Live data from GitHub and npm, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
n8n Vulnerable to Stored XSS via Various Nodes
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
n8n's domain allowlist bypass enables credential exfiltration
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
Other Workflow projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for n8n — without relying on volunteer maintainers.