n8n Vulnerabilities

npm AI Agents

AI Threat Alert tracks 116 known vulnerabilities in n8n, 22 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
69
Risk Score
116
Total CVEs
22
Critical
npm
Ecosystem
Jun 30, 2026
Last CVE
53%
Patch Rate
7d
Avg Time to Patch
194,300 stars 58,888 forks 1,482 issues Last push Jun 28, 2026
View on GitHub
OpenSSF Scorecard 6.6/10

Known Vulnerabilities (116 total, page 1 of 5)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-56777 n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the validator and access the task executor module namespace. The issue only affects self-hosted instances where the Python Task Runner is enabled; where N8N_BLOCK_RUNNER_ENV_ACCESS is configured to allow it, this can disclose environment variables accessible 5.0 Jun 30, 2026 MEDIUM CVE-2026-56356 n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and 2.14.1). An authenticated user with permission to create or modify workflows can inject JavaScript that bypasses sanitization, resulting in stored XSS against any user who visits the public chat page. 5.4 Jun 30, 2026 MEDIUM CVE-2026-56350 n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication. 6.3 Jun 30, 2026 MEDIUM CVE-2026-56358 n8n: stored XSS in Form Trigger enables form hijacking 5.4 Jun 24, 2026 HIGH CVE-2026-56351 n8n: SQL injection in DB nodes via identifier values 8.2 Jun 24, 2026 MEDIUM CVE-2026-56357 n8n: webhook forgery enables unauthorized workflow execution 4.0 Jun 22, 2026 CRITICAL CVE-2026-56348 n8n: SSRF bypasses allowlist, exfiltrates credentials 9.1 Jun 22, 2026 HIGH CVE-2026-54353 Budibase: SSRF via DNS rebinding in automation steps 8.5 Jun 22, 2026 HIGH CVE-2026-49357 line-desktop-mcp: unauthenticated HTTP exposes LINE chats -- Jun 19, 2026 MEDIUM GHSA-664h-gpgq-h6xx n8n: viewer role can start/cancel/delete eval workflow runs 5.4 Jun 17, 2026 UNKNOWN CVE-2026-54312 n8n: prototype pollution renders instance non-functional -- Jun 16, 2026 MEDIUM CVE-2026-54303 n8n: reflected XSS in trigger nodes enables session hijack -- Jun 16, 2026 UNKNOWN CVE-2026-54302 n8n: stored XSS in Chat Trigger enables session hijack -- Jun 16, 2026 MEDIUM GHSA-jwm3-qcfw-c5pp n8n: AST bypass leaks env vars in Python Task Runner 5.0 Jun 16, 2026 MEDIUM GHSA-h3jj-5f3v-3685 n8n: read-only users can trigger workflow execution via API 6.4 Jun 16, 2026 MEDIUM CVE-2026-54314 n8n: decompression bomb DoS via public webhook -- Jun 16, 2026 UNKNOWN CVE-2026-54307 n8n: credential hijack via partial authorization bypass -- Jun 16, 2026 UNKNOWN CVE-2026-54305 n8n: IDOR enables OAuth credential hijack in agent workflows -- Jun 16, 2026 UNKNOWN CVE-2026-54309 n8n: MCP browser auth bypass allows full browser takeover -- Jun 16, 2026 UNKNOWN CVE-2026-54304 n8n: credential exfiltration via SecurityScorecard SSRF node -- Jun 16, 2026 UNKNOWN CVE-2026-49444 n8n: Python sandbox escape enables container RCE -- Jun 16, 2026 UNKNOWN CVE-2026-49465 n8n: Git node path traversal bypasses file sandbox -- Jun 16, 2026 UNKNOWN CVE-2026-54310 n8n: SQL injection in Postgres nodes, CVSS 9.9 -- Jun 16, 2026 UNKNOWN CVE-2026-54313 n8n: MongoDB query injection overwrites arbitrary documents -- Jun 16, 2026 HIGH GHSA-hv7x-3x78-gx53 n8n: auth bypass lets read-only users execute workflows 7.4 Jun 16, 2026

Showing 1–25 of 116

Frequently asked questions

What is n8n?

n8n is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does n8n have?

n8n has 116 known CVEs, 22 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is n8n distributed in?

n8n is distributed via the npm ecosystem and categorized as ai agents.

Where does the n8n vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of n8n?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor n8n in your stack

Get instant alerts when new vulnerabilities affect n8n. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring