Live data from GitHub and npm, updated daily.
Data last fetched: 2026-06-29
10 active CVEs reported via OSV.dev
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
n8n Vulnerable to Stored XSS via Various Nodes
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
n8n's domain allowlist bypass enables credential exfiltration
n8n has XSS in its Credential Management Flow
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
n8n has Webhook Forgery on Zendesk Trigger Node
n8n has XSS in Chat Trigger Node through Custom CSS
Other Workflow projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for n8n — without relying on volunteer maintainers.