If you discover a (suspected) security vulnerability, please report it through our Vulnerability Disclosure Program.
Security: n8n-io/n8n
Security
SECURITY.md
-
SQL Injection in Data Table Node via orderByColumn ExpressionGHSA-98c2-4cr3-4jc3 published
Mar 25, 2026 by JubkeHigh -
Authentication Bypass in Chat Trigger NodeGHSA-jh8h-6c9q-7gmw published
Feb 25, 2026 by JubkeModerate -
Unauthenticated Expression Evaluation via Form NodeGHSA-75g8-rv7v-32f7 published
Feb 25, 2026 by JubkeHigh -
LDAP Filter Injection in LDAP NodeGHSA-w83q-mcmx-mh42 published
Mar 25, 2026 by JubkeModerate -
In-Process Memory Disclosure in Task RunnerGHSA-xvh5-5qg4-x9qp published
Mar 25, 2026 by JubkeHigh -
SSO Enforcement BypassGHSA-vjf3-2gpj-233v published
Feb 25, 2026 by JubkeModerate -
Sandbox Escape in JavaScript Task RunnerGHSA-jjpj-p2wh-qf23 published
Feb 25, 2026 by JubkeCritical -
n8n Guardrail Node BypassGHSA-fvfv-ppw4-7h2w published
Feb 25, 2026 by JubkeModerate -
External Secrets Authorization Bypass in Credential SavingGHSA-fxcw-h3qj-8m8p published
Mar 25, 2026 by JubkeHigh -
XSS in Credential Management FlowGHSA-364x-8g5j-x2pr published
Mar 25, 2026 by JubkeModerate
Learn more about advisories related to n8n-io/n8n in the GitHub Advisory Database