Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

N8n

First CVE: May 10, 2023Active for: 3 yearsTotal CVEs: 112
73.2
VTI Score
TOP TARGET

N8n is a workflow automation and integration platform whose relatively narrow product scope belies its prominence in deployment across business-process automation, data-pipeline orchestration, and API-bridge scenarios. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in code-injection, cross-site scripting, SQL-injection, and authorization-bypass weakness classes that reflect the platform's requirement to execute user-defined workflows and handle dynamic data inputs. The exposure is amplified by N8n's reliance on open-source components such as FastAPI, Pydantic, and Uvicorn, where flaws in the underlying libraries can propagate into the platform itself. Defenders should treat N8n instances, especially internet-reachable deployments and those processing sensitive workflow data, as high-value targets and prioritize security updates for both the platform and its dependencies; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
112
Total CVEs
More Total CVEs than 99% of tracked vendors
9.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by N8n over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 2023
3 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (112 CVEs).

112 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-68613HIGH
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnera
Dec 19, 20258.899YESYES
CVE-2026-21858CRITICAL
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of
Jan 8, 202610.086NOYES
CVE-2026-21877CRITICAL
n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could
Jan 8, 20269.951NOYES
CVE-2026-1470CRITICAL
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configur
Jan 27, 20269.946NONO
CVE-2025-68668CRITICAL
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenti
Dec 26, 20259.944NONO
CVE-2026-27577CRITICAL
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and
Feb 25, 20269.941NONO
CVE-2026-0863CRITICAL
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying
Jan 18, 20269.941NONO
CVE-2026-54305CRITICAL
n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n
Jun 23, 20269.940NONO
CVE-2026-44789CRITICAL
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global
Jun 23, 20269.939NONO
CVE-2026-56348CRITICAL
n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP
Jun 22, 20269.939NONO
View all 112 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products112 CVEs
42%
35%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network112 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low101 (90.2%)
High11 (9.8%)
Unknown0 (0.0%)
User Interaction
None92 (82.1%)
Unknown0 (0.0%)
Required20 (17.9%)
Privileges Required
Low87 (77.7%)
High2 (1.8%)
None23 (20.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (112 CVEs).

CISA KEV
1 CVE
0.9% of CVEs· 99th percentile
Metasploit
1 CVE
0.9% of CVEs· 97th percentile
Nuclei
3 CVEs
2.7% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by N8n.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by N8n — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For N8n's Products

View all 4 CNAs →

Top CWEs