Find out if the version you run is exposed
Two n8n flaws have been scored 10.0, the top of the CVSS scale. A third is on CISA’s list of vulnerabilities confirmed as exploited in real attacks. If you self-host, one question matters more than any of the detail below: is the version you are running on that list?
We keep an n8n security tracker so you can answer it in about ten seconds. It holds every disclosed n8n vulnerability with the severity, the versions affected and the release that fixes each one. You paste in your version and it tells you what applies. It runs in your browser, and nothing you type is sent anywhere.
At the time of writing it held 127 disclosed vulnerabilities, 41 of them rated critical. Those figures will be out of date by the time you read this, which is rather the point: the count has risen every month we have kept the tracker. Check the tracker, not this sentence.
The rest of this post is what independent researchers found behind those numbers. Almost none of it came from us.
The advisories land faster than most teams can patch
A running total hides the thing that actually hurts, which is the batching.
At the time of writing, 28 advisories landed in August 2026 alone, and 16 of those arrived on a single day. June brought 18, July 16.
A batch is not one decision. It is one reading per advisory, one judgement per advisory about whether the affected node is one your workflows touch, one upgrade to test against your own flows, and one maintenance window to schedule. Miss a cycle and you carry the previous batch into the next one.
BleepingComputer’s coverage of one such batch noted that public exploit code accompanied the disclosures. That compresses the window between reading an advisory and needing to have acted on it.
Two flaws scored 10.0, and one needs no login
Ni8mare, CVE-2026-21858, is the one that got the attention. Researchers at Cyera found it and reported it to n8n in early November 2025. The root cause is content-type confusion in how n8n parses webhook data. An attacker who can reach a workflow with a form submission trigger accepting a file, and a form ending node returning a binary file, can read arbitrary files, forge an administrator session and run commands on the host. No authentication required. It affects 1.65.0 up to 1.121.0, and 1.121.0 is the fix.
The independent write-ups are unusually thorough. Horizon3 put the exploit chain under a microscope, Rapid7 covered it alongside the related N8scape flaws, and Orca Security, Censys, SonicWall, Picus and SOC Prime all published breakdowns. CyberScoop reported researchers rushing to warn defenders.
The patching curve is what turns it from a technical story into an operational one. Shadowserver’s scan found six figures worth of unpatched instances exposed online in the days after disclosure, and roughly half of those were still exposed by Sunday 11 January 2026, concentrated in the US and Europe. A fix existing and a fix being applied are different events, and the gap between them gets measured in tens of thousands of servers.
CVE-2026-54309 is the other flaw at the maximum, and it got a fraction of the coverage. Published in June 2026, it exposes unauthenticated browser-control sessions through the MCP browser HTTP transport. It affects versions below 2.25.7 and the 2.26.0 line before 2.26.2. If you are running agents through MCP on n8n, put this one on your list even though it never made the headlines Ni8mare did.
One is already being exploited in the wild
CVE-2025-68613 is an expression-language injection leading to remote code execution, rated 9.9, disclosed in December 2025 and fixed in 1.120.4, 1.121.1 and 1.122.0.
On 11 March 2026 CISA added it to the Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by 25 March. Shadowserver’s tracking at the time still showed tens of thousands of unpatched instances exposed across North America and Europe. Resecurity published a technical breakdown of the injection path.
A KEV listing is a different class of fact from a CVSS score. CVSS is an assessment of how bad a flaw could be. KEV is a statement that someone has already used it.
More ways in, already published
- CVE-2026-25049, an expression escape to remote code execution rated 9.9, disclosed in February 2026 and fixed in 1.123.17 and 2.5.2. SecureLayer7 published a deep dive, and Endor Labs demonstrated it with a working proof of concept.
- CVE-2026-42236, which Checkmarx named OverDoS, an unauthenticated denial of service through MCP client registration, disclosed in April 2026.
- CVE-2026-33660, an authenticated command execution flaw rated 9.4, covered by Qualys.
- Leaked API tokens. The Hacker News reported on researchers collecting n8n API tokens from public GitHub commits and validating them against live instances. GitGuardian has written on the same exposure class, from leaked keys through to encryption key compromise.
- Sandbox escapes. Tenable documents a Python code node sandbox bypass in the 1.x line, where an authenticated user able to edit workflows could run commands as the n8n process.
To be fair to n8n: every one of these has a patch, and the 2.0 release in December 2025 made real changes, with task runners on by default and code node execution isolated. The disclosures continued anyway, which is the point. The question for a self-hosting team is not whether fixes exist. It is whether you apply them within days of each batch.
Attackers are using n8n to phish your people
This part has nothing to do with n8n being vulnerable, and it is the part most teams have not registered.
Cisco Talos documented phishing campaigns running from October 2025 through March 2026 that embedded n8n webhook URLs directly in email, and measured a steep rise in email volume carrying those URLs over that period.
The mechanics are simple. An attacker creates a free trial account, which provisions a subdomain. Workflows call webhooks and reach external APIs. A phishing email impersonating a Microsoft OneDrive share notification points at that webhook, a CAPTCHA gate filters out automated analysis, and the download installs a modified remote monitoring and management agent. Talos saw campaigns delivering both a modified Datto RMM and the ITarian agent. Invisible tracking pixels pointed at n8n webhooks let attackers fingerprint who opened a message and on what device.
It works because the payload appears to come from a trusted domain. The Hacker News, SOC Prime and the Cloud Security Alliance all covered the finding. If your email security stack treats automation platform domains as reputable, that assumption is now load bearing in a way it was not a year ago.
Four things to do before the next batch lands
In order of how much they reduce exposure per hour spent.
- Work out what version you are actually on, across every instance, including the one somebody stood up for a proof of concept and never decommissioned. The scan data suggests forgotten instances are most of the problem.
- Get the editor and the execution API off the public internet. Exposed editor interfaces without authentication and publicly reachable execution APIs are the two findings that turn a moderate flaw into a critical incident.
- Restrict public webhook and form endpoints. Both maximum-severity flaws and CVE-2026-25049 run through unauthenticated public endpoints. Anything you can require authentication on, require it.
- Rotate any API token that has ever been near a git repository, and check whether it is in your history rather than just your working tree.
Check your version now
None of the above is findable in one place. NVD has the records but not the context. The vendor advisories are accurate but arrive in batches. The research write-ups are excellent, and each covers one flaw.
The tracker pulls from the National Vulnerability Database, the GitHub Advisory Database and the CISA KEV catalog, refreshes on every build, and answers the only question that matters on the day a batch drops: does this affect the version I am running?
Check your n8n version against the full advisory list. It takes about ten seconds, it runs entirely in your browser, and nothing you type is sent anywhere.
If the answer comes back worse than you expected, and the patching cycle is not work your team should own, see how Tray.ai compares. We run the platform, and applying security patches is our job rather than yours.
Sources
- Cisco Talos, The n8n n8mare: how threat actors are misusing AI workflow automation, April 2026
- Cyera, Ni8mare: unauthenticated remote code execution in n8n (CVE-2026-21858)
- BleepingComputer, Max severity Ni8mare flaw impacts n8n instances and CISA orders feds to patch n8n RCE flaw exploited in attacks
- Horizon3, The Ni8mare test: n8n RCE under the microscope
- Rapid7, Ni8mare and N8scape flaws among multiple critical vulnerabilities affecting n8n
- Checkmarx, OverDoS: taking down n8n instances
- SecureLayer7, A deep dive into CVE-2026-25049
- Qualys ThreatPROTECT, n8n patches critical remote code execution vulnerability (CVE-2026-33660)
- Resecurity, CVE-2025-68613: remote code execution via expression injection in n8n
- The Hacker News, Leaked n8n API tokens exposed live instances to credential theft and n8n webhooks abused since October 2025
- CyberScoop, Researchers rush to warn defenders of max-severity defect in n8n
- Advisory counts, severities and affected version ranges from our own n8n security tracker, which pulls the National Vulnerability Database, the GitHub Advisory Database and the CISA Known Exploited Vulnerabilities catalog on every build