If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
Cross-Tenant Module-Cache Poisoning in the JS Task RunnerGHSA-9cmh-xcqm-5hqr published
Jul 22, 2026 by csuermannModerate -
Expression sandbox escape via arrow-function bodies enabling command executionGHSA-gv7g-jm28-cr3m published
Jul 22, 2026 by csuermannHigh -
Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type ConfusionGHSA-2x35-3fw4-9jr4 published
Jul 22, 2026 by csuermannHigh -
Authenticated code execution in the n8n Git nodeGHSA-rcv6-pvrj-4xcg published
Jul 22, 2026 by csuermannHigh -
SSRF Protection Bypass via MCP Client NodeGHSA-vhf8-cg2h-cg3p published
Jul 22, 2026 by csuermannModerate -
Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Code ExecutionGHSA-hx4h-vr3m-45vh published
Jul 22, 2026 by csuermannHigh -
Git Node fetch/pull/pushTags Operations Bypass Sandbox Path RestrictionGHSA-gf29-4f56-r2jf published
Jul 22, 2026 by csuermannHigh -
Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM NodesGHSA-64xh-79j6-r5v8 published
Jul 22, 2026 by csuermannHigh -
Account Takeover via Unverified Email Claim in Token Exchange Embed LoginGHSA-8342-988q-86cr published
Jul 22, 2026 by csuermannHigh -
Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base DirectoryGHSA-pf2q-pxhf-hgmw published
Jul 22, 2026 by csuermannModerate
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database