n8n vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-68613Criticaln8n: n8n Vulnerable to Remote Code Execution via Expression InjectionCVE-2025-65964Criticaln8n: n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit HookCVE-2025-62726Highn8n: n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit HookGHSA-365G-VJW2-GRX8Highn8n-nodes-base: n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on HostCVE-2025-58177Mediumn8n: Stored XSS in n8n LangChain Chat Trigger Node via initialMessages ParameterCVE-2025-57749Mediumn8n: n8n symlink traversal vulnerability in "Read/Write File" node allows access to restricted filesCVE-2025-52478Highn8n: Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/sourceCVE-2025-52554Mediumn8n: n8n is vulnerable to Improper Authorization through its `/stop` endpointCVE-2025-49595Mediumn8n: n8n Vulnerable to Denial of Service via Malformed Binary Data RequestsCVE-2025-49592Mediumn8n: n8n allows open redirects via the /signin endpointCVE-2025-46343Mediumn8n: n8n Vulnerable to Stored XSS through Attachments View EndpointCVE-2023-27562Mediumn8n: n8n Directory Traversal vulnerabilityCVE-2023-27564Highn8n: n8n Information Disclosure vulnerabilityCVE-2023-27563Highn8n: n8n Privilege Escalation vulnerability

Stop the waste.
Protect your environment with Kodem.