Known vulnerabilities in n8n n8n 1.10.0

Vendor: n8n
Website: https://n8n.io/
Total Security Bulletins: 18

Security bulletins (18)

Secuity bulletin Severity Status Published
SB2026020966: Improper authenitcation in n8n Stripe Trigger node Medium
Patched
09.02.2026
SB2026020962: Stored XSS in n8n Respond to Webhook node Low
Patched
09.02.2026
SB2026020961: Arbitrary file upload in n8n merge node Medium
Patched
09.02.2026
SB2026020960: Remote code execution in n8n expression evaluation Medium
Patched
09.02.2026
SB2026020957: Remote code execution via Add Config operation in n8n Medium
Patched
09.02.2026
SB2026020956: Remote code execution via Git Node pre-commit hook in n8n Medium
Patched
09.02.2026
SB2026020954: Symbolic link following in n8n Low
Patched
09.02.2026
SB2026020952: Improper authorization in n8n workflow execution Low
Patched
09.02.2026
SB2026020951: Authenticated DoS in n8n Low
Patched
09.02.2026
SB2026020950: Open redirect in n8n login flow Low
Patched
09.02.2026
SB2026020949: Stored XSS in n8n Low
Patched
09.02.2026
SB2026020669: Stored cross-site scripting in n8n Low
Patched
06.02.2026
SB20260205105: Information disclosure in n8n Medium
Patched
05.02.2026
SB20260205103: Information disclosure in n8n Medium
Patched
05.02.2026
SB20260205102: OS Command Injection in n8n Low
Patched
05.02.2026
SB2026010769: Arbitrary file upload in n8n Medium
Patched Public exploit
07.01.2026
SB2026010711: Security restrictions bypass in n8n Medium
Patched
07.01.2026
SB2025122338: Privilege escalation in n8n Medium
Patched Exploited
23.12.2025