n8n vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-27577Criticaln8n: n8n: Expression Sandbox Escape Leads to RCECVE-2026-27498Criticaln8n: n8n has Arbitrary Command Execution via File Write and Git OperationsCVE-2026-27497Criticaln8n: n8n has Potential Remote Code Execution via Merge NodeCVE-2026-27495Criticaln8n: n8n has a Sandbox Escape in its JavaScript Task RunnerCVE-2026-27494Highn8n: n8n has Arbitrary File Read via Python Code Node Sandbox EscapeCVE-2026-27493Criticaln8n: n8n has Unauthenticated Expression Evaluation via Form NodeCVE-2026-25631Mediumn8n: n8n's domain allowlist bypass enables credential exfiltrationCVE-2026-25115Criticaln8n: n8n has a Python sandbox escapeCVE-2026-25056Criticaln8n: n8n Merge Node has Arbitrary File Write leading to RCECVE-2026-25055Highn8n: n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH NodeCVE-2026-25054Highn8n: n8n Has Stored Cross-site Scripting via Markdown Rendering in Workflow UICVE-2026-25053Criticaln8n: n8n has OS Command Injection in Git NodeCVE-2026-25052Criticaln8n: n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated UsersCVE-2026-25051Highn8n: n8n's Improper CSP Enforcement in Webhook Responses May Allow Stored XSSCVE-2026-25049Criticaln8n: n8n Has Expression Escape Vulnerability Leading to RCECVE-2026-21893Criticaln8n: n8n Vulnerable to Command Injection in Community Package InstallationCVE-2025-61917Highn8n: n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task RunnerCVE-2026-1470Criticaln8n: n8n Unsafe Workflow Expression Evaluation Allows Remote Code ExecutionCVE-2025-68949Mediumn8n: n8n: Webhook Node IP Whitelist Bypass via Partial String MatchingCVE-2026-21894Mediumn8n: n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged WebhooksCVE-2026-21858Criticaln8n: n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request HandlingCVE-2026-21877Criticaln8n: n8n Vulnerable to RCE via Arbitrary File WriteCVE-2025-68697Highn8n: Self-hosted n8n has Legacy Code node that enables arbitrary file read/writeCVE-2025-68668Criticaln8n: n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node CVE-2025-61914Highn8n: n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox

Stop the waste.
Protect your environment with Kodem.