n8n Vulnerable to Remote Code Execution via Expression Injection
Affected range
SEMVER: introduced 0.211.0; fixed 1.120.4SEMVER: introduced 1.121.0; fixed 1.121.1
Fixed versions: 1.120.4, 1.121.1
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
Affected range
SEMVER: introduced 0; fixed 1.123.55SEMVER: introduced 2.26.0; fixed 2.26.2SEMVER: introduced 2.0.0-rc.0; fixed 2.25.7
Fixed versions: 1.123.55, 2.26.2, 2.25.7
n8n Has an XML Node Prototype Pollution Patch Bypass
Affected range
SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.22.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7
Fixed versions: 1.123.43, 2.22.1, 2.20.7
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
Affected range
SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.22.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7
Fixed versions: 1.123.43, 2.22.1, 2.20.7
n8n Has a Source Control Pull SQL Injection
Affected range
SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.21.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7
Fixed versions: 1.123.43, 2.21.1, 2.20.7
n8n Has an Arbitrary File Read via Git Node
Affected range
SEMVER: introduced 0; fixed 1.123.43SEMVER: introduced 2.21.0; fixed 2.22.1SEMVER: introduced 2.0.0-rc.0; fixed 2.20.7
Fixed versions: 1.123.43, 2.22.1, 2.20.7
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
Affected range
SEMVER: introduced 0; fixed 2.20.0
Fixed versions: 2.20.0
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
Affected range
SEMVER: introduced 2.26.0; fixed 2.26.2SEMVER: introduced 0; fixed 2.25.7
Fixed versions: 2.26.2, 2.25.7
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
Affected range
SEMVER: introduced 2.26.0; fixed 2.26.2SEMVER: introduced 0; fixed 2.25.7
Fixed versions: 2.26.2, 2.25.7
n8n: Credential Exfiltration via Permission Bypass
Affected range
SEMVER: introduced 0; fixed 1.123.55SEMVER: introduced 2.26.0; fixed 2.26.2SEMVER: introduced 2.0.0-rc.0; fixed 2.25.7
Fixed versions: 1.123.55, 2.26.2, 2.25.7
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
Affected range
SEMVER: introduced 0; fixed 1.123.32SEMVER: introduced 2.18.0; fixed 2.18.1SEMVER: introduced 2.17.0; fixed 2.17.4
Fixed versions: 1.123.32, 2.18.1, 2.17.4
n8n has XML Node Prototype Pollution that to RCE
Affected range
SEMVER: introduced 2.18.0; fixed 2.18.1SEMVER: introduced 2.17.0; fixed 2.17.4SEMVER: introduced 0; fixed 1.123.32
Fixed versions: 2.18.1, 2.17.4, 1.123.32
n8n has SQL Injection in Oracle Database Node via Limit Field
Affected range
SEMVER: introduced 0; fixed 1.123.32SEMVER: introduced 2.18.0; fixed 2.18.1SEMVER: introduced 2.0.0; fixed 2.17.4
Fixed versions: 1.123.32, 2.18.1, 2.17.4
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
Affected range
SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3SEMVER: introduced 0; fixed 1.123.27
Fixed versions: 2.14.1, 2.13.3, 1.123.27
n8n has SQL Injection in Data Table Node via orderByColumn Expression
Affected range
SEMVER: introduced 0; fixed 1.123.26SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3
Fixed versions: 1.123.26, 2.14.1, 2.13.3
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
Affected range
SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3SEMVER: introduced 0; fixed 1.123.27
Fixed versions: 2.14.1, 2.13.3, 1.123.27
n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
Affected range
SEMVER: introduced 0; fixed 1.123.27SEMVER: introduced 2.14.0; fixed 2.14.1SEMVER: introduced 2.0.0-rc.0; fixed 2.13.3
Fixed versions: 1.123.27, 2.14.1, 2.13.3
n8n has a Python sandbox escape
Affected range
SEMVER: introduced 0; fixed 2.4.8
Fixed versions: 2.4.8
n8n: Expression Sandbox Escape Leads to RCE
Affected range
SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1
Fixed versions: 1.123.22, 2.9.3, 2.10.1
n8n has Arbitrary File Read via Python Code Node Sandbox Escape
Affected range
SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1
Fixed versions: 1.123.22, 2.9.3, 2.10.1
n8n has Arbitrary Command Execution via File Write and Git Operations
Affected range
SEMVER: introduced 0; fixed 1.123.8SEMVER: introduced 2.0.0; fixed 2.2.0
Fixed versions: 1.123.8, 2.2.0
n8n has a Sandbox Escape in its JavaScript Task Runner
Affected range
SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1
Fixed versions: 1.123.22, 2.9.3, 2.10.1
n8n has Potential Remote Code Execution via Merge Node
Affected range
SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1
Fixed versions: 1.123.22, 2.9.3, 2.10.1
n8n has Unauthenticated Expression Evaluation via Form Node
Affected range
SEMVER: introduced 0; fixed 1.123.22SEMVER: introduced 2.0.0; fixed 2.9.3SEMVER: introduced 2.10.0; fixed 2.10.1
Fixed versions: 1.123.22, 2.9.3, 2.10.1
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
Affected range
SEMVER: introduced 2.0.0; fixed 2.5.0SEMVER: introduced 0; fixed 1.123.18
Fixed versions: 2.5.0, 1.123.18
Show 75 more advisories
GHSA-62r4-hw23-cc8v n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node GHSA-v4pr-fm98-w9pg n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling GHSA-wpqc-h9wp-chmq n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook GHSA-6xcw-7xm6-48c6 n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution GHSA-34ff-336r-5q23 n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node GHSA-j535-v25q-vx3q n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path GHSA-hw8v-xxg5-vvvx n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution GHSA-hh89-3r9w-qj3j n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint GHSA-g3r5-9h93-4j2c n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution GHSA-64xh-79j6-r5v8 n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes GHSA-cj9h-qx8g-pq2g n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON GHSA-gv7g-jm28-cr3m n8n: Expression sandbox escape via arrow-function bodies enabling command execution GHSA-xwx6-jjhv-84p8 n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service GHSA-gf29-4f56-r2jf n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction GHSA-2x35-3fw4-9jr4 n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion GHSA-6qc9-mqvw-jg7x n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType` GHSA-8342-988q-86cr n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login GHSA-pm35-fqvh-cq5g n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution GHSA-35q8-9mj6-wjmf n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner GHSA-777w-rpr6-c52h n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs GHSA-mq3m-f8x3-579w n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution GHSA-75qm-gp28-rcq9 n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration GHSA-h44j-f5r5-ph73 n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector GHSA-jvc7-762p-3743 n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes GHSA-6h4j-wcr9-2vg7 n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints GHSA-h86q-fx34-gfjr n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints GHSA-365g-vjw2-grx8 n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host GHSA-r4v6-9fqc-w5jr n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay GHSA-49m9-pgww-9vq6 n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration GHSA-756q-gq9h-fp22 n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure GHSA-c545-x2rh-82fc n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover GHSA-49mx-fj45-q3p6 n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner GHSA-j4p8-h8mh-rh8q Self-hosted n8n has Legacy Code node that enables arbitrary file read/write GHSA-58jc-rcg5-95f3 n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox GHSA-hfmv-hhh3-43f2 Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source GHSA-cqr2-h44g-v75v n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints GHSA-cw9w-vv67-hf73 n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution GHSA-q5wm-mgqx-fv2f n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content GHSA-qgpw-8g46-w95v n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read GHSA-679f-58pq-4v2c n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service