CVE Tools

N8N

165 CVEs tracked since 2025. Since Dec 2025, 1 of them reached CISA KEV.

N8N CVEs per month

Dec 2025 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
N8N CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-1251
2026-0160
2026-02180
2026-03110
2026-04null or fewer
2026-05120
2026-06280
2026-07330
2026-08270
2026-09250

Products

The products that kept showing up in N8N's monthly top three, with their CVEs summed over those months.

  1. N8N1659 months

Latest CVEs

The 15 most recently published vulnerabilities affecting N8N.

  1. CVE-2026-86075n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint7.5
  2. CVE-2026-86076n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution8.8
  3. CVE-2026-86077n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket6.5
  4. CVE-2026-86078n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service6.5
  5. CVE-2026-86079n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers6.5
  6. CVE-2026-86080n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open5.3
  7. CVE-2026-86082n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node6.5
  8. CVE-2026-86083n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution8.8
  9. CVE-2026-86084n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions5.5
  10. CVE-2026-86085n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints4.9
  11. CVE-2026-86993n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check4.9
  12. CVE-2026-86994n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter4.3
  13. CVE-2026-86995n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read4.3
  14. CVE-2026-86996n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy5.4
  15. CVE-2026-86074n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content7.1

The record

Peak rank
#28 in Jul 2026
Busiest month shown
Jul 2026, 33 CVEs
Months with a KEV entry
1 since Dec 2025
Monthly snapshots
9 since 2025
N8N's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store