n8n Vulnerabilities

npm AI Agents

AI Threat Alert tracks 229 known vulnerabilities in n8n, 24 rated critical — an AI/ML ai agents in the npm ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
69
Risk Score
229
Total CVEs
24
Critical
npm
Ecosystem
Sep 8, 2026
Last CVE
53%
Patch Rate
5d
Avg Time to Patch
206,068 stars 60,893 forks 1,108 issues Last push Sep 27, 2026
View on GitHub
OpenSSF Scorecard 6.7/10

Known Vulnerabilities (229 total, page 9 of 10)

Severity CVE ID Summary CVSS Published
CRITICAL CVE-2026-25053 n8n: Command Injection enables RCE 9.9 Feb 4, 2026 CRITICAL CVE-2026-25052 n8n: security flaw enables exploitation 9.9 Feb 4, 2026 MEDIUM CVE-2026-25051 n8n: XSS enables session hijacking 5.4 Feb 4, 2026 CRITICAL CVE-2026-25049 n8n: security flaw enables exploitation 9.9 Feb 4, 2026 HIGH CVE-2025-61917 n8n: Info Disclosure leaks sensitive data 7.7 Feb 4, 2026 CRITICAL CVE-2026-1470 n8n: Code Injection enables RCE 9.9 Jan 27, 2026 CRITICAL CVE-2026-0863 n8n: Code Injection enables RCE 9.9 Jan 18, 2026 MEDIUM CVE-2025-68949 n8n: security flaw enables exploitation 5.3 Jan 13, 2026 MEDIUM CVE-2026-21894 n8n: security flaw enables exploitation 6.5 Jan 8, 2026 CRITICAL CVE-2026-21877 n8n: Code Injection enables RCE 9.9 Jan 8, 2026 CRITICAL CVE-2026-21858 n8n: Input Validation flaw enables exploitation 10.0 Jan 8, 2026 MEDIUM CVE-2025-68697 n8n: security flaw enables exploitation 5.4 Dec 26, 2025 CRITICAL CVE-2025-68668 n8n: Protection Bypass circumvents security controls 9.9 Dec 26, 2025 MEDIUM CVE-2025-61914 n8n: XSS enables session hijacking 5.4 Dec 26, 2025 HIGH CVE-2025-68613 n8n: security flaw enables exploitation 8.8 Dec 19, 2025 HIGH CVE-2025-65964 n8n: security flaw enables exploitation 8.8 Dec 9, 2025 HIGH CVE-2025-62726 n8n: security flaw enables exploitation 8.8 Oct 30, 2025 MEDIUM CVE-2025-58177 n8n: stored XSS in LangChain chat trigger (public) 5.4 Sep 15, 2025 HIGH CVE-2025-56265 n8n: unrestricted file upload RCE via Chat Trigger 8.8 Sep 8, 2025 CRITICAL CVE-2025-55526 n8n-workflows: path traversal in download_workflow endpoint 9.1 Aug 26, 2025 MEDIUM CVE-2025-57749 n8n: symlink traversal enables arbitrary file read/write 6.5 Aug 20, 2025 MEDIUM CVE-2025-52478 n8n: Stored XSS enables full account takeover 5.4 Aug 19, 2025 MEDIUM CVE-2025-52554 n8n: broken authz enables cross-user workflow termination 4.3 Jul 3, 2025 MEDIUM CVE-2025-49595 n8n: DoS via empty filesystem URI in binary-data API 4.9 Jul 3, 2025 MEDIUM CVE-2025-49592 n8n: open redirect enables phishing via login flow 5.4 Jun 26, 2025

Showing 201–225 of 229

Frequently asked questions

What is n8n?

n8n is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the npm ecosystem.

How many known vulnerabilities does n8n have?

n8n has 229 known CVEs, 24 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is n8n distributed in?

n8n is distributed via the npm ecosystem and categorized as ai agents.

Where does the n8n vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of n8n?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor n8n in your stack

Get instant alerts when new vulnerabilities affect n8n. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring