n8n
128 known vulnerabilities · 0 critical · 2 high
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
n8n: Webhook Forgery on Github Webhook Trigger
n8n has SQL Injection in Data Table Node via orderByColumn Expression
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no
n8n has Arbitrary Command Execution via File Write and Git Operations
n8n Has External Secrets Authorization Bypass in Credential Saving
n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
n8n: Authenticated XSS and Open Redirect via Form Node
n8n has XSS in its Credential Management Flow
n8n has XSS in Chat Trigger Node through Custom CSS
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
n8n: Webhook Node IP Whitelist Bypass via Partial String Matching
n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
n8n has an Authentication Bypass in its Chat Trigger Node
Self-hosted n8n has Legacy Code node that enables arbitrary file read/write
n8n Has Stored Cross-site Scripting via Markdown Rendering in Workflow UI
n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK
n8n Has an Arbitrary File Read via Git Node
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
n8n Has a Source Control Pull SQL Injection
n8n has a Python Task Runner Sandbox Escape Vulnerability
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
n8n Vulnerable to XSS via MCP OAuth client
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox
n8n has Webhook Forgery on Zendesk Trigger Node
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
n8n Has an XML Node Prototype Pollution Patch Bypass
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
n8n has SQL Injection in SeaTable Node
n8n has XML Node Prototype Pollution that to RCE
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
n8n has a Stored XSS Vulnerability in its Form Trigger
n8n has a Guardrail Node Bypass
n8n has SQL Injection in Oracle Database Node via Limit Field
n8n has SQL Injection in Snowflake and MySQL Nodes
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
n8n: Stored XSS in Chat Trigger Node
n8n has Open Redirect in MCP OAuth Consent Flow
n8n: Git Node Clone and Push Operations Bypass File Sandbox
n8n: Merge Node SQL Mode Prototype Pollution
n8n: Python sandbox escape
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
n8n: Public API Execution Retry Authorization Bypass
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
n8n: Denial of Service via ZIP decompression in webhook workflow
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
n8n: Python Code Node AST Validator Bypass
n8n: Credential Exfiltration via Permission Bypass
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
n8n: Same-Origin XSS in Respond to Webhook Node
n8n Vulnerable to Remote Code Execution via Expression Injection
n8n: Microsoft SQL Node Prototype Pollution
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport
n8n-mcp has authenticated SSRF via instance-URL header in multi-tenant HTTP mode
n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure
n8n-mcp webhook and API client paths has an authenticated SSRF
Malicious code in n8n-nodes-ggdv-hdfvcnnje-uyrokvbkl (npm)
Malicious code in n8n-nodes-vbmkajdsa-uehfitvv-ueqjhhhksdlkkmz (npm)
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
Malicious code in n8n-nodes-zl-vietts (npm)
Malicious code in n8n-nodes-text-helpers (npm)
Malicious code in @contaazul/n8n-nodes-contaazul (npm)
Malicious code in @diendh/n8n-nodes-tiktok-v2 (npm)
Malicious code in n8n-nodes-zalo-fevox (npm)
Malicious code in n8n-zalo-fevox (npm)
Malicious code in n8n-nodes-phoai-ultimate-tools (npm)
Malicious code in n8n-performance-metrics (npm)
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
Malicious code in n8n-nodes-vercel-ai-sdk (npm)
Malicious code in n8n-nodes-pentest-rce (npm)
Malicious code in n8n-nodes-csv-parse (npm)
Malicious code in n8n-nodes-data-transform (npm)
Malicious code in n8n-nodes-format-utils (npm)
Malicious code in n8n-nodes-xml-utils (npm)
Malicious code in n8n-nodes-tmdb (npm)
Malicious code in n8n-nodes-whatsapp-business-api-by-automations-builder (npm)
Malicious code in n8n-nodes-comfyui-illu (npm)
Malicious code in n8n-nodes-zalo-user (npm)
Malicious code in n8n-nodes-hfgjf-irtuinvcm-lasdqewriit (npm)
Malicious code in n8n-nodes-gasdhgfuy-rejerw-ytjsadx (npm)
Malicious code in n8n-nodes-gg-udhasudsh-hgjkhg-official (npm)
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
Malicious code in n8n-nodes-xkwqpzrt-jmflhvbn-dsyocgxwmkelpt (npm)
Malicious code in n8n-nodes-performance-metrics (npm)
Malicious code in n8n-nodes-json-helper (npm)
Malicious code in n8n-nodes-text-utils (npm)
n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders
Malicious code in n8n-nodes-security-test-poc (npm)
Malicious code in @hapheus/n8n-nodes-pgp (npm)
Malicious code in n8n-nodes-viral-app (npm)