SB2026093097 - Multiple vulnerabilities in n8n
Published: September 30, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) SQL injection (CVE-ID: N/A)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SQL against the connected database with the stored credential's privileges.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in version 1 of the Microsoft SQL node when resolving expressions in the Query field. A remote attacker can supply untrusted input that is interpolated into the SQL query to execute arbitrary SQL against the connected database with the stored credential's privileges.
Exploitation requires a workflow that binds untrusted input to the Query field.
2) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access private agent conversations and approve pending tool calls on behalf of other project members.
The vulnerability exists due to improper authorization in the agent tool-call resume endpoint and related conversation read endpoints when handling requests containing run identifiers. A remote user can supply another user's run identifier and use the project-scoped read endpoints to access private agent conversations and approve pending tool calls on behalf of other project members.
The targeted conversation must contain a pending tool approval.
3) Prototype pollution (CVE-ID: N/A)
CWE-ID: CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to take over the instance owner's account.
The vulnerability exists due to improper control of object prototype attributes in the MCP workflow-validation interpreter when evaluating caller-supplied code. A remote user can replace a built-in method with one that returns a truthy value to bypass a server-side permission check and take over the instance owner's account.
Accounts protected by MFA are not affected.
4) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the OAuth authorization endpoint when resolving OAuth clients from URL paths. A remote attacker can send authorization requests with identifiers that differ only by query strings to cause a denial of service.
The persisted records are marked as first-party and outlive the resources they name.
5) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform actions using credential values they are not authorized to use.
The vulnerability exists due to improper authorization validation in the shared-workflow credential check when saving a shared workflow containing nested inline workflows. A remote user can save a workflow with embedded nodes that reference inaccessible credentials to perform actions using credential values they are not authorized to use.
Inline workflows can be nested.
6) OS Command Injection (CVE-ID: N/A)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of repository configuration in the Git node Log operation when executing git commands. A remote user can point the node at a repository whose local configuration they control to execute arbitrary code.
The issue occurs under default settings.
7) Improper Verification of Cryptographic Signature (CVE-ID: N/A)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to approve waiting executions without authorization.
The vulnerability exists due to improper verification of a cryptographic signature in the waiting-webhook endpoint when processing a Send-and-Wait node reference in an alternate form. A remote attacker can send a request containing an alternate Send-and-Wait node reference and a resume token to approve a waiting execution.
Exploitation requires possession of the execution's resume token.
8) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute script in visitors' browsers.
The vulnerability exists due to improper neutralization of input during web page generation in the Chat Trigger hosted-chat page customCss parameter when rendering author-supplied custom CSS. A remote user can supply crafted custom CSS to execute script in visitors' browsers.
User interaction is required to visit the hosted chat page. Only chat pages published without n8n user authentication are affected.
9) Prototype pollution (CVE-ID: N/A)
CWE-ID: CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper control of object prototype attributes in the AI workflow builder's connect-nodes operation when merging workflow connections containing API-submitted node names. A remote user can submit a workflow with a reserved JavaScript property name to cause a denial of service.
The API accepts node names that the editor refuses, and the resulting global object prototype change persists until the instance restarts.
10) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the n8n origin.
The vulnerability exists due to improper neutralization of active content in the binary-data file-preview modal when previewing a crafted uploaded binary-data item. A remote user can upload a crafted item for a victim to preview to execute arbitrary script in the n8n origin.
User interaction is required to preview the crafted item.
Remediation
Install update from vendor's website.
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-5qpp-pqww-h7fp
- https://github.com/n8n-io/n8n/security/advisories/GHSA-p3pg-xw4f-m72c
- https://github.com/n8n-io/n8n/security/advisories/GHSA-5jr4-xmvf-frmj
- https://github.com/n8n-io/n8n/security/advisories/GHSA-3qcw-p65v-c7vq
- https://github.com/n8n-io/n8n/security/advisories/GHSA-r6g9-5cpp-ppwr
- https://github.com/n8n-io/n8n/security/advisories/GHSA-x8wx-g24x-3549
- https://github.com/n8n-io/n8n/security/advisories/GHSA-728h-pmr2-7cgh
- https://github.com/n8n-io/n8n/security/advisories/GHSA-x5cw-hm7v-q7mj
- https://github.com/n8n-io/n8n/security/advisories/GHSA-3p2g-2wpm-8h3g
- https://github.com/n8n-io/n8n/security/advisories/GHSA-29xw-66fq-4xc3