N8n
This hub aggregates every CVE we track for N8n, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
150
CVEs tracked
28
Critical
61
High
1
In CISA KEV
Severity distribution
HIGH61MEDIUM61CRITICAL28
Monthly trend
0
0
0
0
0
0
1
0
1
2
2
2
1
0
5
6
18
11
0
12
28
31
27
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting N8n.
- CVE-2026-77085n8n before 2.34.1 SSRF Protection Bypass via SearXNG Tool6.5
- CVE-2026-77084n8n before 1.123.69 Remote Code Execution via Git Node Configuration Values8.8
- CVE-2026-77083n8n before 1.123.69 Code Node Sandbox Escape via Function.prototype Pollution5.9
- CVE-2026-77082n8n before 1.123.69 ReDoS via Filter and Switch Node4.3
- CVE-2026-77081n8n before 1.123.69 Allowed-Domains Bypass via GraphQL Node7.1
- CVE-2026-77080n8n before 1.123.69 Arbitrary File Read and Write via Snowflake8.8
- CVE-2026-77079n8n before 2.34.1 Authorization Bypass via Custom Role Deletion8.8
- CVE-2026-77077n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution7.6
- CVE-2026-77076n8n before 1.123.69 Credential Leak via GraphQL Node Error6.5
- CVE-2026-77075n8n before 1.123.69 Expression Injection via Resource Locator7.3
- CVE-2026-77074n8n before 1.123.69 SSRF via Edit Image Node6.5
- CVE-2026-77073n8n before 2.34.1 Cross-Project Credential Access via MCP4.3
- CVE-2026-77072n8n before 1.123.69 Stored XSS via Form Completion Page7.6
- CVE-2026-77070n8n before 1.123.69 NoSQL Injection via MongoDB Node9.8
- CVE-2026-77071n8n before 1.123.69 PostgREST Filter Injection via Supabase9.8
Product normalization is registry-driven with AI assist and human review. How it works