OSS Support Hub / Workflow

Node.js Workflow NOASSERTION Latest: n8n@2.27.5

n8n

Fair-code workflow automation tool with visual editor and 400+ integrations

Project Health at a Glance

Live data from GitHub and npm, updated daily.

194.4K+4.0K
GitHub Stars
📦
n8n@2.27.5
Latest Release · Today
🔄
1d
Avg. Release Cadence
🐛
1.5K
Open Issues
📅
Today
Last Commit
⬇️
86.0K
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

Published: 2026-06-16 Fixed in: 1.123.55

n8n Vulnerable to Stored XSS via Various Nodes

Published: 2026-02-25 Fixed in: 1.123.22

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

Published: 2026-06-16 Fixed in: 2.26.2

n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

Published: 2026-05-19 Fixed in: 2.19.3

n8n's domain allowlist bypass enables credential exfiltration

Published: 2026-02-04 Fixed in: 1.121.0

n8n has XSS in its Credential Management Flow

Published: 2026-03-27 Fixed in: 2.8.0

n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host

Published: 2025-10-09 No fix available

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

Published: 2026-05-19 Fixed in: 2.20.0

n8n has Webhook Forgery on Zendesk Trigger Node

Published: 2026-02-26 Fixed in: 1.123.18

n8n has XSS in Chat Trigger Node through Custom CSS

Published: 2026-03-27 Fixed in: 1.123.27

Alternatives to n8n

Other Workflow projects in the Node.js ecosystem worth evaluating.

Support Options for n8n

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for n8n — without relying on volunteer maintainers.