N8n
This hub aggregates every CVE we track for N8n, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
123
CVEs tracked
25
Critical
48
High
1
In CISA KEV
Severity distribution
MEDIUM50HIGH48CRITICAL25
Monthly trend
0
0
0
0
0
0
0
1
0
1
2
2
2
1
0
5
6
18
11
0
12
28
31
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting N8n.
- CVE-2026-65599n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header6.5
- CVE-2026-65598n8n before 1.123.64 Remote Code Execution via Git Clone7.5
- CVE-2026-65597n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe5.4
- CVE-2026-65596n8n before 1.123.64 Credential Exfiltration via GraphQL Node8.1
- CVE-2026-65595n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange8.8
- CVE-2026-65594n8n before 2.30.1 Missing OAuth Authorization Check6.5
- CVE-2026-65593n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters5.4
- CVE-2026-65592n8n before 1.123.64 Stored DOM XSS via cachedResultUrl5.4
- CVE-2026-65590n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows9.8
- CVE-2026-65591n8n before 1.123.64 Sanitizer Bypass Remote Code Execution8.8
- CVE-2026-65589n8n before 1.123.64 Credential Exposure via LLM Node Execution Data6.5
- CVE-2026-65016n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance-Role8.8
- CVE-2026-65015n8n before 2.30.1 Privilege Escalation via run_node_tool8.8
- CVE-2026-65014n8n before 2.28.0 Authentication Bypass via test-webhook5.3
- CVE-2026-59259n8n - Permission Bypass via Expression Parser Mismatch in External Secrets6.5
Product normalization is registry-driven with AI assist and human review. How it works