Security: n8n-io/n8n
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Expression Sandbox SpreadElement Bypass Enables Persistent Cross-Evaluation Native Object MutationGHSA-fg85-4wv2-p98j published
Aug 19, 2026 by JubkeHigh -
Shared-Workflow Editor Can Exfiltrate Credentials via Workflow Tool Node Inline Sub-WorkflowGHSA-4r56-g65c-fm83 published
Aug 19, 2026 by JubkeHigh -
Query Injection in Elasticsearch and Google Cloud Firestore Nodes via Unescaped Expression InterpolationGHSA-wxwj-8wv6-vpw2 published
Aug 19, 2026 by JubkeModerate -
Git Node Remote Code Execution via Incomplete Repository-Local Configuration NeutralizationGHSA-mwp5-2m32-r54h published
Aug 19, 2026 by JubkeHigh -
Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCEGHSA-9x83-43r8-5hwc published
Aug 19, 2026 by JubkeHigh -
Gmail and Brevo nodes accept non-string content, enabling local file read and SSRFGHSA-95ph-833c-4wrp published
Aug 19, 2026 by JubkeHigh -
Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error DataGHSA-vrv8-j27g-g7cr published
Aug 19, 2026 by JubkeHigh -
Legacy Request Helper SSRF Check Validates uri While Axios Dispatches urlGHSA-jp9j-jr97-w9pj published
Aug 19, 2026 by JubkeModerate -
Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across ProjectsGHSA-jmmj-93rg-6j39 published
Aug 19, 2026 by JubkeModerate -
RCE in the n8n Main Process via Path Traversal in MCP Node-Schema LoadingGHSA-6h4x-896x-fw5m published
Aug 5, 2026 by JubkeHigh