CVE-2026-86075n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity High CVE-2026-86076n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity High CVE-2026-86077n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket Exploitation status Not confirmed Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86078n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86079n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86080n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86081n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity High CVE-2026-86082n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node Exploitation status Not confirmed Fix YesPublished 09/08/2026 Severity High CVE-2026-86083n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity High CVE-2026-86084n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86085n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints Exploitation status Not confirmed Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86993n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86994n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86995n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86996n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86074n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-86073n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution Exploitation status Not known exploited Fix YesPublished 09/08/2026 Severity Medium CVE-2026-85173n8n before 2.36.2 Missing Authorization via Insights API Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity Medium CVE-2026-85172n8n before 2.34.1 SSRF via Request Helper URI Validation Bypass Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity Medium CVE-2026-85171n8n before 1.123.73 Credential Exposure via Error Logging Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity High CVE-2026-85170n8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodes Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity High CVE-2026-85169n8n before 1.123.73 Remote Code Execution via $fromAI Prototype Leak Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity High CVE-2026-85168n8n before 1.123.73 Remote Code Execution via Git Node Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity High CVE-2026-85167n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity Medium CVE-2026-85166n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity High CVE-2026-85165n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement Exploitation status Not known exploited Fix YesPublished 09/03/2026 Severity High CVE-2026-77085n8n before 2.34.1 SSRF Protection Bypass via SearXNG Tool Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity Medium CVE-2026-77084n8n before 1.123.69 Remote Code Execution via Git Node Configuration Values Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77083n8n before 1.123.69 Code Node Sandbox Escape via Function.prototype Pollution Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity Medium CVE-2026-77082n8n before 1.123.69 ReDoS via Filter and Switch Node Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity Medium CVE-2026-77081n8n before 1.123.69 Allowed-Domains Bypass via GraphQL Node Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity Medium CVE-2026-77080n8n before 1.123.69 Arbitrary File Read and Write via Snowflake Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77079n8n before 2.34.1 Authorization Bypass via Custom Role Deletion Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77077n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77076n8n before 1.123.69 Credential Leak via GraphQL Node Error Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77075n8n before 1.123.69 Expression Injection via Resource Locator Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77074n8n before 1.123.69 SSRF via Edit Image Node Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity Medium CVE-2026-77073n8n before 2.34.1 Cross-Project Credential Access via MCP Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity Medium CVE-2026-77072n8n before 1.123.69 Stored XSS via Form Completion Page Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77071n8n before 1.123.69 PostgREST Filter Injection via Supabase Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77070n8n before 1.123.69 NoSQL Injection via MongoDB Node Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-77069n8n before 1.123.69 SSRF Protection Bypass via OAuth2 Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity Low CVE-2026-77068n8n before 2.34.1 Remote Code Execution via Path Traversal Exploitation status Not known exploited Fix YesPublished 08/20/2026 Severity High CVE-2026-71539n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution Exploitation status Not known exploited Fix YesPublished 08/18/2026 Severity High CVE-2026-72775n8n before 1.123.67 SQL Injection via PostgresTrigger Node Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity Medium CVE-2026-72774n8n before 1.123.67 Authentication Bypass via HTTP Request Node Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72773n8n before 2.32.1 Path Traversal via computer-use search_files Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity Medium CVE-2026-72772n8n before 2.32.1 Authentication Bypass via Token Exchange Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72771n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72770n8n before 1.123.67 Path Traversal via Git Node Operations Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72769n8n before 1.123.67 Prototype Pollution via VM Expression Engine Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity Medium CVE-2026-72768n8n before 2.32.1 SSRF Protection Bypass via MCP Client Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity Medium CVE-2026-72767n8n before 1.123.67 Remote Code Execution via Git node Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72766n8n before 1.123.67 Arbitrary File Read via Send Email Node Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72765n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72764n8n before 1.123.67 Module Cache Poisoning via Code Node Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity Medium CVE-2026-72763n8n before 1.123.67 Credential Exfiltration via Sub-Workflow Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72762n8n before 1.123.67 Arbitrary File Write via Edit Image Node Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-72750n8n before 1.123.67 SQL Injection via executeQuery Operation Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity Medium CVE-2026-72749n8n before 1.123.67 Prototype Pollution via Edit Fields Exploitation status Not known exploited Fix YesPublished 08/11/2026 Severity High CVE-2026-65599n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-65598n8n before 1.123.64 Remote Code Execution via Git Clone Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-65597n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-65596n8n before 1.123.64 Credential Exfiltration via GraphQL Node Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-65595n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-65594n8n before 2.30.1 Missing OAuth Authorization Check Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-65593n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-65592n8n before 1.123.64 Stored DOM XSS via cachedResultUrl Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-65591n8n before 1.123.64 Sanitizer Bypass Remote Code Execution Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-65590n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-65589n8n before 1.123.64 Credential Exposure via LLM Node Execution Data Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-65016n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance-Role Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-65015n8n before 2.30.1 Privilege Escalation via run_node_tool Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-65014n8n before 2.28.0 Authentication Bypass via test-webhook Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-59209n8n: Shared Credential Header Leak via HTTP Request Pagination Expression Exploitation status Not known exploited Fix YesPublished 07/09/2026 Severity High CVE-2026-59206n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration Exploitation status Not known exploited Fix YesPublished 07/09/2026 Severity High CVE-2026-59208n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution Exploitation status Not known exploited Fix YesPublished 07/09/2026 Severity High CVE-2026-59207n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector Exploitation status Not known exploited Fix YesPublished 07/09/2026 Severity High CVE-2026-44792n8n: Source Control Pull SQL Injection Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-44791n8n: XML Node Prototype Pollution Patch Bypass Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Critical CVE-2026-44790n8n: Arbitrary File Read via Git Node Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Critical CVE-2026-44789n8n: HTTP Request Node Pagination Prototype Pollution to RCE Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Critical CVE-2026-45732n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-49444n8n: Python sandbox escape Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-49465n8n: Git Node Clone and Push Operations Bypass File Sandbox Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-54304n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-54307n8n: Credential Exfiltration via Permission Bypass Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-54302n8n: Stored XSS in Chat Trigger Node Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-54305n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-54301n8n: Same-Origin XSS in Respond to Webhook Node Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-54306n8n: Prototype Pollution enables confused-deputy execution via public webhooks Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-54308n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-54311n8n: Merge Node SQL Mode Prototype Pollution Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-54310n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-54309n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-54314n8n: Denial of Service via ZIP decompression in webhook workflow Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-54312n8n: Microsoft SQL Node Prototype Pollution Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity High CVE-2026-54303n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-54313n8n: NoSQL Injection in MongoDB Node Find And Replace Operation Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Medium CVE-2026-42237n8n: SQL Injection in Snowflake and MySQL Nodes Exploitation status Not known exploited Fix YesPublished 05/04/2026 Severity Medium