Direct Vulnerabilities

Known vulnerabilities in the n8n package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Race Condition

<2.32.5-r0
  • L
CVE-2026-13676

<2.32.5-r0
  • L
Use of Less Trusted Source

<2.32.5-r0
  • L
Cross-site Scripting (XSS)

<2.32.5-r0
  • M
Cross-site Scripting (XSS)

<2.29.8-r0
  • L
Authorization Bypass Through User-Controlled Key

<2.27.4-r0
  • L
GHSA-vhf8-cg2h-cg3p

<2.31.5-r0
  • M
Cleartext Storage of Sensitive Information

<2.29.8-r0
  • H
Improper Privilege Management

<2.29.8-r0
  • H
Expression Language Injection

<2.29.8-r0
  • C
OS Command Injection

<2.29.8-r0
  • L
GHSA-9cmh-xcqm-5hqr

<2.31.5-r0
  • L
GHSA-xmc9-4f2h-jf9c

<2.31.5-r0
  • H
Time-of-check Time-of-use (TOCTOU)

<2.29.8-r0
  • L
GHSA-64xh-79j6-r5v8

<2.31.5-r0
  • M
Cross-site Scripting (XSS)

<2.29.8-r0
  • L
GHSA-652q-gvq3-74qv

<2.31.5-r0
  • L
GHSA-jqwr-vx3p-r266

<2.31.5-r0
  • L
GHSA-6qc9-mqvw-jg7x

<2.31.5-r0
  • L
GHSA-8342-988q-86cr

<2.31.5-r0
  • L
GHSA-gv7g-jm28-cr3m

<2.31.5-r0
  • M
Server-Side Request Forgery (SSRF)

<2.29.8-r0
  • L
GHSA-gf29-4f56-r2jf

<2.31.5-r0
  • H
Authorization Bypass Through User-Controlled Key

<2.29.8-r0
  • L
GHSA-rcv6-pvrj-4xcg

<2.31.5-r0
  • L
GHSA-cj9h-qx8g-pq2g

<2.31.5-r0
  • L
GHSA-pf2q-pxhf-hgmw

<2.31.5-r0
  • L
GHSA-hx4h-vr3m-45vh

<2.31.5-r0
  • L
GHSA-xwx6-jjhv-84p8

<2.31.5-r0
  • H
Incorrect Authorization

<2.29.8-r0
  • M
Information Exposure Through Log Files

<2.29.8-r0
  • H
Incorrect Authorization

<2.29.8-r0
  • L
GHSA-2x35-3fw4-9jr4

<2.31.5-r0
  • M
Incorrect Authorization

<2.29.8-r0
  • M
Missing Authentication for Critical Function

<2.27.4-r0
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
CVE-2026-6733

<2.31.5-r0
  • L
Uncaught Exception

<2.31.5-r0
  • L
CVE-2026-9679

<2.31.5-r0
  • L
CVE-2026-11525

<2.31.5-r0
  • L
GHSA-hcpx-6fm6-wx23

<2.28.3-r0
  • L
GHSA-42h9-826w-cgv3

<2.28.3-r0
  • L
GHSA-pmv8-rq9r-6j72

<2.28.3-r0
  • L
GHSA-xj6q-8x83-jv6g

<2.28.3-r0
  • L
GHSA-7q8q-rj6j-mhjq

<2.28.3-r0
  • L
GHSA-mmx7-hfxf-jppx

<2.28.3-r0
  • L
GHSA-gcfj-64vw-6mp9

<2.28.3-r0
  • L
GHSA-f4gw-2p7v-4548

<2.28.3-r0
  • L
GHSA-mwf2-3pr3-8698

<2.28.3-r0
  • L
GHSA-jqh4-m9w3-8hp9

<2.28.3-r0
  • L
Authorization Bypass Through User-Controlled Key

<2.27.4-r0
  • L
Allocation of Resources Without Limits or Throttling

<2.28.3-r0
  • L
Information Exposure

<2.27.4-r0
  • L
Inefficient Regular Expression Complexity

<2.32.5-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<2.27.4-r0
  • L
Protection Mechanism Failure

<2.27.4-r0
  • M
Improper Authentication

<2.27.4-r0
  • M
Incorrect Authorization

<2.25.7-r0
  • L
Authorization Bypass Through User-Controlled Key

<2.28.3-r0
  • H
SQL Injection

<2.27.4-r0
  • M
Incorrect Authorization

<2.25.7-r0
  • H
Incorrect Authorization

<2.25.7-r0
  • M
Incomplete Blacklist

<2.25.7-r0
  • H
CVE-2026-5038

<2.28.3-r0
  • L
Improper Input Validation

<2.28.3-r0
  • L
Uncontrolled Recursion

<2.28.3-r0
  • L
Allocation of Resources Without Limits or Throttling

<2.28.3-r0
  • L
Algorithmic Complexity

<2.28.3-r0
  • L
CVE-2026-9678

<2.28.3-r0
  • L
SQL Injection

<2.22.6-r0
  • H
Authorization Bypass Through User-Controlled Key

<2.22.6-r0
  • L
Use of Less Trusted Source

<2.27.3-r0
  • L
Improper Encoding or Escaping of Output

<2.27.3-r0
  • H
CVE-2026-6734

<2.28.3-r0
  • L
GHSA-268h-hp4c-crq3

<2.27.3-r0
  • L
GHSA-r7g4-qg5f-qqm2

<2.27.3-r0
  • L
Interpretation Conflict

<2.27.3-r0
  • L
Directory Traversal

<2.27.3-r0
  • L
Insufficient Verification of Data Authenticity

<2.27.3-r0
  • L
GHSA-wqvq-jvpq-h66f

<2.27.3-r0
  • L
CVE-2026-12151

<2.31.5-r0
  • L
GHSA-p6gq-j5cr-w38f

*
  • L
CRLF Injection

<2.28.3-r0
  • L
CVE-2026-5079

<2.28.3-r0
  • L
CVE-2026-9697

<2.28.3-r0
  • L
CVE-2026-12143

<2.28.3-r0
  • L
Overly Permissive Cross-domain Whitelist

<2.27.3-r0
  • L
Uncontrolled Recursion

<2.28.3-r0
  • L
Improper Input Validation

<2.28.3-r0
  • L
GHSA-664h-gpgq-h6xx

<2.25.7-r0
  • L
CVE-2026-9277

<2.26.4-r0
  • L
Incorrect Authorization

<2.25.7-r0
  • L
GHSA-h3jj-5f3v-3685

<2.25.7-r0
  • L
Exposure of Data Element to Wrong Session

<2.25.7-r0
  • L
Information Exposure

<2.25.7-r0
  • L
GHSA-hv7x-3x78-gx53

<2.25.7-r0
  • L
Directory Traversal

<2.22.6-r0
  • L
GHSA-jwm3-qcfw-c5pp

<2.25.7-r0
  • L
Uncaught Exception

<2.27.3-r0
  • L
Uncaught Exception

<2.27.3-r0
  • L
Cross-site Scripting (XSS)

<2.25.6-r0
  • L
Resource Exhaustion

<2.26.4-r0
  • L
Missing Authentication for Critical Function

<2.25.7-r0
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<2.25.6-r0
  • L
Improper Input Validation

<2.22.6-r0
  • L
Information Exposure

<2.25.7-r0
  • L
Cross-site Scripting (XSS)

<2.25.7-r0
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<2.25.7-r0
  • L
Cross-site Scripting (XSS)

<2.25.7-r0
  • L
SQL Injection

<2.25.6-r0
  • L
SQL Injection

<2.25.7-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<2.25.6-r0
  • L
Authentication Bypass

<2.25.7-r0
  • M
Improper Authorization

<2.26.4-r0
  • L
HTTP Request Smuggling

<2.26.4-r0
  • L
Incorrect Regular Expression

<2.26.4-r0
  • M
HTTP Response Splitting

<2.26.4-r0
  • L
CVE-2026-8723

<2.26.4-r0
  • L
CVE-2026-3449

<2.26.4-r0
  • L
Cross-site Scripting (XSS)

<2.26.4-r0
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.29.7-r0
  • L
GHSA-c7w3-x93f-qmm8

<2.27.3-r0
  • H
Out-of-bounds Write

<2.26.4-r0
  • H
Directory Traversal

<2.26.4-r0
  • L
GHSA-vvjj-xcjg-gr5g

<2.27.3-r0
  • L
Improper Control of Dynamically-Managed Code Resources

<2.23.2-r0
  • L
Improper Control of Dynamically-Managed Code Resources

<2.23.2-r0
  • L
Arbitrary Argument Injection

<2.22.6-r0
  • L
Exposure of Resource to Wrong Sphere

<2.23.2-r0
  • L
Improper Control of Dynamically-Managed Code Resources

<2.23.2-r0
  • H
Resource Exhaustion

<2.23.2-r0
  • L
Improper Control of Dynamically-Managed Code Resources

<2.23.2-r0
  • L
Protection Mechanism Failure

<2.23.2-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<2.22.6-r0
  • M
Resource Exhaustion

<2.23.2-r0
  • H
XML Injection

<2.23.2-r0
  • L
Improper Handling of Exceptional Conditions

<2.22.6-r0
  • L
Arbitrary Code Injection

<2.22.6-r0
  • L
Deserialization of Untrusted Data

<2.22.6-r0
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<2.22.6-r0
  • L
Improper Input Validation

<2.22.6-r0
  • L
Uncontrolled Recursion

<2.22.6-r0
  • L
Improper Handling of Unicode Encoding

<2.22.6-r0
  • H
Uncontrolled Recursion

<2.23.2-r0
  • H
Arbitrary Code Injection

<2.22.6-r0
  • L
Protection Mechanism Failure

<2.23.2-r0
  • L
GHSA-q3fm-4wcw-g57x

<2.23.2-r0
  • L
Protection Mechanism Failure

<2.23.2-r0
  • L
Exposure of Resource to Wrong Sphere

<2.22.6-r0
  • M
Cross-site Scripting (XSS)

<2.23.2-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<2.22.6-r0
  • L
Protection Mechanism Failure

<2.23.2-r0
  • H
Use of Uninitialized Resource

<2.23.2-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<2.22.6-r0