N8n is a workflow automation and integration platform whose relatively narrow product scope belies its prominence in deployment across business-process automation, data-pipeline orchestration, and API-bridge scenarios. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in code-injection, cross-site scripting, SQL-injection, and authorization-bypass weakness classes that reflect the platform's requirement to execute user-defined workflows and handle dynamic data inputs. The exposure is amplified by N8n's reliance on open-source components such as FastAPI, Pydantic, and Uvicorn, where flaws in the underlying libraries can propagate into the platform itself. Defenders should treat N8n instances, especially internet-reachable deployments and those processing sensitive workflow data, as high-value targets and prioritize security updates for both the platform and its dependencies; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by N8n over time
Signals from CVEs in this vendor scope (112 CVEs).
112 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68613HIGH n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnera | Dec 19, 2025 | 8.8 | 99 | YES | YES |
CVE-2026-21858CRITICAL n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of | Jan 8, 2026 | 10.0 | 86 | NO | YES |
CVE-2026-21877CRITICAL n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could | Jan 8, 2026 | 9.9 | 51 | NO | YES |
CVE-2026-1470CRITICAL n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configur | Jan 27, 2026 | 9.9 | 46 | NO | NO |
CVE-2025-68668CRITICAL n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenti | Dec 26, 2025 | 9.9 | 44 | NO | NO |
CVE-2026-27577CRITICAL n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and | Feb 25, 2026 | 9.9 | 41 | NO | NO |
CVE-2026-0863CRITICAL Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying | Jan 18, 2026 | 9.9 | 41 | NO | NO |
CVE-2026-54305CRITICAL n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n | Jun 23, 2026 | 9.9 | 40 | NO | NO |
CVE-2026-44789CRITICAL n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global | Jun 23, 2026 | 9.9 | 39 | NO | NO |
CVE-2026-56348CRITICAL n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP | Jun 22, 2026 | 9.9 | 39 | NO | NO |
Signals from CVEs in this vendor scope (112 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by N8n.
Media articles that mention a CVE ID that affects a product developed by N8n — matched by CVE ID, not by vendor name.