CVE-2025-68668
- EPSS 13.17%
- Veröffentlicht 26.12.2025 21:49:20
- Zuletzt bearbeitet 05.01.2026 17:15:46
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit t...
CVE-2025-61914
- EPSS 0.23%
- Veröffentlicht 26.12.2025 21:48:59
- Zuletzt bearbeitet 31.12.2025 21:31:37
n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this node responds with HTML content containing executable...
CVE-2025-68613
- EPSS 97.95%
- Veröffentlicht 19.12.2025 22:23:47
- Zuletzt bearbeitet 11.03.2026 19:40:09
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain c...
CVE-2025-65964
- EPSS 0.67%
- Veröffentlicht 08.12.2025 23:35:02
- Zuletzt bearbeitet 02.01.2026 21:10:59
n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation allows workflows to set arbitrary Git configuration ...
CVE-2025-62726
- EPSS 0.76%
- Veröffentlicht 30.10.2025 16:24:11
- Zuletzt bearbeitet 31.12.2025 02:30:18
n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote repository co...
CVE-2025-58177
- EPSS 0.24%
- Veröffentlicht 15.09.2025 16:49:06
- Zuletzt bearbeitet 14.10.2025 19:34:18
n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node wi...
CVE-2025-56265
- EPSS 0.6%
- Veröffentlicht 08.09.2025 00:00:00
- Zuletzt bearbeitet 12.09.2025 20:47:21
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.
CVE-2025-55526
- EPSS 0.82%
- Veröffentlicht 26.08.2025 00:00:00
- Zuletzt bearbeitet 20.08.2026 13:12:43
n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
CVE-2025-57749
- EPSS 0.48%
- Veröffentlicht 20.08.2025 21:46:39
- Zuletzt bearbeitet 03.09.2025 15:07:16
n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly account fo...
CVE-2025-52478
- EPSS 0.37%
- Veröffentlicht 19.08.2025 16:32:34
- Zuletzt bearbeitet 03.09.2025 15:12:04
n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifically in the Form Trigger node's HTML form element. An authenticated attacker can inject malicious HT...