{"schema_version":1,"title":"N8n vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 247 vulnerabilities in N8n: 0 in the last 7 days and 149 in the last 90 days, 15 of them critical and 1 exploited in the wild. The most recent, CVE-2026-92588, was published on 16 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/n8n","json_url":"https://junglewise.ai/threats/vendors/n8n.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/n8n","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":73,"all_time":247,"critical":15,"exploited":1,"last_7_days":0,"last_30_days":28,"last_90_days":149,"last_365_days":236},"latest":[{"cve":"CVE-2026-92588","cvss":4.4,"epss":0.0032,"slug":"cve-2026-92588-n8n-source-control-push-improper-authorization-for-cross-project","title":"n8n source control push improper authorization for cross-project deletion","severity":"medium","exploited":false,"published_at":"2026-09-16T22:18:29.447+00:00","url":"https://junglewise.ai/threats/cve-2026-92588-n8n-source-control-push-improper-authorization-for-cross-project"},{"cve":"CVE-2026-92587","cvss":5,"epss":0.0031,"slug":"cve-2026-92587-n8n-git-node-sandbox-escape-via-relative-url-path-traversal","title":"n8n Git node sandbox escape via relative URL path traversal","severity":"medium","exploited":false,"published_at":"2026-09-16T22:18:29.293+00:00","url":"https://junglewise.ai/threats/cve-2026-92587-n8n-git-node-sandbox-escape-via-relative-url-path-traversal"},{"cve":"CVE-2026-86996","cvss":5.4,"epss":0.0029,"slug":"cve-2026-86996-n8n-agent-workflow-tool-bypasses-sub-workflow-caller-policy","title":"n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by wa","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:18.24+00:00","url":"https://junglewise.ai/threats/cve-2026-86996-n8n-agent-workflow-tool-bypasses-sub-workflow-caller-policy"},{"cve":"CVE-2026-86995","cvss":4.3,"epss":0.0041,"slug":"cve-2026-86995-n8n-git-node-config-bypass-enables-local-repository-read","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter f","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:18.103+00:00","url":"https://junglewise.ai/threats/cve-2026-86995-n8n-git-node-config-bypass-enables-local-repository-read"},{"cve":"CVE-2026-86994","cvss":4.3,"epss":0.0034,"slug":"cve-2026-86994-n8n-missing-authorization-in-active-workflows-endpoint","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned ever","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:17.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86994-n8n-missing-authorization-in-active-workflows-endpoint"},{"cve":"CVE-2026-86993","cvss":4.9,"epss":0.0046,"slug":"cve-2026-86993-n8n-log-streaming-credentials-unauthorized-access","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:17.81+00:00","url":"https://junglewise.ai/threats/cve-2026-86993-n8n-log-streaming-credentials-unauthorized-access"},{"cve":"CVE-2026-86085","cvss":4.9,"epss":0.0044,"slug":"cve-2026-86085-n8n-missing-authorization-in-role-assignment-endpoints","title":"n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assi","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:17.67+00:00","url":"https://junglewise.ai/threats/cve-2026-86085-n8n-missing-authorization-in-role-assignment-endpoints"},{"cve":"CVE-2026-86084","cvss":5.5,"epss":0.0046,"slug":"cve-2026-86084-n8n-authentication-bypass-via-disabled-oidc-sso-endpoints","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints comp","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:17.527+00:00","url":"https://junglewise.ai/threats/cve-2026-86084-n8n-authentication-bypass-via-disabled-oidc-sso-endpoints"},{"cve":"CVE-2026-86083","cvss":8.8,"epss":0.0066,"slug":"cve-2026-86083-n8n-expression-sandbox-escape-in-legacy-engine-via-json-stringify","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source tex","severity":"high","exploited":false,"published_at":"2026-09-08T22:19:17.383+00:00","url":"https://junglewise.ai/threats/cve-2026-86083-n8n-expression-sandbox-escape-in-legacy-engine-via-json-stringify"},{"cve":"CVE-2026-86082","cvss":6.5,"epss":0.0042,"slug":"cve-2026-86082-n8n-openai-chat-model-domain-restriction-bypass-in-model-search","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential al","severity":"high","exploited":false,"published_at":"2026-09-08T22:19:17.24+00:00","url":"https://junglewise.ai/threats/cve-2026-86082-n8n-openai-chat-model-domain-restriction-bypass-in-model-search"},{"cve":"CVE-2026-86081","cvss":4,"epss":0.0056,"slug":"cve-2026-86081-n8n-regular-expression-denial-of-service-in-git-node-file-pattern","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker","severity":"high","exploited":false,"published_at":"2026-09-08T22:19:17.093+00:00","url":"https://junglewise.ai/threats/cve-2026-86081-n8n-regular-expression-denial-of-service-in-git-node-file-pattern"},{"cve":"CVE-2026-86080","cvss":5.3,"epss":0.0026,"slug":"cve-2026-86080-n8n-github-trigger-cryptographic-signature-verification-fail-open","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:16.953+00:00","url":"https://junglewise.ai/threats/cve-2026-86080-n8n-github-trigger-cryptographic-signature-verification-fail-open"},{"cve":"CVE-2026-86079","cvss":6.5,"epss":0.0049,"slug":"cve-2026-86079-n8n-path-injection-in-elasticsearch-and-elasticsecurity-nodes","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes inter","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:16.813+00:00","url":"https://junglewise.ai/threats/cve-2026-86079-n8n-path-injection-in-elasticsearch-and-elasticsecurity-nodes"},{"cve":"CVE-2026-86078","cvss":6.5,"epss":0.0059,"slug":"cve-2026-86078-n8n-prototype-pollution-in-workflow-summary","title":"n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connect","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:16.677+00:00","url":"https://junglewise.ai/threats/cve-2026-86078-n8n-prototype-pollution-in-workflow-summary"},{"cve":"CVE-2026-86077","cvss":6.5,"epss":0.0043,"slug":"cve-2026-86077-n8n-approval-gate-bypass-via-reused-resumetoken-in-chat-websocket","title":"n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed","severity":"medium","exploited":false,"published_at":"2026-09-08T22:19:16.533+00:00","url":"https://junglewise.ai/threats/cve-2026-86077-n8n-approval-gate-bypass-via-reused-resumetoken-in-chat-websocket"},{"cve":"CVE-2026-86076","cvss":8.8,"epss":0.0079,"slug":"cve-2026-86076-n8n-expression-sandbox-escape-via-class-field-sanitizer-rebinding","title":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved throug","severity":"high","exploited":false,"published_at":"2026-09-08T22:19:16.387+00:00","url":"https://junglewise.ai/threats/cve-2026-86076-n8n-expression-sandbox-escape-via-class-field-sanitizer-rebinding"},{"cve":"CVE-2026-86075","cvss":7.5,"epss":0.0061,"slug":"cve-2026-86075-n8n-unauthenticated-storage-exhaustion-via-oauth-registration","title":"n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redir","severity":"high","exploited":false,"published_at":"2026-09-08T22:19:16.25+00:00","url":"https://junglewise.ai/threats/cve-2026-86075-n8n-unauthenticated-storage-exhaustion-via-oauth-registration"},{"cve":"CVE-2026-86074","cvss":7.1,"epss":0.0038,"slug":"cve-2026-86074-n8n-instance-ai-credential-setup-ssrf-via-unvalidated-probe-url","title":"n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential","severity":"high","exploited":false,"published_at":"2026-09-08T18:21:14.273+00:00","url":"https://junglewise.ai/threats/cve-2026-86074-n8n-instance-ai-credential-setup-ssrf-via-unvalidated-probe-url"},{"cve":"CVE-2026-86073","cvss":7.6,"epss":0.0039,"slug":"cve-2026-86073-n8n-oauth-consent-bypass-via-unbound-refresh-token","title":"n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first","severity":"high","exploited":false,"published_at":"2026-09-08T17:18:39.167+00:00","url":"https://junglewise.ai/threats/cve-2026-86073-n8n-oauth-consent-bypass-via-unbound-refresh-token"},{"cve":"CVE-2026-85173","cvss":4.3,"epss":0.0035,"slug":"cve-2026-85173-n8n-insights-api-missing-per-project-authorization","title":"n8n Insights API missing per-project authorization","severity":"medium","exploited":false,"published_at":"2026-09-03T13:06:24.99+00:00","url":"https://junglewise.ai/threats/cve-2026-85173-n8n-insights-api-missing-per-project-authorization"},{"cve":"CVE-2026-85172","cvss":6.4,"epss":0.0026,"slug":"cve-2026-85172-n8n-server-side-request-forgery-in-legacy-request-helper","title":"n8n server-side request forgery in legacy request helper","severity":"medium","exploited":false,"published_at":"2026-09-03T13:06:24.843+00:00","url":"https://junglewise.ai/threats/cve-2026-85172-n8n-server-side-request-forgery-in-legacy-request-helper"},{"cve":"CVE-2026-85171","cvss":6.5,"epss":0.0056,"slug":"cve-2026-85171-n8n-strapi-seatable-mailcheck-credential-exposure-in-error-logs","title":"n8n Strapi SeaTable Mailcheck credential exposure in error logs","severity":"medium","exploited":false,"published_at":"2026-09-03T13:06:24.703+00:00","url":"https://junglewise.ai/threats/cve-2026-85171-n8n-strapi-seatable-mailcheck-credential-exposure-in-error-logs"},{"cve":"CVE-2026-85170","cvss":6.5,"epss":0.004,"slug":"cve-2026-85170-n8n-gmail-and-brevo-nodes-local-file-read-and-ssrf","title":"n8n Gmail and Brevo nodes local file read and SSRF","severity":"medium","exploited":false,"published_at":"2026-09-03T13:06:24.54+00:00","url":"https://junglewise.ai/threats/cve-2026-85170-n8n-gmail-and-brevo-nodes-local-file-read-and-ssrf"},{"cve":"CVE-2026-85169","cvss":8.8,"epss":0.0088,"slug":"cve-2026-85169-n8n-expression-sandbox-escape-in-fromai-handler","title":"n8n expression sandbox escape in $fromAI handler","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:24.31+00:00","url":"https://junglewise.ai/threats/cve-2026-85169-n8n-expression-sandbox-escape-in-fromai-handler"},{"cve":"CVE-2026-85168","cvss":8.8,"epss":0.0084,"slug":"cve-2026-85168-n8n-git-node-remote-code-execution-via-incomplete-config","title":"n8n Git node remote code execution via incomplete config neutralization","severity":"high","exploited":false,"published_at":"2026-09-03T13:06:24.15+00:00","url":"https://junglewise.ai/threats/cve-2026-85168-n8n-git-node-remote-code-execution-via-incomplete-config"}],"vendor":{"hub":true,"name":"N8n","slug":"n8n","homepage":"https://n8n.io","description":"Low-code workflow automation platform for integrating applications and services.","url":"https://junglewise.ai/threats/vendors/n8n"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":18},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":57},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":16},{"week":"2026-08-17","critical":2,"exploited":0,"vulnerabilities":17},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":9},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":17},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-68613","cvss":3.1,"epss":0.9899,"slug":"cve-2025-68613-n8n-remote-code-execution-in-workflow-expression-evaluation","title":"n8n Vulnerable to Remote Code Execution via Expression Injection","severity":"critical","exploited":true,"published_at":"2025-12-22T16:19:13+00:00","url":"https://junglewise.ai/threats/cve-2025-68613-n8n-remote-code-execution-in-workflow-expression-evaluation"},{"cve":"CVE-2026-54309","cvss":10,"epss":0.0055,"slug":"cve-2026-54309-n8n-missing-authentication-in-mcp-browser-http-transport","title":"n8n missing authentication in MCP Browser HTTP transport","severity":"critical","exploited":false,"published_at":"2026-06-23T16:17:01.86+00:00","url":"https://junglewise.ai/threats/cve-2026-54309-n8n-missing-authentication-in-mcp-browser-http-transport"},{"cve":"CVE-2026-27577","cvss":9.9,"epss":0.0101,"slug":"cve-2026-27577-n8n-code-injection-in-expression-evaluation","title":"n8n code injection in expression evaluation","severity":"critical","exploited":false,"published_at":"2026-02-25T23:16:21.387+00:00","url":"https://junglewise.ai/threats/cve-2026-27577-n8n-code-injection-in-expression-evaluation"},{"cve":"CVE-2026-72765","cvss":9.9,"epss":0.0086,"slug":"cve-2026-72765-n8n-expression-sandbox-escape-via-arrow-functions","title":"n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission t","severity":"critical","exploited":false,"published_at":"2026-08-11T13:19:06.67+00:00","url":"https://junglewise.ai/threats/cve-2026-72765-n8n-expression-sandbox-escape-via-arrow-functions"},{"cve":"CVE-2026-85165","cvss":9.9,"epss":0.0057,"slug":"cve-2026-85165-n8n-expression-sandbox-bypass-in-spread-and-computed-key","title":"n8n expression sandbox bypass in spread and computed-key evaluation","severity":"critical","exploited":false,"published_at":"2026-09-03T13:06:23.71+00:00","url":"https://junglewise.ai/threats/cve-2026-85165-n8n-expression-sandbox-bypass-in-spread-and-computed-key"},{"cve":"CVE-2026-54310","cvss":9.9,"epss":0.0055,"slug":"cve-2026-54310-n8n-sql-injection-in-timescaledb-and-postgres-v1-nodes","title":"n8n SQL injection in TimescaleDB and Postgres v1 nodes","severity":"critical","exploited":false,"published_at":"2026-06-23T16:17:01.99+00:00","url":"https://junglewise.ai/threats/cve-2026-54310-n8n-sql-injection-in-timescaledb-and-postgres-v1-nodes"},{"cve":"CVE-2026-44791","cvss":9.9,"epss":0.0054,"slug":"cve-2026-44791-n8n-prototype-pollution-in-xml-node-leading-to-rce","title":"n8n prototype pollution in XML node leading to RCE","severity":"critical","exploited":false,"published_at":"2026-06-23T17:16:59.547+00:00","url":"https://junglewise.ai/threats/cve-2026-44791-n8n-prototype-pollution-in-xml-node-leading-to-rce"},{"cve":"CVE-2026-44789","cvss":9.9,"epss":0.0053,"slug":"cve-2026-44789-n8n-prototype-pollution-in-http-request-node","title":"n8n prototype pollution in HTTP Request node","severity":"critical","exploited":false,"published_at":"2026-06-23T17:16:59.29+00:00","url":"https://junglewise.ai/threats/cve-2026-44789-n8n-prototype-pollution-in-http-request-node"},{"cve":"CVE-2026-54305","cvss":9.9,"epss":0.0037,"slug":"cve-2026-54305-n8n-improper-access-control-in-dynamic-credentials-ee-endpoints","title":"n8n improper access control in Dynamic Credentials EE endpoints","severity":"critical","exploited":false,"published_at":"2026-06-23T17:17:06.743+00:00","url":"https://junglewise.ai/threats/cve-2026-54305-n8n-improper-access-control-in-dynamic-credentials-ee-endpoints"},{"cve":"CVE-2026-77071","cvss":9.8,"epss":0.0062,"slug":"cve-2026-77071-n8n-supabase-node-postgrest-filter-injection-in-row-operations","title":"n8n Supabase node PostgREST filter injection in Row operations","severity":"critical","exploited":false,"published_at":"2026-08-20T12:16:38.353+00:00","url":"https://junglewise.ai/threats/cve-2026-77071-n8n-supabase-node-postgrest-filter-injection-in-row-operations"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"N8n","slug":"n8n","vulnerabilities":249,"url":"https://junglewise.ai/threats/technologies/n8n"},{"name":"N8n Computer-Use","slug":"computer-use","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/computer-use"}]}