n8n Vulnerabilities

npm AI Agents

AI Threat Alert tracks 229 known vulnerabilities in n8n, 24 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
69
Risk Score
229
Total CVEs
24
Critical
npm
Ecosystem
Sep 8, 2026
Last CVE
53%
Patch Rate
5d
Avg Time to Patch
206,068 stars 60,893 forks 1,108 issues Last push Sep 27, 2026
View on GitHub
OpenSSF Scorecard 6.7/10

Known Vulnerabilities (229 total, page 1 of 10)

Severity CVE ID Summary CVSS Published
UNKNOWN CVE-2026-86996 n8n: Agent tool bypasses workflow caller restriction -- Sep 8, 2026 MEDIUM CVE-2026-86995 n8n Git node: config injection leaks local files -- Sep 8, 2026 MEDIUM CVE-2026-86994 n8n: broken authZ leaks workflow IDs to any member -- Sep 8, 2026 MEDIUM CVE-2026-86993 n8n: cross-project credential theft via Log Streaming -- Sep 8, 2026 MEDIUM CVE-2026-86085 n8n: missing scope check leaks project member emails -- Sep 8, 2026 MEDIUM CVE-2026-86084 n8n: stale OIDC endpoint bypasses disabled SSO -- Sep 8, 2026 HIGH CVE-2026-86083 n8n: code injection via legacy expression engine -- Sep 8, 2026 HIGH CVE-2026-86082 n8n: OpenAI node leaks API key via SSRF bypass -- Sep 8, 2026 HIGH CVE-2026-86081 n8n: ReDoS via Git node clone freezes instance -- Sep 8, 2026 MEDIUM CVE-2026-86080 n8n: GitHub webhook signature bypass on 422 retry -- Sep 8, 2026 MEDIUM CVE-2026-86079 n8n: path traversal in Elasticsearch node leaks data -- Sep 8, 2026 MEDIUM CVE-2026-86078 n8n: prototype pollution in AI workflow summary -- Sep 8, 2026 MEDIUM CVE-2026-86077 n8n: chat token replay bypasses HITL approval gates -- Sep 8, 2026 HIGH CVE-2026-86076 n8n: expression sandbox escape enables RCE -- Sep 8, 2026 HIGH CVE-2026-86075 n8n: unauth OAuth DCR fields exhaust DB storage -- Sep 8, 2026 MEDIUM CVE-2026-86074 n8n: SSRF in AI credential setup leaks tokens -- Sep 8, 2026 MEDIUM CVE-2026-86073 n8n: OAuth refresh token skips workflow-resource binding -- Sep 8, 2026 UNKNOWN CVE-2026-85172 n8n: SSRF bypass via uri/url validation mismatch -- Sep 3, 2026 UNKNOWN CVE-2026-85173 n8n: IDOR exposes workflow data across projects -- Sep 3, 2026 UNKNOWN CVE-2026-85170 n8n: local file read & SSRF via Gmail/Brevo nodes -- Sep 3, 2026 UNKNOWN CVE-2026-85171 n8n: plaintext credential leak via error logging -- Sep 3, 2026 UNKNOWN CVE-2026-85167 n8n: query injection turns lookup into full DB read -- Sep 3, 2026 HIGH CVE-2026-85169 n8n: $fromAI sandbox escape enables RCE -- Sep 3, 2026 UNKNOWN CVE-2026-85168 n8n: Git node RCE via poisoned filter/merge config -- Sep 3, 2026 UNKNOWN CVE-2026-85166 n8n: credential theft via unvalidated workflow node -- Sep 3, 2026

Showing 1–25 of 229

Frequently asked questions

What is n8n?

n8n is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does n8n have?

n8n has 229 known CVEs, 24 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is n8n distributed in?

n8n is distributed via the npm ecosystem and categorized as ai agents.

Where does the n8n vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of n8n?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor n8n in your stack

Get instant alerts when new vulnerabilities affect n8n. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring