Skip to content
RequestGuard Vulnerabilities
Pricing

n8n

n8n Workflow Automation Tool

npm latest 2.39.8 SEE LICENSE IN LICENSE.md

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

2.39.8

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

156 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

156
GHSA-v98v-ff95-f3cp critical CISA KEV

n8n Vulnerable to Remote Code Execution via Expression Injection

Affected range

SEMVER: introduced 0.211.0; fixed 1.120.4SEMVER: introduced 1.121.0; fixed 1.121.1

Fixed versions: 1.120.4, 1.121.1

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

Affected range

SEMVER: introduced 0; fixed 1.123.55SEMVER: introduced 2.26.0; fixed 2.26.2SEMVER: introduced 2.0.0-rc.0; fixed 2.25.7

Fixed versions: 1.123.55, 2.26.2, 2.25.7

n8n Has an XML Node Prototype Pollution Patch Bypass

Affected range

SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.22.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7

Fixed versions: 1.123.43, 2.22.1, 2.20.7

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

Affected range

SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.22.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7

Fixed versions: 1.123.43, 2.22.1, 2.20.7

n8n Has a Source Control Pull SQL Injection

Affected range

SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.21.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7

Fixed versions: 1.123.43, 2.21.1, 2.20.7

n8n Has an Arbitrary File Read via Git Node

Affected range

SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.22.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7

Fixed versions: 1.123.43, 2.22.1, 2.20.7

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

Affected range

SEMVER: introduced 2.26.0; fixed 2.26.2SEMVER: introduced 0; fixed 2.25.7

Fixed versions: 2.26.2, 2.25.7

n8n: Credential Exfiltration via Permission Bypass

Affected range

SEMVER: introduced 0; fixed 1.123.55SEMVER: introduced 2.26.0; fixed 2.26.2SEMVER: introduced 2.0.0-rc.0; fixed 2.25.7

Fixed versions: 1.123.55, 2.26.2, 2.25.7

n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE

Affected range

SEMVER: introduced 0; fixed 1.123.32SEMVER: introduced 2.18.0; fixed 2.18.1SEMVER: introduced 2.17.0; fixed 2.17.4

Fixed versions: 1.123.32, 2.18.1, 2.17.4

n8n has XML Node Prototype Pollution that to RCE

Affected range

SEMVER: introduced 2.18.0; fixed 2.18.1SEMVER: introduced 2.17.0; fixed 2.17.4SEMVER: introduced 0; fixed 1.123.32

Fixed versions: 2.18.1, 2.17.4, 1.123.32

n8n has SQL Injection in Oracle Database Node via Limit Field

Affected range

SEMVER: introduced 0; fixed 1.123.32SEMVER: introduced 2.18.0; fixed 2.18.1SEMVER: introduced 2.0.0; fixed 2.17.4

Fixed versions: 1.123.32, 2.18.1, 2.17.4

n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode

Affected range

SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3SEMVER: introduced 0; fixed 1.123.27

Fixed versions: 2.14.1, 2.13.3, 1.123.27

n8n has SQL Injection in Data Table Node via orderByColumn Expression

Affected range

SEMVER: introduced 0; fixed 1.123.26SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3

Fixed versions: 1.123.26, 2.14.1, 2.13.3

n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE

Affected range

SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3SEMVER: introduced 0; fixed 1.123.27

Fixed versions: 2.14.1, 2.13.3, 1.123.27

n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition

Affected range

SEMVER: introduced 0; fixed 1.123.27SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3

Fixed versions: 1.123.27, 2.14.1, 2.13.3

n8n: Expression Sandbox Escape Leads to RCE

Affected range

SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1

Fixed versions: 1.123.22, 2.9.3, 2.10.1

n8n has Arbitrary File Read via Python Code Node Sandbox Escape

Affected range

SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1

Fixed versions: 1.123.22, 2.9.3, 2.10.1

n8n has Arbitrary Command Execution via File Write and Git Operations

Affected range

SEMVER: introduced 0; fixed 1.123.8SEMVER: introduced 2.0.0; fixed 2.2.0

Fixed versions: 1.123.8, 2.2.0

n8n has a Sandbox Escape in its JavaScript Task Runner

Affected range

SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1

Fixed versions: 1.123.22, 2.9.3, 2.10.1

n8n has Potential Remote Code Execution via Merge Node

Affected range

SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1

Fixed versions: 1.123.22, 2.9.3, 2.10.1

n8n has Unauthenticated Expression Evaluation via Form Node

Affected range

SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1

Fixed versions: 1.123.22, 2.9.3, 2.10.1

n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users

Affected range

SEMVER: introduced 2.0.0; fixed 2.5.0SEMVER: introduced 0; fixed 1.123.18

Fixed versions: 2.5.0, 1.123.18

Show 75 more advisories
GHSA-9g95-qf3f-ggrw n8n has OS Command Injection in Git Node
GHSA-hv53-3329-vmrm n8n Merge Node has Arbitrary File Write leading to RCE
GHSA-6cqr-8cfr-67f8 n8n Has Expression Escape Vulnerability Leading to RCE
GHSA-7c4h-vh2m-743m n8n Vulnerable to Command Injection in Community Package Installation
GHSA-v364-rw7m-3263 n8n Vulnerable to RCE via Arbitrary File Write
GHSA-62r4-hw23-cc8v n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
GHSA-5xrp-6693-jjx9 n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
GHSA-v4pr-fm98-w9pg n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
GHSA-wpqc-h9wp-chmq n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
GHSA-6xcw-7xm6-48c6 n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
GHSA-34ff-336r-5q23 n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
GHSA-j535-v25q-vx3q n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
GHSA-hw8v-xxg5-vvvx n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
GHSA-hh89-3r9w-qj3j n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
GHSA-g3r5-9h93-4j2c n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
GHSA-xmc9-4f2h-jf9c n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GHSA-rcv6-pvrj-4xcg n8n: Authenticated code execution in the n8n Git node
GHSA-64xh-79j6-r5v8 n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-cj9h-qx8g-pq2g n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
GHSA-gv7g-jm28-cr3m n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GHSA-xwx6-jjhv-84p8 n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GHSA-gf29-4f56-r2jf n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-2x35-3fw4-9jr4 n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-6qc9-mqvw-jg7x n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-8342-988q-86cr n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-pm35-fqvh-cq5g n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-35q8-9mj6-wjmf n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-777w-rpr6-c52h n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
GHSA-mq3m-f8x3-579w n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
GHSA-75qm-gp28-rcq9 n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
GHSA-q3j5-8vrg-4p9q n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
GHSA-h44j-f5r5-ph73 n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
GHSA-p3rg-hrf9-w9gj n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GHSA-9wcp-9r3j-383q n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-x5vx-c2c8-m3w9 n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-f3f2-mcxc-pwjx n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
GHSA-42h7-m79w-wvg5 n8n: Stored XSS in Chat Trigger Node
GHSA-5xp3-2w67-427v n8n: Git Node Clone and Push Operations Bypass File Sandbox
GHSA-jvc7-762p-3743 n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
GHSA-rm2v-h48j-895m n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
GHSA-v733-mwr6-fgcm n8n: Same-Origin XSS in Respond to Webhook Node
GHSA-6h4j-wcr9-2vg7 n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
GHSA-x6p3-m6h9-fx7r n8n: Microsoft SQL Node Prototype Pollution
GHSA-9pq8-m8gp-4p53 n8n: Python sandbox escape
GHSA-jpq7-226w-6cxx n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
GHSA-h86q-fx34-gfjr n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
GHSA-hv7x-3x78-gx53 n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
GHSA-365g-vjw2-grx8 n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
GHSA-r4v6-9fqc-w5jr n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
GHSA-44v6-jhgm-p3m4 n8n has a Python Task Runner Sandbox Escape Vulnerability
GHSA-49m9-pgww-9vq6 n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
GHSA-hp3c-vfpm-q4f7 n8n has SQL Injection in Snowflake and MySQL Nodes
GHSA-756q-gq9h-fp22 n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
GHSA-537j-gqpc-p7fq n8n Vulnerable to XSS via MCP OAuth client
GHSA-xvh5-5qg4-x9qp n8n has In-Process Memory Disclosure in its Task Runner
GHSA-qfc3-hm4j-7q77 n8n Vulnerable to XSS via Binary Data Inline HTML Rendering
GHSA-fxcw-h3qj-8m8p n8n Has External Secrets Authorization Bypass in Credential Saving
GHSA-c545-x2rh-82fc n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
GHSA-2p9h-rqjw-gm92 n8n Vulnerable to Stored XSS via Various Nodes
GHSA-qpq4-pw7f-pp8w n8n Has Stored Cross-site Scripting via Markdown Rendering in Workflow UI
GHSA-m82q-59gv-mcr9 n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node
GHSA-49mx-fj45-q3p6 n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
GHSA-825q-w924-xhgx n8n's Improper CSP Enforcement in Webhook Responses May Allow Stored XSS
GHSA-j4p8-h8mh-rh8q Self-hosted n8n has Legacy Code node that enables arbitrary file read/write
GHSA-58jc-rcg5-95f3 n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox
GHSA-xgp7-7qjq-vg47 n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
GHSA-hfmv-hhh3-43f2 Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source
GHSA-r9xw-p7wj-w792 n8n Information Disclosure vulnerability
GHSA-97cp-mr4m-9mcf n8n Privilege Escalation vulnerability
GHSA-cqr2-h44g-v75v n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
GHSA-cw9w-vv67-hf73 n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
GHSA-q5wm-mgqx-fv2f n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
GHSA-qgpw-8g46-w95v n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
GHSA-pf83-w3f9-8m37 n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
GHSA-679f-58pq-4v2c n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service