N8n-Io
AI Threat Alert tracks 41 known AI/ML vulnerabilities affecting N8n-Io products — each enriched with CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis. Browse every N8n-Io CVE below, sorted by severity and recency.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| HIGH | CVE-2026-77070 | n8n: NoSQL injection in MongoDB node wipes/exfils data | n8n | - |
| HIGH | CVE-2026-77075 | n8n: expression injection executes JS in victim session | n8n | - |
| MEDIUM | CVE-2026-77074 | n8n: SSRF/LFI via MVG injection in Edit Image node | n8n | - |
| MEDIUM | CVE-2026-77081 | n8n: GraphQL node allowed-domains bypass leaks creds | n8n | - |
| HIGH | CVE-2026-77084 | n8n: RCE via unsanitized Git node config values | n8n | - |
| MEDIUM | CVE-2026-77082 | n8n: ReDoS in Filter/Switch nodes stalls workers | n8n | - |
| MEDIUM | CVE-2026-77085 | n8n: SSRF protection bypass in SearXNG Agent tool | n8n | - |
| HIGH | CVE-2026-77080 | n8n: Snowflake node allows arbitrary file read/write | n8n | - |
| HIGH | CVE-2026-77079 | n8n: authz bypass in role deletion grants project admin | n8n | - |
| HIGH | CVE-2026-77077 | n8n: EventEmitter prototype pollution enables sandbox RCE | n8n | - |
| MEDIUM | CVE-2026-77083 | n8n: Code node sandbox escape via proto pollution | n8n | - |
| UNKNOWN | CVE-2026-85165 | n8n: expression sandbox bypass mutates host globals | n8n | - |
| UNKNOWN | CVE-2026-85166 | n8n: credential theft via unvalidated workflow node | n8n | - |
| UNKNOWN | CVE-2026-85168 | n8n: Git node RCE via poisoned filter/merge config | n8n | - |
| UNKNOWN | CVE-2026-85167 | n8n: query injection turns lookup into full DB read | n8n | - |
| HIGH | CVE-2026-85169 | n8n: $fromAI sandbox escape enables RCE | n8n | - |
| UNKNOWN | CVE-2026-85171 | n8n: plaintext credential leak via error logging | n8n | - |
| UNKNOWN | CVE-2026-85170 | n8n: local file read & SSRF via Gmail/Brevo nodes | n8n | - |
| UNKNOWN | CVE-2026-85173 | n8n: IDOR exposes workflow data across projects | n8n | - |
| UNKNOWN | CVE-2026-85172 | n8n: SSRF bypass via uri/url validation mismatch | n8n | - |
Frequently asked questions
How many known vulnerabilities affect N8n-Io?
41 AI/ML CVEs affecting N8n-Io products are tracked, sourced from NVD and GitHub Advisory.
What N8n-Io products are affected?
The CVEs below map to the N8n-Io AI/ML packages and tools tracked by AI Threat Alert; open any CVE to see the affected components and versions.
Where does the N8n-Io vulnerability data come from?
Data is sourced from NVD and GitHub Advisory, then enriched with CVSS severity, EPSS exploit probability, and patch status for each CVE.
How can I monitor N8n-Io for new vulnerabilities?
AI Threat Alert tracks N8n-Io continuously; a Pro subscription adds breaking alerts when new CVEs affecting N8n-Io are published.
How do I assess N8n-Io's security exposure?
Each CVE below carries CVSS severity and exploitation signals, so you can review the highest-severity N8n-Io issues first and judge the exposure for your stack.