Security: n8n-io/n8n
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
MongoDB Node NoSQL Injection in Find, Delete, and Aggregate Operations via Unescaped Expression InterpolationGHSA-953p-jm2c-8h5j published
Aug 5, 2026 by JubkeHigh -
Supabase Node PostgREST Filter Injection in Row Get Many, Delete, and Update OperationsGHSA-f4f3-2g67-4vhm published
Aug 5, 2026 by JubkeHigh -
Form Node Completion Page Sandbox CSP Bypass Leads to Stored XSSGHSA-rmr5-775f-jvm2 published
Aug 5, 2026 by JubkeHigh -
MCP create_workflow_from_code Accepts Cross-Project Credentials When Auth Type Is an ExpressionGHSA-vfrj-582q-mvcp published
Aug 5, 2026 by JubkeModerate -
Edit Image Node Injection Enables Blind SSRFGHSA-233r-fpgw-fx8x published
Aug 5, 2026 by JubkeModerate -
Resource Locator Link Preview Expression Injection Allows Cross-User Script ExecutionGHSA-fh4c-9rr2-p7qc published
Aug 5, 2026 by JubkeHigh -
GraphQL Node Raw Error Re-throw Leaks Decrypted Credential Headers into Persisted Execution DataGHSA-9fqj-7wc5-cwhx published
Aug 5, 2026 by JubkeHigh -
JavaScript Task Runner VM Sandbox Escape via EventEmitter Prototype Pollution Leads to Remote Code ExecutionGHSA-m3hg-p5r9-fg9h published
Aug 5, 2026 by JubkeHigh -
Custom-role deletion's reassignment path bypasses project-scoped authorizationGHSA-xhmh-8fgr-xqhj published
Aug 5, 2026 by JubkeHigh -
Snowflake Node Arbitrary File Read and Write via Client-Side CommandsGHSA-r4j2-j3wm-q689 published
Aug 5, 2026 by JubkeHigh