability for Source Control with SSH
Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK
XSS and Open Redirect in Form Node
XSS in Credential Management Flow
External Secrets Authorization Bypass in Credential Saving
In-Process Memory Disclosure in Task Runner
LDAP Filter Injection in LDAP Node
SQL Injection in Data Table Node via orderByColumn Expression
XSS in Chat Trigger Node via Custom CSS
Stored XSS in Form Trigger
Prototype Pollution in GSuiteAdmin node parameters leads to RCE
XSS via Binary Data Inline HTML Rendering
Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
RCE via SQL Mode of Merge Node
Python Code Node Sandbox Escape
Arbitrary Command Execution via File Write and Git Operations
Webhook Forgery on Github Webhook Trigger
Webhook Forgery on Zendesk Trigger
n8n Guardrail Node Bypass
Sandbox Escape in JavaScript Task Runner
SSO Enforcement Bypass
Unauthenticated Expression Evaluation via Form Node
Authentication Bypass in Chat Trigger Node
Stored XSS via Various Nodes
Expression Sandbox Escape Leading to RCE
Remote Code Execution via Merge Node
SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
Python sandbox escape
Domain allowlist bypass enables credential exfiltration
Improper CSP Enforcement in Webhook Responses May Allow Stored XSS
Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
OS Command Injection in Git Node
Command Injection in Community Package Installation
Expression Escape Vulnerability Leading to RCE
Stored Cross-Site Scripting via Markdown Rendering in Workflow UI
Arbitrary File Write on Remote Systems via SSH Node
Arbitrary File Write leading to RCE in n8n Merge Node
IP Whitelist Bypass via Partial String Matching
Unauthenticated File Access via Improper Webhook Request Handling
Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
RCE via Arbitrary File Write
Possible Stored XSS in “Respond to Webhook” Node May Execute Outside Sandbox
Arbitrary Command Execution in Pyodide based Python Code Node
Legacy Code node enables file read/write in self-hosted n8n
n8n Remote Code Execution via Expression Injection
Remote Code Execution via Git Node Custom Pre-Commit Hook
Remote Code Execution via Git Node Pre-Commit Hook
Execute Command Node in n8n Allows Authenticated Users to Run Arbitrary Commands on Host
Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter
Symlink traversal vulnerability in "Read/Write File" node allows access to restricted files
Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source
Denial of Service via Malformed Binary Data Requests
Improper Authorization in Workflow Execution Stop Endpoint Allows Terminating Other Users’ Workflows
Open Redirect Vulnerability in n8n Login Flow
Stored XSS through Attachments View Endpoint