[NEW] [high] n8n: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, conduct cross site scripting or server side request forgery, or trigger a denial of service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow arbitrary code execution, security bypass, information disclosure, data manipulation, cross-site scripting, server-side request forgery, and denial of service.
- Who is affected
- All n8n deployments.
- Urgency
- High severity with code execution capability requires urgent patching.
- Action
- Apply available n8n security patches immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2681
Recent advisories for n8n
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] n8n: Multiple vulnerabilitiescert-bund · 2026-07-23
- mediumGHSA-652q-gvq3-74qv: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expre…ghsa · 2026-07-22
- mediumGHSA-jqwr-vx3p-r266: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary S…ghsa · 2026-07-22
- mediumGHSA-9cmh-xcqm-5hqr: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runnerghsa · 2026-07-22
- mediumGHSA-89gh-3pgc-v5h2: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Dataghsa · 2026-07-22
- mediumGHSA-33q9-f52j-gc75: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhookghsa · 2026-07-22
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] jsoup: Vulnerability enables Cross-Site Scripting2026-08-07
- high[NEW] [high] Apache Portable Runtime (APR): Multiple vulnerabilities2026-08-07
- high[UPDATE] [high] Linux Kernel: Multiple Vulnerabilities2026-08-07
- medium[UPDATE] [medium] Golang Go: Multiple vulnerabilities2026-08-07
- high[UPDATE] [high] Linux Kernel: Multiple vulnerabilities2026-08-07