Live data from GitHub and npm, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
n8n Vulnerable to Stored XSS via Various Nodes
n8n's domain allowlist bypass enables credential exfiltration
n8n has XSS in its Credential Management Flow
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
n8n has Webhook Forgery on Zendesk Trigger Node
n8n has XSS in Chat Trigger Node through Custom CSS
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no
n8n has a Python Task Runner Sandbox Escape Vulnerability
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
Other Workflow projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for n8n โ without relying on volunteer maintainers.
Talk to an Expert โ