CVE-2026-21877
- EPSS 5.26%
- Veröffentlicht 08.01.2026 00:39:58
- Zuletzt bearbeitet 20.01.2026 15:08:24
n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Clo...
- EPSS 71.65%
- Veröffentlicht 07.01.2026 23:57:52
- Zuletzt bearbeitet 16.01.2026 19:31:34
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant acces...
CVE-2025-68697
- EPSS 0.24%
- Veröffentlicht 26.12.2025 21:51:12
- Zuletzt bearbeitet 31.12.2025 21:27:25
n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with workflow editing access can invoke inter...
CVE-2025-68668
- EPSS 12.69%
- Veröffentlicht 26.12.2025 21:49:20
- Zuletzt bearbeitet 05.01.2026 17:15:46
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit t...
CVE-2025-61914
- EPSS 0.22%
- Veröffentlicht 26.12.2025 21:48:59
- Zuletzt bearbeitet 31.12.2025 21:31:37
n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this node responds with HTML content containing executable...
CVE-2025-68613
- EPSS 97.88%
- Veröffentlicht 19.12.2025 22:23:47
- Zuletzt bearbeitet 11.03.2026 19:40:09
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain c...
CVE-2025-65964
- EPSS 0.61%
- Veröffentlicht 08.12.2025 23:35:02
- Zuletzt bearbeitet 02.01.2026 21:10:59
n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-commit hooks. The Add Config operation allows workflows to set arbitrary Git configuration ...
CVE-2025-62726
- EPSS 0.73%
- Veröffentlicht 30.10.2025 16:24:11
- Zuletzt bearbeitet 31.12.2025 02:30:18
n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote repository co...
CVE-2025-58177
- EPSS 0.22%
- Veröffentlicht 15.09.2025 16:49:06
- Zuletzt bearbeitet 14.10.2025 19:34:18
n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node wi...
CVE-2025-56265
- EPSS 0.56%
- Veröffentlicht 08.09.2025 00:00:00
- Zuletzt bearbeitet 12.09.2025 20:47:21
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.