N8n
This hub aggregates every CVE we track for N8n, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
66
CVEs tracked
17
Critical
27
High
1
In CISA KEV
Severity distribution
HIGH27MEDIUM22CRITICAL17
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
1
2
2
2
1
0
5
6
18
11
0
12
2
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting N8n.
- CVE-2026-56357n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook Trigger4.0
- CVE-2026-56348n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dynamic Node Parameters Endpoint9.1
- CVE-2026-42237n8n: SQL Injection in Snowflake and MySQL Nodes8.8
- CVE-2026-42236n8n: Unauthenticated Denial of Service via MCP Client Registration7.5
- CVE-2026-42235n8n: XSS via MCP OAuth client9.6
- CVE-2026-42234n8n: Python Task Runner Sandbox Escape8.8
- CVE-2026-42233n8n: SQL Injection in Oracle Database Node via Limit Field9.8
- CVE-2026-42232n8n: XML Node Prototype Pollution to RCE8.8
- CVE-2026-42231n8n: Prototype Pollution in XML Webhook Body Parser Leads to RCE8.8
- CVE-2026-42230n8n: Open Redirect in MCP OAuth Consent Flow6.1
- CVE-2026-42229n8n: SQL Injection in SeaTable Node8.8
- CVE-2026-42228n8n: Hijacking of Unauthenticated Chat Execution6.5
- CVE-2026-42227n8n: Public API Variables IDOR Allows Cross-Project Secret Disclosure6.5
- CVE-2026-42226n8n: Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay7.5
- CVE-2026-33751n8n Vulnerable to LDAP Filter Injection in LDAP Node4.8
Product normalization is registry-driven with AI assist and human review. How it works