n8n Vulnerabilities

npm AI Agents

AI Threat Alert tracks 229 known vulnerabilities in n8n, 24 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
69
Risk Score
229
Total CVEs
24
Critical
npm
Ecosystem
Sep 8, 2026
Last CVE
53%
Patch Rate
5d
Avg Time to Patch
206,068 stars 60,893 forks 1,108 issues Last push Sep 27, 2026
View on GitHub
OpenSSF Scorecard 6.7/10

Known Vulnerabilities (229 total, page 3 of 10)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-72770 n8n: path traversal in Git node bypasses repo sandbox 6.5 Aug 11, 2026 UNKNOWN CVE-2026-72769 n8n: prototype pollution in VM engine crashes process -- Aug 11, 2026 HIGH CVE-2026-72768 n8n: SSRF bypass in MCP Client node exposes internal hosts 8.3 Aug 11, 2026 UNKNOWN CVE-2026-72767 n8n: Git node RCE via malicious repo hooks -- Aug 11, 2026 HIGH CVE-2026-72766 n8n: Send Email node type confusion enables SSRF, LFI 7.5 Aug 11, 2026 CRITICAL CVE-2026-72765 n8n: expression sandbox escape leads to RCE 9.9 Aug 11, 2026 UNKNOWN CVE-2026-72764 n8n: module cache poisoning breaks multi-user isolation -- Aug 11, 2026 MEDIUM CVE-2026-72763 n8n: Editor role bypasses credential ACL via sub-workflow 6.5 Aug 11, 2026 UNKNOWN CVE-2026-72762 n8n: arbitrary file write via Edit Image node format param -- Aug 11, 2026 HIGH CVE-2026-72750 n8n: SQL injection via Snowflake node Execute Query 8.8 Aug 11, 2026 MEDIUM CVE-2026-72749 n8n: prototype pollution DoS via Edit Fields node 6.5 Aug 11, 2026 HIGH GHSA-v42f-v8xc-j435 Budibase: SSRF guard bypass via DNS rebinding 8.5 Jul 24, 2026 HIGH GHSA-8342-988q-86cr n8n: auth bypass via embed login token exchange -- Jul 22, 2026 HIGH GHSA-64xh-79j6-r5v8 n8n: AI node credential allowlist bypass leaks secrets -- Jul 22, 2026 HIGH GHSA-gf29-4f56-r2jf n8n: Git node bypass leaks arbitrary local repos -- Jul 22, 2026 MEDIUM GHSA-vhf8-cg2h-cg3p n8n: MCP Client SSRF bypasses egress protection -- Jul 22, 2026 HIGH GHSA-rcv6-pvrj-4xcg n8n: Git node RCE via malicious repo hooks -- Jul 22, 2026 HIGH GHSA-2x35-3fw4-9jr4 n8n: type confusion in Send Email leaks host files -- Jul 22, 2026 HIGH GHSA-gv7g-jm28-cr3m n8n: expression sandbox bypass enables host RCE -- Jul 22, 2026 HIGH GHSA-6qc9-mqvw-jg7x n8n: authz bypass exposes shared workflow credentials -- Jul 22, 2026 HIGH GHSA-cj9h-qx8g-pq2g n8n: credential authz bypass via sub-workflow JSON -- Jul 22, 2026 HIGH GHSA-xmc9-4f2h-jf9c n8n: Edit Image node path traversal allows file write -- Jul 22, 2026 HIGH GHSA-xwx6-jjhv-84p8 n8n: prototype pollution causes instance-wide DoS -- Jul 22, 2026 MEDIUM GHSA-hx4h-vr3m-45vh n8n: prototype pollution in expression engine causes DoS -- Jul 22, 2026 MEDIUM GHSA-pf2q-pxhf-hgmw n8n: path traversal in computer-use tool leaks files -- Jul 22, 2026

Showing 51–75 of 229

Frequently asked questions

What is n8n?

n8n is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does n8n have?

n8n has 229 known CVEs, 24 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is n8n distributed in?

n8n is distributed via the npm ecosystem and categorized as ai agents.

Where does the n8n vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of n8n?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor n8n in your stack

Get instant alerts when new vulnerabilities affect n8n. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring