n8n Vulnerabilities

npm AI Agents

AI Threat Alert tracks 229 known vulnerabilities in n8n, 24 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
69
Risk Score
229
Total CVEs
24
Critical
npm
Ecosystem
Sep 8, 2026
Last CVE
53%
Patch Rate
5d
Avg Time to Patch
206,068 stars 60,893 forks 1,108 issues Last push Sep 27, 2026
View on GitHub
OpenSSF Scorecard 6.7/10

Known Vulnerabilities (229 total, page 4 of 10)

Severity CVE ID Summary CVSS Published
MEDIUM GHSA-9cmh-xcqm-5hqr n8n: shared module cache poisoning breaks user isolation -- Jul 22, 2026 MEDIUM GHSA-jqwr-vx3p-r266 n8n: SQL injection in Postgres Trigger node -- Jul 22, 2026 MEDIUM GHSA-652q-gvq3-74qv n8n: SQL injection in Snowflake Execute Query node -- Jul 22, 2026 MEDIUM CVE-2026-65599 n8n: GCP service account key leaks via JWT header -- Jul 22, 2026 HIGH CVE-2026-65598 n8n: Git clone TOCTOU race allows RCE via symlink swap -- Jul 22, 2026 HIGH CVE-2026-65597 n8n: DOM XSS in preview hijacks editor session -- Jul 22, 2026 MEDIUM CVE-2026-65596 n8n: GraphQL node bypasses domain allowlist, leaks creds -- Jul 22, 2026 HIGH CVE-2026-65595 n8n: Token Exchange bug grants admin API access -- Jul 22, 2026 HIGH CVE-2026-65592 n8n: stored XSS via javascript: URI in Resource Locator -- Jul 22, 2026 MEDIUM CVE-2026-65593 n8n: SSRF bypass in dynamic-node-parameters endpoint -- Jul 22, 2026 HIGH CVE-2026-65015 n8n: Project Viewer escalates via AI Agent tool -- Jul 22, 2026 MEDIUM CVE-2026-65594 n8n: authz bypass hijacks other users' MCP workflows -- Jul 22, 2026 HIGH CVE-2026-65591 n8n: expression sanitizer bypass leads to host RCE -- Jul 22, 2026 MEDIUM CVE-2026-65590 n8n computer-use: unsandboxed shell on Linux/Windows -- Jul 22, 2026 HIGH CVE-2026-65016 n8n: SSO instance-role provisioning grants owner -- Jul 22, 2026 MEDIUM CVE-2026-65589 n8n: plaintext credential leak in LLM node logs -- Jul 22, 2026 MEDIUM CVE-2026-65014 n8n: unauth DELETE cancels test webhook sessions -- Jul 22, 2026 MEDIUM CVE-2026-59259 n8n: permission bypass exposes external secrets -- Jul 15, 2026 MEDIUM CVE-2026-59254 n8n: authz bypass leaks external secrets -- Jul 15, 2026 MEDIUM CVE-2026-56353 n8n: auth bypass in Chat Trigger webhook node 4.8 Jul 15, 2026 UNKNOWN CVE-2026-56349 n8n: input validation bypass in Guardrail node -- Jul 15, 2026 MEDIUM CVE-2026-56352 n8n: legacy node bypasses file path restrictions 6.4 Jul 15, 2026 MEDIUM CVE-2026-55608 n8n-mcp: cross-tenant leak of workflow backups 4.2 Jul 14, 2026 CRITICAL CVE-2026-54052 n8n-mcp: broken tenant isolation leaks workflow credentials 9.9 Jul 14, 2026 MEDIUM CVE-2026-58661 n8n: disk exhaustion via data-table upload quota gap 4.3 Jul 10, 2026

Showing 76–100 of 229

Frequently asked questions

What is n8n?

n8n is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does n8n have?

n8n has 229 known CVEs, 24 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is n8n distributed in?

n8n is distributed via the npm ecosystem and categorized as ai agents.

Where does the n8n vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of n8n?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor n8n in your stack

Get instant alerts when new vulnerabilities affect n8n. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring