Loading...
Skip to main content
npm (Node.js)

n8n Security Analysis

n8n has 59 known security vulnerabilities in npm (Node.js). Upgrade to version 2.32.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

59 Vulnerabilities

Actively Exploited

CISA has confirmed this package has vulnerabilities under active exploitation. Prioritize updating immediately.

Recommended safe version: 2.32.1

Upgrading to 2.32.1 or later resolves all 59 known vulnerabilities in n8n. Run: npm install n8n@2.32.1

Is n8n in your project?

Check if you're affected and upgrade to 2.32.1 to stay secure.

59
Total
0
Critical
0
High
0
Medium
0
Low

Active Exploitation Warning

One or more vulnerabilities in this package are known to be actively exploited in the wild. Immediate action is recommended.

Vulnerabilities

59 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
CRITICAL
All versions1.120.4, 1.121.1
CVE-2026-42231
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
CRITICAL
All versions1.123.32, 2.18.1, 2.17.4
CVE-2026-44791
n8n Has an XML Node Prototype Pollution Patch Bypass
CRITICAL
All versions1.123.43, 2.22.1, 2.20.7
CVE-2026-44789
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CRITICAL
All versions1.123.43, 2.22.1, 2.20.7
CVE-2026-42232
n8n has XML Node Prototype Pollution that to RCE
CRITICAL
All versions2.18.1, 2.17.4, 1.123.32
CVE-2026-33696
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
CRITICAL
2.14.02.14.1, 2.13.3, 1.123.27
CVE-2026-33660
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
CRITICAL
2.14.02.14.1, 2.13.3, 1.123.27
CVE-2026-27577
n8n: Expression Sandbox Escape Leads to RCE
CRITICAL
All versions1.123.22, 2.9.3, 2.10.1
CVE-2026-27497
n8n has Potential Remote Code Execution via Merge Node
CRITICAL
All versions1.123.22, 2.9.3, 2.10.1
CVE-2026-27495
n8n has a Sandbox Escape in its JavaScript Task Runner
CRITICAL
All versions1.123.22, 2.9.3, 2.10.1
CVE-2026-1470
n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
CRITICAL
All versions1.123.17, 2.4.5, 2.5.1
CVE-2026-25056
n8n Merge Node has Arbitrary File Write leading to RCE
CRITICAL
All versions1.118.0, 2.4.0
CVE-2026-25053
n8n has OS Command Injection in Git Node
CRITICAL
All versions2.5.0, 1.123.10
CVE-2026-25052
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
CRITICAL
All versions2.5.0, 1.123.18
CVE-2026-25049
n8n Has Expression Escape Vulnerability Leading to RCE
CRITICAL
All versions1.123.17, 2.5.2
CVE-2026-21858
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
CRITICAL
All versions1.121.0
CVE-2026-21877
n8n Vulnerable to RCE via Arbitrary File Write
CRITICAL
All versions1.121.3
CVE-2025-68668
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
CRITICAL
All versions2.0.0
CVE-2025-65964
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
CRITICAL
All versions1.119.2
CVE-2026-27493
n8n has Unauthenticated Expression Evaluation via Form Node
CRITICAL
All versions1.123.22, 2.9.3, 2.10.1
CVE-2026-44790
n8n Has an Arbitrary File Read via Git Node
CRITICAL
All versions1.123.43, 2.22.1, 2.20.7
CVE-2026-21893
n8n Vulnerable to Command Injection in Community Package Installation
CRITICAL
All versions1.120.3
CVE-2026-27498
n8n has Arbitrary Command Execution via File Write and Git Operations
CRITICAL
All versions1.123.8, 2.2.0
CVE-2025-62726
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
HIGH
All versions1.113.0
CVE-2026-42235
n8n Vulnerable to XSS via MCP OAuth client
HIGH
All versions1.123.32, 2.18.1, 2.17.4
CVE-2026-54305
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
HIGH
All versions1.123.55, 2.26.2, 2.25.7
CVE-2026-33713
n8n has SQL Injection in Data Table Node via orderByColumn Expression
HIGH
2.14.01.123.26, 2.14.1, 2.13.3
CVE-2026-33663
n8n is Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
HIGH
2.14.01.123.27, 2.14.1, 2.13.3
CVE-2026-54309
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
HIGH
All versions2.26.2, 2.25.7
CVE-2026-27494
n8n has Arbitrary File Read via Python Code Node Sandbox Escape
HIGH
All versions1.123.22, 2.9.3, 2.10.1
CVE-2026-25055
n8n Vulnerable to Arbitrary File Write on Remote Systems via SSH Node
HIGH
All versions2.4.0, 1.123.12
CVE-2026-54307
n8n: Credential Exfiltration via Permission Bypass
HIGH
All versions1.123.55, 2.26.2, 2.25.7
CVE-2026-65591
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
HIGH
All versions1.123.64, 2.30.1, 2.29.8
CVE-2026-72763
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
HIGH
All versions1.123.67, 2.32.1, 2.31.5
CVE-2026-72772
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
HIGH
All versions2.32.1, 2.31.5
CVE-2026-65595
n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
HIGH
All versions2.30.1, 2.29.8
CVE-2026-72774
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
HIGH
All versions1.123.67, 2.32.1, 2.31.5
CVE-2026-44792
n8n Has a Source Control Pull SQL Injection
HIGH
All versions1.123.43, 2.21.1, 2.20.7
CVE-2026-72767
n8n: Authenticated code execution in the n8n Git node
HIGH
All versions1.123.67, 2.32.1, 2.31.5
CVE-2026-72765
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
HIGH
All versions2.32.1, 2.31.5
CVE-2026-59206
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
HIGH
All versions1.123.61, 2.28.1, 2.27.4
CVE-2026-65015
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
HIGH
All versions2.30.1, 2.29.8
CVE-2026-65016
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
HIGH
All versions1.123.64, 2.30.1, 2.29.8
CVE-2026-25051
n8n's Improper CSP Enforcement in Webhook Responses May Allow Stored XSS
HIGH
All versions1.123.2, 1.122.5
CVE-2026-65592
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
HIGH
All versions1.123.64, 2.30.1, 2.29.8
CVE-2026-65598
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
HIGH
All versions1.123.64, 2.30.1, 2.29.8
CVE-2025-71380
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
HIGH
All versionsNo fix available
CVE-2026-42226
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
HIGH
All versions2.17.5, 1.123.33
CVE-2026-42233
n8n has SQL Injection in Oracle Database Node via Limit Field
MEDIUM
All versions1.123.32, 2.18.1, 2.17.4
CVE-2026-72768
n8n: SSRF Protection Bypass via MCP Client Node
MEDIUM
All versions2.32.1, 2.31.5
CVE-2026-54310
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
MEDIUM
All versions2.26.2, 2.25.7
CVE-2026-72775
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
MEDIUM
All versions1.123.67, 2.32.1, 2.31.5
CVE-2026-72764
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
MEDIUM
All versions1.123.67, 2.32.1, 2.31.5
CVE-2026-72750
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
MEDIUM
All versions1.123.67, 2.32.1, 2.31.5
CVE-2026-59257
n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
MEDIUM
All versions1.123.61, 2.28.1, 2.27.4
CVE-2026-33749
n8n Vulnerable to XSS via Binary Data Inline HTML Rendering
MEDIUM
2.14.01.123.27, 2.14.1, 2.13.3
CVE-2026-56348
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
MEDIUM
All versions2.20.0
CVE-2026-65590
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
MEDIUM
All versions2.30.1, 2.29.8
CVE-2026-65593
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
MEDIUM
All versions1.123.64, 2.30.1, 2.29.8

About This Data

Vulnerability data for n8n is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related npm (Node.js) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of n8n.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed