n8n vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-42230Mediumn8n: n8n has Open Redirect in MCP OAuth Consent FlowCVE-2026-42233Mediumn8n: n8n has SQL Injection in Oracle Database Node via Limit FieldCVE-2026-42237Mediumn8n: n8n has SQL Injection in Snowflake and MySQL NodesGHSA-364X-8G5J-X2PRMediumn8n: n8n has XSS in its Credential Management FlowGHSA-3C7F-5HGJ-H279Mediumn8n: n8n has XSS in Chat Trigger Node through Custom CSSGHSA-W673-8FJW-457CMediumn8n: n8n: Authenticated XSS and Open Redirect via Form NodeCVE-2026-56358Mediumn8n: n8n has a Stored XSS Vulnerability in its Form TriggerCVE-2026-33751Mediumn8n: n8n Vulnerable to LDAP Filter Injection in LDAP NodeCVE-2026-33749Mediumn8n: n8n Vulnerable to XSS via Binary Data Inline HTML RenderingCVE-2026-33713Highn8n: n8n has SQL Injection in Data Table Node via orderByColumn ExpressionCVE-2026-33696Criticaln8n: n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCECVE-2026-33724Mediumn8n: n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=noCVE-2026-33722Highn8n: n8n Has External Secrets Authorization Bypass in Credential SavingCVE-2026-33720Mediumn8n: n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACKCVE-2026-33665Highn8n: n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account TakeoverCVE-2026-33663Highn8n: n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community EditionCVE-2026-33660Criticaln8n: n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL ModeCVE-2026-27496Highn8n: n8n has In-Process Memory Disclosure in its Task RunnerGHSA-38C7-23HJ-2WGQMediumn8n: n8n has Webhook Forgery on Zendesk Trigger NodeGHSA-FVFV-PPW4-7H2WMediumn8n: n8n has a Guardrail Node BypassGHSA-JH8H-6C9Q-7GMWMediumn8n: n8n has an Authentication Bypass in its Chat Trigger NodeGHSA-VJF3-2GPJ-233VMediumn8n: n8n has an SSO Enforcement Bypass in its Self-Service Settings APICVE-2026-56357Mediumn8n: n8n: Webhook Forgery on Github Webhook TriggerCVE-2026-56351Mediumn8n: n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodesCVE-2026-27578Highn8n: n8n Vulnerable to Stored XSS via Various Nodes

Stop the waste.
Protect your environment with Kodem.