If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of ServiceGHSA-xwx6-jjhv-84p8 published
Jul 22, 2026 by csuermannHigh -
Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression InterpolationGHSA-652q-gvq3-74qv published
Jul 22, 2026 by csuermannModerate -
Edit Image Node Format Injection Allows Arbitrary File WriteGHSA-xmc9-4f2h-jf9c published
Jul 22, 2026 by csuermannHigh -
Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSONGHSA-cj9h-qx8g-pq2g published
Jul 22, 2026 by csuermannHigh -
Cross-Tenant Module-Cache Poisoning in the JS Task RunnerGHSA-9cmh-xcqm-5hqr published
Jul 22, 2026 by csuermannModerate -
Expression sandbox escape via arrow-function bodies enabling command executionGHSA-gv7g-jm28-cr3m published
Jul 22, 2026 by csuermannHigh -
Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type ConfusionGHSA-2x35-3fw4-9jr4 published
Jul 22, 2026 by csuermannHigh -
Authenticated code execution in the n8n Git nodeGHSA-rcv6-pvrj-4xcg published
Jul 22, 2026 by csuermannHigh -
SSRF Protection Bypass via MCP Client NodeGHSA-vhf8-cg2h-cg3p published
Jul 22, 2026 by csuermannModerate -
Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of ServiceGHSA-hx4h-vr3m-45vh published
Jul 22, 2026 by csuermannModerate
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database