If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
XML Node Prototype Pollution to RCEGHSA-hqr4-h3xv-9m3r published
Apr 22, 2026 by JubkeCritical -
RCE via SQL Mode of Merge NodeGHSA-58qr-rcgv-642v published
Mar 25, 2026 by JubkeCritical -
Prototype Pollution in XML Webhook Body Parser Leads to RCEGHSA-q5f4-99jv-pgg5 published
Apr 22, 2026 by JubkeCritical -
XSS via MCP OAuth clientGHSA-537j-gqpc-p7fq published
Apr 22, 2026 by JubkeHigh -
Hijacking of Unauthenticated Chat ExecutionGHSA-f77h-j2v7-g6mw published
Apr 22, 2026 by JubkeModerate -
Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key ReplayGHSA-r4v6-9fqc-w5jr published
Apr 22, 2026 by JubkeHigh -
SQL Injection in SeaTable NodeGHSA-mp4j-h6gh-f6mp published
Apr 22, 2026 by JubkeModerate -
Unauthenticated Denial of Service via MCP Client RegistrationGHSA-49m9-pgww-9vq6 published
Apr 22, 2026 by JubkeHigh -
SQL Injection in Snowflake and MySQL NodesGHSA-hp3c-vfpm-q4f7 published
Apr 22, 2026 by JubkeModerate -
Public API Variables IDOR Allows Cross-Project Secret DisclosureGHSA-756q-gq9h-fp22 published
Apr 22, 2026 by JubkeModerate
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database