n8n Vulnerabilities

npm AI Agents

AI Threat Alert tracks 229 known vulnerabilities in n8n, 24 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
69
Risk Score
229
Total CVEs
24
Critical
npm
Ecosystem
Sep 8, 2026
Last CVE
53%
Patch Rate
5d
Avg Time to Patch
206,068 stars 60,893 forks 1,108 issues Last push Sep 27, 2026
View on GitHub
OpenSSF Scorecard 6.7/10

Known Vulnerabilities (229 total, page 5 of 10)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-56354 n8n: stored XSS + phishing redirect in Form Node 5.4 Jul 10, 2026 MEDIUM CVE-2026-59209 n8n: editor-level access leaks credential headers 6.5 Jul 9, 2026 MEDIUM CVE-2026-59208 n8n: multi-issuer JWT sub collision bypasses auth 6.8 Jul 9, 2026 MEDIUM CVE-2026-59207 n8n: MCP tool bypasses credential domain allowlist 6.5 Jul 9, 2026 HIGH CVE-2026-59206 n8n: prototype pollution lets guests hit admin APIs 7.1 Jul 9, 2026 HIGH CVE-2026-59257 n8n: SQL injection via MySQL v1 node expressions 8.8 Jul 8, 2026 MEDIUM CVE-2026-59253 n8n: auth bypass moves workflows across project folders 5.0 Jul 8, 2026 MEDIUM CVE-2026-56778 n8n: workflow:read scope triggers executions via API 6.4 Jul 8, 2026 HIGH CVE-2026-56776 n8n: workflow:read scope bypass triggers execution 7.4 Jul 8, 2026 MEDIUM CVE-2026-56775 n8n: viewer role bypasses RBAC on eval test runs 5.4 Jul 8, 2026 MEDIUM CVE-2026-56360 n8n: unsigned Zendesk webhook allows workflow forgery 4.0 Jul 8, 2026 MEDIUM CVE-2026-56359 n8n: XSS via malicious OAuth2 Authorization URL 5.4 Jul 8, 2026 HIGH CVE-2025-71380 n8n: authenticated RCE via Execute Command node 8.8 Jul 4, 2026 MEDIUM CVE-2026-56777 n8n: AST validator bypass leaks env vars in Python node 5.0 Jun 30, 2026 MEDIUM CVE-2026-56356 n8n: stored XSS in Chat Trigger Custom CSS field 5.4 Jun 30, 2026 MEDIUM CVE-2026-56350 n8n: authenticated users can disable SSO enforcement via API 6.3 Jun 30, 2026 MEDIUM CVE-2026-56358 n8n: stored XSS in Form Trigger enables form hijacking 5.4 Jun 24, 2026 HIGH CVE-2026-56351 n8n: SQL injection in DB nodes via identifier values 8.2 Jun 24, 2026 MEDIUM CVE-2026-56357 n8n: webhook forgery enables unauthorized workflow execution 4.0 Jun 22, 2026 CRITICAL CVE-2026-56348 n8n: SSRF bypasses allowlist, exfiltrates credentials 9.1 Jun 22, 2026 HIGH CVE-2026-54353 Budibase: SSRF via DNS rebinding in automation steps 8.5 Jun 22, 2026 HIGH CVE-2026-49357 line-desktop-mcp: unauthenticated HTTP exposes LINE chats -- Jun 19, 2026 MEDIUM GHSA-664h-gpgq-h6xx n8n: viewer role can start/cancel/delete eval workflow runs 5.4 Jun 17, 2026 UNKNOWN CVE-2026-54312 n8n: prototype pollution renders instance non-functional -- Jun 16, 2026 MEDIUM CVE-2026-54303 n8n: reflected XSS in trigger nodes enables session hijack -- Jun 16, 2026

Showing 101–125 of 229

Frequently asked questions

What is n8n?

n8n is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does n8n have?

n8n has 229 known CVEs, 24 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is n8n distributed in?

n8n is distributed via the npm ecosystem and categorized as ai agents.

Where does the n8n vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of n8n?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor n8n in your stack

Get instant alerts when new vulnerabilities affect n8n. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring