Known vulnerabilities in n8n n8n 1.121.0

Vendor: n8n
Website: https://n8n.io/
Total Security Bulletins: 7

Security bulletins (7)

Secuity bulletin Severity Status Published
SB2026020966: Improper authenitcation in n8n Stripe Trigger node Medium
Patched
09.02.2026
SB2026020960: Remote code execution in n8n expression evaluation Medium
Patched
09.02.2026
SB2026020669: Stored cross-site scripting in n8n Low
Patched
06.02.2026
SB2026011349: IP whitelist bypass in n8n Medium
Patched
13.01.2026
SB2026010769: Arbitrary file upload in n8n Medium
Patched Public exploit
07.01.2026
SB2026010711: Security restrictions bypass in n8n Medium
Patched
07.01.2026
SB2025122338: Privilege escalation in n8n Medium
Patched Exploited
23.12.2025