N8n
This hub aggregates every CVE we track for N8n, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
109
CVEs tracked
24
Critical
42
High
1
In CISA KEV
Severity distribution
MEDIUM43HIGH42CRITICAL24
Monthly trend
0
0
0
0
0
0
0
0
1
0
1
2
2
2
1
0
5
6
18
11
0
12
28
17
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting N8n.
- CVE-2026-59259n8n - Permission Bypass via Expression Parser Mismatch in External Secrets6.5
- CVE-2026-56353n8n - Authentication Bypass in Chat Trigger Node4.8
- CVE-2026-56352n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter6.4
- CVE-2026-58661n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint4.3
- CVE-2026-56354n8n - Cross-Site Scripting and Open Redirect in Form Node4.1
- CVE-2026-59209n8n: Shared Credential Header Leak via HTTP Request Pagination Expression6.5
- CVE-2026-59206n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration7.1
- CVE-2026-59208n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution6.8
- CVE-2026-59207n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector6.5
- CVE-2026-59257n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation8.8
- CVE-2026-59253n8n - Improper Authorization in Workflow Assignment to Folders5.0
- CVE-2026-56778n8n - Authorization Bypass in Public API Execution Retry Endpoint6.4
- CVE-2026-56775n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints5.4
- CVE-2026-56776n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint7.4
- CVE-2026-56360n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger4.0
Product normalization is registry-driven with AI assist and human review. How it works