n8n vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-8342-988Q-86CRHighn8n: n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed LoginCVE-2026-65016Highn8n: n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance OwnerCVE-2026-65591Highn8n: n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code ExecutionCVE-2026-65593Mediumn8n: n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network AccessCVE-2026-65595Highn8n: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTsCVE-2026-59208Highn8n: n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity ResolutionCVE-2026-59207Highn8n: n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP ConnectorCVE-2026-59206Highn8n: n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project EnumerationCVE-2026-59209Highn8n: n8n: Shared Credential Header Leak via HTTP Request Pagination ExpressionCVE-2026-65599Mediumn8n: n8n: Google Service Account Private Key Exposed in JWT HeaderCVE-2026-65592Highn8n: n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`CVE-2026-65597Highn8n: n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML PreviewCVE-2026-65598Highn8n: n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code ExecutionCVE-2026-65015Highn8n: n8n: AI Agents Project Viewer Privilege Escalation via run_node_toolGHSA-664H-GPGQ-H6XXMediumn8n: n8n: Wrong OAuth Scope on Evaluation Test Runs EndpointsCVE-2026-54304Highn8n: n8n: SecurityScorecard Node Leaks API Token to User-Controlled HostCVE-2026-54309Highn8n: n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control SessionsCVE-2026-54305Highn8n: n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE EndpointsCVE-2026-54307Highn8n: n8n: Credential Exfiltration via Permission BypassCVE-2026-54314Mediumn8n: n8n: Denial of Service via ZIP decompression in webhook workflowGHSA-H3JJ-5F3V-3685Mediumn8n: n8n: Public API Execution Retry Authorization BypassGHSA-JWM3-QCFW-C5PPMediumn8n: n8n: Python Code Node AST Validator BypassCVE-2026-54302Highn8n: n8n: Stored XSS in Chat Trigger NodeCVE-2026-54303Mediumn8n: n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification EndpointsCVE-2026-54312Highn8n: n8n: Microsoft SQL Node Prototype Pollution

Stop the waste.
Protect your environment with Kodem.