n8n vulnerabilities
24 CVEs tracked
n8n appears in our reports as a workflow automation platform with multiple critical vulnerabilities disclosed. Key themes include bypassing domain restrictions (CVE-2026-65596), credential exposure (CVE-2026-65599, CVE-2026-65589), Sandbox escapes (CVE-2026-65590, DOM-based XSS via CVE-2026-65597/65592), and privilege escalation (CVE-2026-65016). Some flaws, like the TOCTOU race condition in Git operations (CVE-2026-65598) and leaked PEM keys, allow exploitation by authenticated users, posing insider threats. Defenders must urgently update to versions 1.123.64, 2.29.8, and 2.30.1, paying special attention to SSO role provisioning (global:owner) and plaintext secrets in workflow execution records.
Azərbaycanca: n8n, son hesabatlarda bir sıra kritik zəifliklərin aşkarlandığı iş axını avtomatlaşdırma platforması kimi diqqət mərkəzindədir. Əsas mövzular domen məhdudiyyətlərinin yan keçilməsi (CVE-2026-65596), etimadnamələrin ifşası (CVE-2026-65599, CVE-2026-65589), Sandbox mühitindən qaçış (CVE-2026-65590, CVE-2026-65597/65592 ilə DOM-based XSS) və imtiyaz artımıdır (CVE-2026-65016). Bəzi zəifliklər, məsələn, Git əməliyyatlarında TOCTOU yarış şəraiti (CVE-2026-65598) və məxfiliyi pozulmuş PEM açarları, daxili təhlükə yaradan autentifikasiyalı istifadəçilər tərəfindən istismara imkan verir. Müdafiəçilər 1.123.64, 2.29.8 və 2.30.1 versiyalarına təcili yeniləməyə, xüsusilə SSO rollarının təyin edilməsi (global:owner) və iş axını icra qeydlərində düz mətn sirlərin ifşasına diqqət yetirməlidirlər.
This vendor's CVEs24
- CVE-2026-72773EPSS 0.38%
- CVE-2026-72771EPSS 0.21%
- CVE-2026-72770EPSS 0.47%
- CVE-2026-72769EPSS 0.25%
- CVE-2026-72767EPSS 0.39%
- CVE-2026-72766EPSS 0.27%
- CVE-2026-72764EPSS 0.37%
- CVE-2026-72763EPSS 0.21%
- CVE-2026-72762EPSS 0.20%
- CVE-2026-72750EPSS 0.26%
- CVE-2026-72749EPSS 0.31%
- CVE-2026-65599EPSS 0.15%
- CVE-2026-65598EPSS 0.25%
- CVE-2026-65597EPSS 0.21%
- CVE-2026-65596EPSS 0.21%
- CVE-2026-65595EPSS 0.48%
- CVE-2026-65592EPSS 0.17%
- CVE-2026-65591EPSS 0.48%
- CVE-2026-65590EPSS 0.32%
- CVE-2026-65589EPSS 0.37%
- CVE-2026-65016EPSS 0.31%
- CVE-2026-65014EPSS 0.33%
- CVE-2026-35219EPSS 0.27%
- CVE-2026-27577EPSS 10%
This hub is built from skopnix's own reporting on n8n: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.