N8n
124 known vulnerabilities
Top Products
n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressi
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions a
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat
n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass v
n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker t
n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability e
n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.
n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to
n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th
n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scriptin
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac
n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Writ
n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability w
n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re
n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/bina
n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. A
n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) t
The n8n package 0.218.0 for Node.js allows Information Disclosure.
The n8n package 0.218.0 for Node.js allows Escalation of Privileges.
The n8n package 0.218.0 for Node.js allows Directory Traversal.
Frequently Asked Questions
How many CVEs affect N8n?
N8n has 124 CVE records in our database, including 25 critical and 49 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe N8n vulnerabilities?
N8n has 25 critical severity (CVSS 9.0+) and 49 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for N8n vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in N8n products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect N8n Vulnerabilities
CyberStrike scans your infrastructure for N8n vulnerabilities and provides real-time remediation guidance.
Get Started