Known Vulnerabilities for products from N8n
Listed below are 20 of the newest known vulnerabilities associated with the vendor "N8n".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65599 json | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google S... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65598 json | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authen... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65597 json | n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65596 json | n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credent... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65595 json | n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65594 json | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was intr... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65593 json | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-para... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65592 json | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator comp... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65591 json | n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated ... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65590 json | n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/compu... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65589 json | n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing pla... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65016 json | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-65015 json | n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution too... | Not Provided | 2026-07-22 | 2026-07-28 |
| CVE-2026-65014 json | n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint be... | Not Provided | 2026-07-22 | 2026-07-27 |
| CVE-2026-59259 json | n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caus... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-59257 json | n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59253 json | n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to folder... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-59209 json | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-... | Not Provided | 2026-07-09 | 2026-07-13 |
| CVE-2026-59208 json | n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured... | Not Provided | 2026-07-09 | 2026-07-14 |
| CVE-2026-59207 json | n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the All... | Not Provided | 2026-07-09 | 2026-07-09 |