n8n Vulnerabilities

npm AI Agents

AI Threat Alert tracks 116 known vulnerabilities in n8n, 22 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
69
Risk Score
116
Total CVEs
22
Critical
npm
Ecosystem
Jun 30, 2026
Last CVE
53%
Patch Rate
7d
Avg Time to Patch
194,300 stars 58,888 forks 1,482 issues Last push Jun 28, 2026
View on GitHub
OpenSSF Scorecard 6.6/10

Known Vulnerabilities (116 total, page 4 of 5)

Severity CVE ID Summary CVSS Published
CRITICAL CVE-2026-27577 n8n: Code Injection enables RCE 9.9 Feb 25, 2026 HIGH CVE-2026-27498 n8n: Code Injection enables RCE 8.8 Feb 25, 2026 HIGH CVE-2026-27497 n8n: SQL Injection exposes database 8.8 Feb 25, 2026 CRITICAL CVE-2026-27495 n8n: Code Injection enables RCE 9.9 Feb 25, 2026 CRITICAL CVE-2026-27494 n8n: security flaw enables exploitation 9.9 Feb 25, 2026 CRITICAL CVE-2026-27493 n8n: Code Injection enables RCE 9.0 Feb 25, 2026 MEDIUM CVE-2026-25631 n8n: Input Validation flaw enables exploitation 6.5 Feb 6, 2026 HIGH CVE-2026-21893 n8n: Input Validation flaw enables exploitation 7.2 Feb 4, 2026 CRITICAL CVE-2026-25115 n8n: Protection Bypass circumvents security controls 9.9 Feb 4, 2026 HIGH CVE-2026-25056 n8n: Arbitrary File Upload enables RCE 8.8 Feb 4, 2026 HIGH CVE-2026-25055 n8n: Path Traversal enables file access 8.1 Feb 4, 2026 MEDIUM CVE-2026-25054 n8n: XSS enables session hijacking 5.4 Feb 4, 2026 CRITICAL CVE-2026-25053 n8n: Command Injection enables RCE 9.9 Feb 4, 2026 CRITICAL CVE-2026-25052 n8n: security flaw enables exploitation 9.9 Feb 4, 2026 MEDIUM CVE-2026-25051 n8n: XSS enables session hijacking 5.4 Feb 4, 2026 CRITICAL CVE-2026-25049 n8n: security flaw enables exploitation 9.9 Feb 4, 2026 HIGH CVE-2025-61917 n8n: Info Disclosure leaks sensitive data 7.7 Feb 4, 2026 CRITICAL CVE-2026-1470 n8n: Code Injection enables RCE 9.9 Jan 27, 2026 CRITICAL CVE-2026-0863 n8n: Code Injection enables RCE 9.9 Jan 18, 2026 MEDIUM CVE-2025-68949 n8n: security flaw enables exploitation 5.3 Jan 13, 2026 MEDIUM CVE-2026-21894 n8n: security flaw enables exploitation 6.5 Jan 8, 2026 CRITICAL CVE-2026-21877 n8n: Code Injection enables RCE 9.9 Jan 8, 2026 CRITICAL CVE-2026-21858 n8n: Input Validation flaw enables exploitation 10.0 Jan 8, 2026 MEDIUM CVE-2025-68697 n8n: security flaw enables exploitation 5.4 Dec 26, 2025 CRITICAL CVE-2025-68668 n8n: Protection Bypass circumvents security controls 9.9 Dec 26, 2025

Showing 76–100 of 116

Frequently asked questions

What is n8n?

n8n is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does n8n have?

n8n has 116 known CVEs, 22 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is n8n distributed in?

n8n is distributed via the npm ecosystem and categorized as ai agents.

Where does the n8n vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of n8n?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor n8n in your stack

Get instant alerts when new vulnerabilities affect n8n. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring