N8n-Io
AI Threat Alert tracks 41 known AI/ML vulnerabilities affecting N8n-Io products — each enriched with CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis. Browse every N8n-Io CVE below, sorted by severity and recency.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| MEDIUM | CVE-2026-65014 | n8n: unauth DELETE cancels test webhook sessions | n8n | - |
| MEDIUM | CVE-2026-65589 | n8n: plaintext credential leak in LLM node logs | n8n | - |
| HIGH | CVE-2026-65016 | n8n: SSO instance-role provisioning grants owner | n8n | - |
| MEDIUM | CVE-2026-65594 | n8n: authz bypass hijacks other users' MCP workflows | n8n | - |
| MEDIUM | CVE-2026-65590 | n8n computer-use: unsandboxed shell on Linux/Windows | n8n | - |
| HIGH | CVE-2026-65591 | n8n: expression sanitizer bypass leads to host RCE | n8n | - |
| HIGH | CVE-2026-65015 | n8n: Project Viewer escalates via AI Agent tool | n8n | - |
| MEDIUM | CVE-2026-65593 | n8n: SSRF bypass in dynamic-node-parameters endpoint | n8n | - |
| HIGH | CVE-2026-65592 | n8n: stored XSS via javascript: URI in Resource Locator | n8n | - |
| HIGH | CVE-2026-65595 | n8n: Token Exchange bug grants admin API access | n8n | - |
| MEDIUM | CVE-2026-65596 | n8n: GraphQL node bypasses domain allowlist, leaks creds | n8n | - |
| HIGH | CVE-2026-65597 | n8n: DOM XSS in preview hijacks editor session | n8n | - |
| HIGH | CVE-2026-65598 | n8n: Git clone TOCTOU race allows RCE via symlink swap | n8n | - |
| MEDIUM | CVE-2026-65599 | n8n: GCP service account key leaks via JWT header | n8n | - |
| HIGH | CVE-2026-77068 | n8n: RCE via path traversal in MCP schema loader | n8n | - |
| LOW | CVE-2026-77069 | n8n: SSRF bypass in OAuth2 token exchange | n8n | - |
| HIGH | CVE-2026-77072 | n8n: stored XSS in Form node completion page | n8n | - |
| HIGH | CVE-2026-77071 | n8n: Supabase filter injection leaks/wipes full tables | n8n | - |
| MEDIUM | CVE-2026-77073 | n8n: MCP auth bypass grants cross-project credentials | n8n | - |
| HIGH | CVE-2026-77076 | n8n: GraphQL error leaks decrypted credential secret | n8n | - |
Page 1 of 3
Frequently asked questions
How many known vulnerabilities affect N8n-Io?
41 AI/ML CVEs affecting N8n-Io products are tracked, sourced from NVD and GitHub Advisory.
What N8n-Io products are affected?
The CVEs below map to the N8n-Io AI/ML packages and tools tracked by AI Threat Alert; open any CVE to see the affected components and versions.
Where does the N8n-Io vulnerability data come from?
Data is sourced from NVD and GitHub Advisory, then enriched with CVSS severity, EPSS exploit probability, and patch status for each CVE.
How can I monitor N8n-Io for new vulnerabilities?
AI Threat Alert tracks N8n-Io continuously; a Pro subscription adds breaking alerts when new CVEs affecting N8n-Io are published.
How do I assess N8n-Io's security exposure?
Each CVE below carries CVSS severity and exploitation signals, so you can review the highest-severity N8n-Io issues first and judge the exposure for your stack.