Skip to content

Blog / Operations in practice

n8n vulnerabilities: is the version you run exposed?

Two n8n flaws scored 10.0 and one is being exploited in the wild. Check the version you run against the full advisory list, and see what researchers found.

Find out if the version you run is exposed

Two n8n flaws have been scored 10.0, the top of the CVSS scale. A third is on CISA’s list of vulnerabilities confirmed as exploited in real attacks. If you self-host, one question matters more than any of the detail below: is the version you are running on that list?

We keep an n8n security tracker so you can answer it in about ten seconds. It holds every disclosed n8n vulnerability with the severity, the versions affected and the release that fixes each one. You paste in your version and it tells you what applies. It runs in your browser, and nothing you type is sent anywhere.

At the time of writing it held 127 disclosed vulnerabilities, 41 of them rated critical. Those figures will be out of date by the time you read this, which is rather the point: the count has risen every month we have kept the tracker. Check the tracker, not this sentence.

The rest of this post is what independent researchers found behind those numbers. Almost none of it came from us.

The advisories land faster than most teams can patch

A running total hides the thing that actually hurts, which is the batching.

Bar chart of n8n advisories published per month from December 2025 to September 2026. Five in December, four in January, 17 in February, nine in March, nine in April, seven in May, 18 in June, 16 in July, 28 in August, and 13 in a partial September.

At the time of writing, 28 advisories landed in August 2026 alone, and 16 of those arrived on a single day. June brought 18, July 16.

A batch is not one decision. It is one reading per advisory, one judgement per advisory about whether the affected node is one your workflows touch, one upgrade to test against your own flows, and one maintenance window to schedule. Miss a cycle and you carry the previous batch into the next one.

BleepingComputer’s coverage of one such batch noted that public exploit code accompanied the disclosures. That compresses the window between reading an advisory and needing to have acted on it.

Two flaws scored 10.0, and one needs no login

Ni8mare, CVE-2026-21858, is the one that got the attention. Researchers at Cyera found it and reported it to n8n in early November 2025. The root cause is content-type confusion in how n8n parses webhook data. An attacker who can reach a workflow with a form submission trigger accepting a file, and a form ending node returning a binary file, can read arbitrary files, forge an administrator session and run commands on the host. No authentication required. It affects 1.65.0 up to 1.121.0, and 1.121.0 is the fix.

The independent write-ups are unusually thorough. Horizon3 put the exploit chain under a microscope, Rapid7 covered it alongside the related N8scape flaws, and Orca Security, Censys, SonicWall, Picus and SOC Prime all published breakdowns. CyberScoop reported researchers rushing to warn defenders.

The patching curve is what turns it from a technical story into an operational one. Shadowserver’s scan found six figures worth of unpatched instances exposed online in the days after disclosure, and roughly half of those were still exposed by Sunday 11 January 2026, concentrated in the US and Europe. A fix existing and a fix being applied are different events, and the gap between them gets measured in tens of thousands of servers.

CVE-2026-54309 is the other flaw at the maximum, and it got a fraction of the coverage. Published in June 2026, it exposes unauthenticated browser-control sessions through the MCP browser HTTP transport. It affects versions below 2.25.7 and the 2.26.0 line before 2.26.2. If you are running agents through MCP on n8n, put this one on your list even though it never made the headlines Ni8mare did.

One is already being exploited in the wild

CVE-2025-68613 is an expression-language injection leading to remote code execution, rated 9.9, disclosed in December 2025 and fixed in 1.120.4, 1.121.1 and 1.122.0.

On 11 March 2026 CISA added it to the Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by 25 March. Shadowserver’s tracking at the time still showed tens of thousands of unpatched instances exposed across North America and Europe. Resecurity published a technical breakdown of the injection path.

A KEV listing is a different class of fact from a CVSS score. CVSS is an assessment of how bad a flaw could be. KEV is a statement that someone has already used it.

More ways in, already published

  • CVE-2026-25049, an expression escape to remote code execution rated 9.9, disclosed in February 2026 and fixed in 1.123.17 and 2.5.2. SecureLayer7 published a deep dive, and Endor Labs demonstrated it with a working proof of concept.
  • CVE-2026-42236, which Checkmarx named OverDoS, an unauthenticated denial of service through MCP client registration, disclosed in April 2026.
  • CVE-2026-33660, an authenticated command execution flaw rated 9.4, covered by Qualys.
  • Leaked API tokens. The Hacker News reported on researchers collecting n8n API tokens from public GitHub commits and validating them against live instances. GitGuardian has written on the same exposure class, from leaked keys through to encryption key compromise.
  • Sandbox escapes. Tenable documents a Python code node sandbox bypass in the 1.x line, where an authenticated user able to edit workflows could run commands as the n8n process.

To be fair to n8n: every one of these has a patch, and the 2.0 release in December 2025 made real changes, with task runners on by default and code node execution isolated. The disclosures continued anyway, which is the point. The question for a self-hosting team is not whether fixes exist. It is whether you apply them within days of each batch.

Attackers are using n8n to phish your people

This part has nothing to do with n8n being vulnerable, and it is the part most teams have not registered.

Cisco Talos documented phishing campaigns running from October 2025 through March 2026 that embedded n8n webhook URLs directly in email, and measured a steep rise in email volume carrying those URLs over that period.

The mechanics are simple. An attacker creates a free trial account, which provisions a subdomain. Workflows call webhooks and reach external APIs. A phishing email impersonating a Microsoft OneDrive share notification points at that webhook, a CAPTCHA gate filters out automated analysis, and the download installs a modified remote monitoring and management agent. Talos saw campaigns delivering both a modified Datto RMM and the ITarian agent. Invisible tracking pixels pointed at n8n webhooks let attackers fingerprint who opened a message and on what device.

It works because the payload appears to come from a trusted domain. The Hacker News, SOC Prime and the Cloud Security Alliance all covered the finding. If your email security stack treats automation platform domains as reputable, that assumption is now load bearing in a way it was not a year ago.

Four things to do before the next batch lands

In order of how much they reduce exposure per hour spent.

  1. Work out what version you are actually on, across every instance, including the one somebody stood up for a proof of concept and never decommissioned. The scan data suggests forgotten instances are most of the problem.
  2. Get the editor and the execution API off the public internet. Exposed editor interfaces without authentication and publicly reachable execution APIs are the two findings that turn a moderate flaw into a critical incident.
  3. Restrict public webhook and form endpoints. Both maximum-severity flaws and CVE-2026-25049 run through unauthenticated public endpoints. Anything you can require authentication on, require it.
  4. Rotate any API token that has ever been near a git repository, and check whether it is in your history rather than just your working tree.

Check your version now

None of the above is findable in one place. NVD has the records but not the context. The vendor advisories are accurate but arrive in batches. The research write-ups are excellent, and each covers one flaw.

The tracker pulls from the National Vulnerability Database, the GitHub Advisory Database and the CISA KEV catalog, refreshes on every build, and answers the only question that matters on the day a batch drops: does this affect the version I am running?

Check your n8n version against the full advisory list. It takes about ten seconds, it runs entirely in your browser, and nothing you type is sent anywhere.

If the answer comes back worse than you expected, and the patching cycle is not work your team should own, see how Tray.ai compares. We run the platform, and applying security patches is our job rather than yours.

Sources

Frequently asked questions

How many n8n vulnerabilities have been disclosed?

+

At the time of writing our n8n security tracker held 127 disclosed vulnerabilities, 41 of them rated critical, with one confirmed as exploited in the wild. That count moves, which is why we keep it in the tracker rather than in a post. It refreshes from the National Vulnerability Database, the GitHub Advisory Database and the CISA Known Exploited Vulnerabilities catalog on every build, so the tracker is always the current figure.

Is n8n safe to self-host?

+

It can be, but the patching work is yours. Advisories arrive in batches rather than one at a time. At the time of writing, 28 landed in August 2026 alone and 16 of those on a single day. Each batch means reading the advisories, working out which affected nodes you actually use, testing the upgrade and scheduling a window. Shadowserver has repeatedly found tens of thousands of instances still unpatched weeks after fixes shipped.

What is Ni8mare, CVE-2026-21858?

+

Ni8mare is an unauthenticated remote code execution flaw in n8n, rated CVSS 10.0. Researchers at Cyera discovered it and reported it to n8n in early November 2025. It stems from content-type confusion in how n8n parses webhook data, and it lets an attacker read arbitrary files and reach command execution on the host. It affects versions 1.65.0 up to 1.121.0, and 1.121.0 is the release that fixes it.

Has any n8n vulnerability been exploited in real attacks?

+

Yes. CISA added CVE-2025-68613 to its Known Exploited Vulnerabilities catalog on 11 March 2026 and set a 25 March 2026 deadline for federal agencies to patch. It is an expression-language injection leading to remote code execution, rated CVSS 9.9, fixed in 1.120.4, 1.121.1 and 1.122.0.

Are attackers using n8n itself as attack infrastructure?

+

Cisco Talos documented phishing campaigns running from October 2025 to March 2026 that embedded n8n webhook URLs in email. The campaigns delivered modified remote monitoring tools and used invisible tracking pixels for device fingerprinting. This is separate from n8n being vulnerable. It is n8n's own trusted domain being used to carry payloads past filters.