Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox High
CVE-2025-61914 was published for n8n (npm) Dec 26, 2025
nlgbao1340 Credited to nlgbao1340
n8n Merge Node has Arbitrary File Write leading to RCE Critical
CVE-2026-25056 was published for n8n (npm) Feb 4, 2026
nlgbao1340 Credited to nlgbao1340
nlgbao1340 Credited to nlgbao1340
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes High
GHSA-64xh-79j6-r5v8 was published for n8n (npm) Jul 22, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON High
GHSA-cj9h-qx8g-pq2g was published for n8n (npm) Jul 22, 2026
nlgbao1340 Credited to nlgbao1340
ProTip! Advisories are also available from the GraphQL API