[NEW] [high] n8n: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in n8n to bypass security measures, conduct a denial of service attack, disclose information, manipulate files, perform an SQL injection attack, and execute arbitrary code.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in n8n to bypass security measures, conduct a denial of service attack, disclose information, manipulate files, perform an SQL injection attack, and execute arbitrary code.
- Who is affected
- Users and deployments of n8n.
- Urgency
- Remediation is high urgency due to the variety of severe vulnerabilities including remote code execution.
- Action
- Update n8n to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2489
Recent advisories for n8n
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumGHSA-652q-gvq3-74qv: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expre…ghsa · 2026-07-22
- mediumGHSA-jqwr-vx3p-r266: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary S…ghsa · 2026-07-22
- mediumGHSA-9cmh-xcqm-5hqr: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runnerghsa · 2026-07-22
- mediumGHSA-89gh-3pgc-v5h2: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Dataghsa · 2026-07-22
- mediumGHSA-33q9-f52j-gc75: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhookghsa · 2026-07-22
- mediumGHSA-gq66-9cw5-j5jm: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restrictionghsa · 2026-07-22
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31