Known vulnerabilities in n8n n8n

Vendor: n8n
Website: https://n8n.io/
Total Security Bulletins: 30

Security bulletins (30)

Secuity bulletin Severity Status Published
SB2026031350: Authenticated OS command injection in n8n Medium
Patched
13.03.2026
SB2026031349: Multiple vulnerabilities in n8n High
Patched
13.03.2026
SB2026031345: SQL injection in n8n workflows implementation Low
Patched
13.03.2026
SB2026020966: Improper authenitcation in n8n Stripe Trigger node Medium
Patched
09.02.2026
SB2026020965: Information disclosure in n8n Medium
Patched Public exploit
09.02.2026
SB2026020962: Stored XSS in n8n Respond to Webhook node Low
Patched
09.02.2026
SB2026020961: Arbitrary file upload in n8n merge node Medium
Patched
09.02.2026
SB2026020960: Remote code execution in n8n expression evaluation Medium
Patched
09.02.2026
SB2026020957: Remote code execution via Add Config operation in n8n Medium
Patched
09.02.2026
SB2026020956: Remote code execution via Git Node pre-commit hook in n8n Medium
Patched
09.02.2026
SB2026020955: Stored XSS in n8n LangChain Chat Trigger Node Low
Patched
09.02.2026
SB2026020954: Symbolic link following in n8n Low
Patched
09.02.2026
SB2026020953: Stored XSS in n8n form trigger Low
Patched
09.02.2026
SB2026020952: Improper authorization in n8n workflow execution Low
Patched
09.02.2026
SB2026020951: Authenticated DoS in n8n Low
Patched
09.02.2026
SB2026020950: Open redirect in n8n login flow Low
Patched
09.02.2026
SB2026020949: Stored XSS in n8n Low
Patched
09.02.2026
SB2026020673: Path traversal in n8n High
Patched
06.02.2026
SB2026020672: Stored cross-site scripting in n8n Low
Patched
06.02.2026
SB2026020671: OS Command Injection in n8n Medium
Patched
06.02.2026


Showing elements 1 - 20 out of 30