Technology · N8n
N8n vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 249 vulnerabilities in N8n: 0 in the last 7 days and 151 in the last 90 days, 15 of them critical and 1 exploited in the wild. The most recent, CVE-2026-92588, was published on 16 September 2026.
- Last 7 days
- 0
- Last 90 days
- 151
- Critical, all time
- 15
- Exploited in the wild
- 1
About N8n
Open-source workflow automation and integration platform.
Latest N8n vulnerabilities
- CVE-2026-92588: n8n source control push improper authorization for cross-project deletionmediumCVSS 4.4EPSS 0.3%
- CVE-2026-92587: n8n Git node sandbox escape via relative URL path traversalmediumCVSS 5EPSS 0.3%
- CVE-2026-86996: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow…mediumCVSS 5.4EPSS 0.3%
- CVE-2026-86995: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the…mediumCVSS 4.3EPSS 0.4%
- CVE-2026-86994: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows…mediumCVSS 4.3EPSS 0.3%
- CVE-2026-86993: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event…mediumCVSS 4.9EPSS 0.5%
- CVE-2026-86085: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and…mediumCVSS 4.9EPSS 0.4%
- CVE-2026-86084: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and…mediumCVSS 5.5EPSS 0.5%
- CVE-2026-86083: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine…highCVSS 8.8EPSS 0.7%
- CVE-2026-86082: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node…highCVSS 6.5EPSS 0.4%
- CVE-2026-86081: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation…highCVSS 4EPSS 0.6%
- CVE-2026-86080: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-86079: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-86078: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node…mediumCVSS 6.5EPSS 0.6%
- CVE-2026-86077: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-86076: n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler…highCVSS 8.8EPSS 0.8%
- CVE-2026-86075: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration…highCVSS 7.5EPSS 0.6%
- CVE-2026-86074: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow…highCVSS 7.1EPSS 0.4%
- CVE-2026-86073: n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an…highCVSS 7.6EPSS 0.4%
- CVE-2026-85173: n8n Insights API missing per-project authorizationmediumCVSS 4.3EPSS 0.4%
- CVE-2026-85172: n8n server-side request forgery in legacy request helpermediumCVSS 6.4EPSS 0.3%
- CVE-2026-85171: n8n Strapi SeaTable Mailcheck credential exposure in error logsmediumCVSS 6.5EPSS 0.6%
- CVE-2026-85170: n8n Gmail and Brevo nodes local file read and SSRFmediumCVSS 6.5EPSS 0.4%
- CVE-2026-85169: n8n expression sandbox escape in $fromAI handlerhighCVSS 8.8EPSS 0.9%
- CVE-2026-85168: n8n Git node remote code execution via incomplete config neutralizationhighCVSS 8.8EPSS 0.8%
Most severe N8n vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-68613: n8n Vulnerable to Remote Code Execution via Expression Injectioncriticalexploited in the wildCVSS 3.1EPSS 99.0%
- CVE-2026-54309: n8n missing authentication in MCP Browser HTTP transportcriticalCVSS 10EPSS 0.5%
- CVE-2026-27577: n8n code injection in expression evaluationcriticalCVSS 9.9EPSS 1.0%
- CVE-2026-72765: n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user…criticalCVSS 9.9EPSS 0.9%
- CVE-2026-85165: n8n expression sandbox bypass in spread and computed-key evaluationcriticalCVSS 9.9EPSS 0.6%
- CVE-2026-54310: n8n SQL injection in TimescaleDB and Postgres v1 nodescriticalCVSS 9.9EPSS 0.5%
- CVE-2026-44791: n8n prototype pollution in XML node leading to RCEcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-44789: n8n prototype pollution in HTTP Request nodecriticalCVSS 9.9EPSS 0.5%
- CVE-2026-54305: n8n improper access control in Dynamic Credentials EE endpointscriticalCVSS 9.9EPSS 0.4%
- CVE-2026-77071: n8n Supabase node PostgREST filter injection in Row operationscriticalCVSS 9.8EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 4 | 0 | |
| 6 Jul 2026 | 19 | 0 | |
| 13 Jul 2026 | 9 | 0 | |
| 20 Jul 2026 | 58 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 16 | 1 | |
| 17 Aug 2026 | 17 | 2 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 9 | 1 | |
| 7 Sep 2026 | 17 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/n8n.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "N8n vulnerabilities", https://junglewise.ai/threats/technologies/n8n, 26 September 2026.