n8n
79 known vulnerabilities · 0 critical · 2 high
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
n8n: Webhook Forgery on Github Webhook Trigger
n8n has SQL Injection in Data Table Node via orderByColumn Expression
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no
n8n has Arbitrary Command Execution via File Write and Git Operations
n8n Has External Secrets Authorization Bypass in Credential Saving
n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
n8n: Authenticated XSS and Open Redirect via Form Node
n8n has XSS in its Credential Management Flow
n8n has XSS in Chat Trigger Node through Custom CSS
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
n8n has an Authentication Bypass in its Chat Trigger Node
n8n: Webhook Node IP Whitelist Bypass via Partial String Matching
n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
Self-hosted n8n has Legacy Code node that enables arbitrary file read/write
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
n8n Has Stored Cross-site Scripting via Markdown Rendering in Workflow UI
n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
n8n has Webhook Forgery on Zendesk Trigger Node
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
n8n has a Stored XSS Vulnerability in its Form Trigger
n8n has a Guardrail Node Bypass
n8n Vulnerable to Remote Code Execution via Expression Injection
n8n-mcp has authenticated SSRF via instance-URL header in multi-tenant HTTP mode
n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport
Malicious code in @hapheus/n8n-nodes-pgp (npm)
Malicious code in n8n-nodes-viral-app (npm)
Malicious code in n8n-nodes-ggdv-hdfvcnnje-uyrokvbkl (npm)
Malicious code in n8n-nodes-vbmkajdsa-uehfitvv-ueqjhhhksdlkkmz (npm)
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
Malicious code in n8n-nodes-zl-vietts (npm)
Malicious code in n8n-nodes-text-helpers (npm)
Malicious code in @diendh/n8n-nodes-tiktok-v2 (npm)
Malicious code in n8n-nodes-zalo-fevox (npm)
Malicious code in n8n-zalo-fevox (npm)
Malicious code in n8n-nodes-phoai-ultimate-tools (npm)
Malicious code in n8n-performance-metrics (npm)
Malicious code in n8n-nodes-vercel-ai-sdk (npm)
Malicious code in n8n-nodes-comfyui-illu (npm)
Malicious code in n8n-nodes-xml-utils (npm)
Malicious code in n8n-nodes-csv-parse (npm)
Malicious code in n8n-nodes-data-transform (npm)
Malicious code in n8n-nodes-format-utils (npm)
Malicious code in n8n-nodes-hfgjf-irtuinvcm-lasdqewriit (npm)
Malicious code in n8n-nodes-tmdb (npm)
Malicious code in n8n-nodes-gasdhgfuy-rejerw-ytjsadx (npm)
Malicious code in n8n-nodes-gg-udhasudsh-hgjkhg-official (npm)
Malicious code in n8n-nodes-xkwqpzrt-jmflhvbn-dsyocgxwmkelpt (npm)
Malicious code in n8n-nodes-performance-metrics (npm)
Malicious code in n8n-nodes-zalo-user (npm)
Malicious code in n8n-nodes-json-helper (npm)
Malicious code in n8n-nodes-text-utils (npm)