CVE-2026-25049
- EPSS 1.43%
- Veröffentlicht 04.02.2026 17:16:22
- Zuletzt bearbeitet 05.02.2026 20:22:47
n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command ...
CVE-2026-25051
- EPSS 0.22%
- Veröffentlicht 04.02.2026 17:16:22
- Zuletzt bearbeitet 05.02.2026 20:23:13
n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP endpoints. Under certain conditions, the Content Securi...
CVE-2025-61917
- EPSS 0.36%
- Veröffentlicht 04.02.2026 17:16:08
- Zuletzt bearbeitet 18.02.2026 17:46:40
n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buf...
CVE-2026-1470
- EPSS 18.72%
- Veröffentlicht 27.01.2026 14:23:53
- Zuletzt bearbeitet 20.02.2026 13:44:27
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficientl...
CVE-2026-0863
- EPSS 8.64%
- Veröffentlicht 18.01.2026 15:37:07
- Zuletzt bearbeitet 10.02.2026 17:23:41
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via the Code blo...
CVE-2025-68949
- EPSS 0.26%
- Veröffentlicht 13.01.2026 18:43:20
- Zuletzt bearbeitet 16.01.2026 18:47:32
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the so...
CVE-2026-21894
- EPSS 0.44%
- Veröffentlicht 08.01.2026 09:56:04
- Zuletzt bearbeitet 20.01.2026 15:09:07
n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe webhook event...
CVE-2026-21877
- EPSS 5.26%
- Veröffentlicht 08.01.2026 00:39:58
- Zuletzt bearbeitet 20.01.2026 15:08:24
n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Clo...
- EPSS 72.55%
- Veröffentlicht 07.01.2026 23:57:52
- Zuletzt bearbeitet 16.01.2026 19:31:34
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant acces...
CVE-2025-68697
- EPSS 0.25%
- Veröffentlicht 26.12.2025 21:51:12
- Zuletzt bearbeitet 31.12.2025 21:27:25
n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can invoke inter...