If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
Unauthenticated Expression Evaluation via Form NodeGHSA-75g8-rv7v-32f7 published
Feb 25, 2026 by JubkeHigh -
LDAP Filter Injection in LDAP NodeGHSA-w83q-mcmx-mh42 published
Mar 25, 2026 by JubkeModerate -
Legacy ExecuteWorkflow Node Bypassed File Path RestrictionsGHSA-2vx9-7wpg-88jq published
May 13, 2026 by JubkeModerate -
In-Process Memory Disclosure in Task RunnerGHSA-xvh5-5qg4-x9qp published
Mar 25, 2026 by JubkeHigh -
SSO Enforcement BypassGHSA-vjf3-2gpj-233v published
Feb 25, 2026 by JubkeModerate -
Sandbox Escape in JavaScript Task RunnerGHSA-jjpj-p2wh-qf23 published
Feb 25, 2026 by JubkeCritical -
n8n Guardrail Node BypassGHSA-fvfv-ppw4-7h2w published
Feb 25, 2026 by JubkeModerate -
External Secrets Authorization Bypass in Credential SavingGHSA-fxcw-h3qj-8m8p published
Mar 25, 2026 by JubkeHigh -
XSS in Credential Management FlowGHSA-364x-8g5j-x2pr published
Mar 25, 2026 by JubkeModerate -
XSS and Open Redirect in Form NodeGHSA-w673-8fjw-457c published
Mar 25, 2026 by JubkeModerate
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database