If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
Improper File Access Controls Allow Arbitrary File Read by Authenticated UsersGHSA-gfvg-qv54-r4pc published
Feb 4, 2026 by csuermannCritical -
Improper CSP Enforcement in Webhook Responses May Allow Stored XSSGHSA-825q-w924-xhgx published
Feb 4, 2026 by csuermannHigh -
n8n Remote Code Execution via Expression InjectionGHSA-v98v-ff95-f3cp published
Dec 19, 2025 by csuermannCritical -
Unauthenticated File Access via Improper Webhook Request HandlingGHSA-v4pr-fm98-w9pg published
Jan 7, 2026 by csuermannCritical -
Remote Code Execution via Git Node Custom Pre-Commit HookGHSA-wpqc-h9wp-chmq published
Dec 8, 2025 by csuermannCritical -
Python Code Node Sandbox EscapeGHSA-mmgg-m5j7-f83h published
Feb 25, 2026 by JubkeCritical -
LDAP Email-Based Account Linking Allows Privilege Escalation and Account TakeoverGHSA-c545-x2rh-82fc published
Mar 25, 2026 by JubkeHigh -
Domain allowlist bypass enables credential exfiltrationGHSA-2xcx-75h9-vr9h published
Feb 4, 2026 by csuermannModerate -
Python sandbox escapeGHSA-8398-gmmx-564h published
Feb 4, 2026 by csuermannCritical -
Remote Code Execution via Git Node Pre-Commit HookGHSA-xgp7-7qjq-vg47 published
Oct 30, 2025 by csuermannHigh
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database