If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
Snowflake Node Arbitrary File Read and Write via Client-Side CommandsGHSA-r4j2-j3wm-q689 published
Aug 5, 2026 by JubkeHigh -
GraphQL Node Allowed-Domains Bypass Permits Restricted Credential ExfiltrationGHSA-wcv8-x773-j96r published
Aug 5, 2026 by JubkeModerate -
ReDoS in Filter and Switch Node Regex Matching Allows Worker Denial of ServiceGHSA-q3fv-295f-qfpf published
Aug 5, 2026 by JubkeModerate -
Sandbox Escape in JavaScript Code Node via Prototype PollutionGHSA-c9c6-rq46-h25v published
Aug 5, 2026 by JubkeModerate -
Code execution in the n8n Git node via unchecked repository-local git configurationGHSA-m87g-qr43-ccvc published
Aug 5, 2026 by JubkeHigh -
SSRF Protection Bypass via SearXNG Tool Allows Member Users to Read Internal Service ResponsesGHSA-9rp2-wm75-c5fj published
Aug 5, 2026 by JubkeModerate -
Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of ServiceGHSA-xwx6-jjhv-84p8 published
Jul 22, 2026 by csuermannHigh -
Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression InterpolationGHSA-652q-gvq3-74qv published
Jul 22, 2026 by csuermannModerate -
Edit Image Node Format Injection Allows Arbitrary File WriteGHSA-xmc9-4f2h-jf9c published
Jul 22, 2026 by csuermannHigh -
Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSONGHSA-cj9h-qx8g-pq2g published
Jul 22, 2026 by csuermannHigh
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database