If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
RCE in the n8n Main Process via Path Traversal in MCP Node-Schema LoadingGHSA-6h4x-896x-fw5m published
Aug 5, 2026 by JubkeHigh -
SSRF Protection Bypass via OAuth2 Credential Token Exchange Reflects Internal Response BodyGHSA-c4f6-59xq-95ww published
Aug 5, 2026 by JubkeLow -
MongoDB Node NoSQL Injection in Find, Delete, and Aggregate Operations via Unescaped Expression InterpolationGHSA-953p-jm2c-8h5j published
Aug 5, 2026 by JubkeHigh -
Supabase Node PostgREST Filter Injection in Row Get Many, Delete, and Update OperationsGHSA-f4f3-2g67-4vhm published
Aug 5, 2026 by JubkeHigh -
Form Node Completion Page Sandbox CSP Bypass Leads to Stored XSSGHSA-rmr5-775f-jvm2 published
Aug 5, 2026 by JubkeHigh -
MCP create_workflow_from_code Accepts Cross-Project Credentials When Auth Type Is an ExpressionGHSA-vfrj-582q-mvcp published
Aug 5, 2026 by JubkeModerate -
Edit Image Node Injection Enables Blind SSRFGHSA-233r-fpgw-fx8x published
Aug 5, 2026 by JubkeModerate -
Resource Locator Link Preview Expression Injection Allows Cross-User Script ExecutionGHSA-fh4c-9rr2-p7qc published
Aug 5, 2026 by JubkeHigh -
GraphQL Node Raw Error Re-throw Leaks Decrypted Credential Headers into Persisted Execution DataGHSA-9fqj-7wc5-cwhx published
Aug 5, 2026 by JubkeHigh -
JavaScript Task Runner VM Sandbox Escape via EventEmitter Prototype Pollution Leads to Remote Code ExecutionGHSA-m3hg-p5r9-fg9h published
Aug 5, 2026 by JubkeHigh
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database