OSS Support Hub / Workflow

Node.js Workflow NOASSERTION Latest: stable

n8n

Fair-code workflow automation tool with visual editor and 400+ integrations

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
187.9K
GitHub Stars
๐Ÿ“ฆ
stable
Latest Release ยท Today
๐Ÿ”„
1d
Avg. Release Cadence
๐Ÿ›
1.5K
Open Issues
๐Ÿ“…
Today
Last Commit
โฌ‡๏ธ
79.8K
Weekly Downloads
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

n8n Vulnerable to Stored XSS via Various Nodes

Published: 2026-02-25 Fixed in: 1.123.22

n8n's domain allowlist bypass enables credential exfiltration

Published: 2026-02-04 Fixed in: 1.121.0

n8n has XSS in its Credential Management Flow

Published: 2026-03-27 Fixed in: 2.8.0

n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host

Published: 2025-10-09 No fix available

n8n has Webhook Forgery on Zendesk Trigger Node

Published: 2026-02-26 Fixed in: 1.123.18

n8n has XSS in Chat Trigger Node through Custom CSS

Published: 2026-03-27 Fixed in: 1.123.27

n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no

Published: 2026-03-25 Fixed in: 2.5.0

n8n has a Python Task Runner Sandbox Escape Vulnerability

Published: 2026-04-29 Fixed in: 1.123.32

n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration

Published: 2026-04-29 Fixed in: 1.123.32

n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

Published: 2026-02-04 Fixed in: 1.114.3

Alternatives to n8n

Other Workflow projects in the Node.js ecosystem worth evaluating.

Support Options for n8n

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for n8n โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’