LIVE · cybersecurity feed
Live wire
vendor

N8n

45 CVEs published in the last four months and 1 stories. Exploited flaws first.

Critical12
High33
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-5430910criticaln8nn8n is an open source workflow automation platform.74d ago
CVE-2026-727659.9criticaln8nn8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation.25d ago
CVE-2026-447899.9criticaln8nn8n is an open source workflow automation platform.74d ago
CVE-2026-543059.9criticaln8nn8n is an open source workflow automation platform.74d ago
CVE-2026-543109.9criticaln8nn8n is an open source workflow automation platform.74d ago
CVE-2026-447919.9criticaln8nn8n is an open source workflow automation platform.74d ago
CVE-2026-655909.8criticaln8nn8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the45d ago
CVE-2026-770719.8criticaln8nn8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's16d ago
CVE-2026-770709.8criticaln8nn8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delet16d ago
CVE-2026-543079.6criticaln8nn8n is an open source workflow automation platform.74d ago
CVE-2026-563489.1criticaln8nn8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/optio75d ago
CVE-2026-447929criticaln8nn8n is an open source workflow automation platform.74d ago
CVE-2026-727758.8highn8nn8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which 25d ago
CVE-2026-447908.8highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-592578.8highn8nn8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the leg59d ago
CVE-2026-650158.8highn8nn8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-ex45d ago
CVE-2026-650168.8highn8nn8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO in45d ago
CVE-2026-655918.8highn8nn8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler.45d ago
CVE-2026-655958.8highn8nn8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module re45d ago
CVE-2026-727508.8highn8nn8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Que25d ago
CVE-2026-770688.8highn8nn8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk 16d ago
CVE-2026-770798.8highn8nn8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) p16d ago
CVE-2026-770808.8highn8nn8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerab16d ago
CVE-2026-770848.8highn8nn8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node.16d ago
CVE-2026-543128.5highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-494448.5highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-727688.3highn8nn8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client25d ago
CVE-2026-563518.2highn8nn8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that73d ago
CVE-2026-457328.1highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-655968.1highn8nn8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-ba45d ago
CVE-2026-543117.7highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-727737.7highn8nn8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search 25d ago
CVE-2026-543137.7highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-543047.7highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-494657.7highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-770777.6highn8nn8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape.16d ago
CVE-2026-770727.6highn8nn8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's co16d ago
CVE-2026-543147.5highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-655987.5highn8nn8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that al45d ago
CVE-2026-727667.5highn8nn8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Sen25d ago
CVE-2026-567767.4highn8nn8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-59d ago
CVE-2026-770757.3highn8nn8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in 16d ago
CVE-2026-543087.2highn8nn8n is an open source workflow automation platform.74d ago
CVE-2026-770817.1highn8nn8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL nod16d ago
CVE-2026-592067.1highn8nn8n is an open source workflow automation platform.58d ago

Filter the full tracker by N8n

Our coverage of N8n

malwarehigh

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

This week's cybersecurity landscape features several significant threats, including the abuse of legitimate signed drivers for kernel operations, a large-scale cyber espionage campaign by an Iran-based group targeting universities, and malware utilizing DLL sideloading. Additionally, advancements in AI safety are being explored by OpenAI and Google, while a new service, Kriminal AI, offers unfiltered AI responses, raising concerns about misuse. Apple is also modifying its App Tracking Transparency feature in Germany following regulatory scrutiny.