PatchSiren

N8n CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM n8n CVE published 2026-07-15

CVE-2026-59259

CVE-2026-59259 is a permission bypass vulnerability in n8n's external secrets handling. An authenticated user with limited permissions can embed external secret references into credentials, potentially exposing secret values they are not authorized to access. This issue only affects instances where an external secrets provider is configured and Advanced Permissions are in use. The vulnerability has a CVSS [truncated]

MEDIUM n8n CVE published 2026-07-15

CVE-2026-56353

CVE-2026-56353 is an authentication bypass vulnerability in the Chat Trigger node of n8n, a workflow automation tool. The vulnerability occurs when the Chat Trigger node is configured with n8n User Auth, a non-default configuration. In affected versions, including before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0, the authentication check on the Chat Trigger webhook endpoint can be circumvented, a [truncated]

MEDIUM n8n CVE published 2026-07-10

CVE-2026-58661

CVE-2026-58661 is a MEDIUM severity vulnerability in n8n, a workflow automation tool. The vulnerability is caused by a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota check does not account for files already written to the shared temporary directory, allowing an authenticated user to repeatedly upload files that accumulate on disk until the periodic cleanu [truncated]

MEDIUM n8n CVE published 2026-07-10

CVE-2026-56354

CVE-2026-56354 is a medium-severity vulnerability in n8n, a workflow automation tool. The vulnerability exists in the Form Node and is caused by unsanitized HTML description fields and overly permissive iframe sandbox policies. This allows authenticated users with workflow creation permissions to inject malicious scripts or redirect parameters, potentially leading to stored XSS attacks or phishing redirec [truncated]

MEDIUM n8n CVE published 2026-07-08

CVE-2026-59253

CVE-2026-59253 is an improper authorization vulnerability in n8n before 2.28.0. Authenticated users can assign workflows to folders in other projects by supplying crafted request payloads during workflow creation. This causes logical integrity violations in target project folder structures. The vulnerability allows attackers to bypass project and folder authorization boundaries, potentially leading to una [truncated]

MEDIUM n8n CVE published 2026-07-08

CVE-2026-56778

CVE-2026-56778 is an authorization bypass vulnerability in the n8n workflow automation tool. The vulnerability affects n8n versions before 2.25.7 and 2.26.x before 2.26.2. An authenticated user with read-only access to a shared workflow can use the Public API to retry executions of that workflow, bypassing the intended permission boundary between read and execute access. This vulnerability allows for unau [truncated]

MEDIUM n8n CVE published 2026-07-08

CVE-2026-56775

The n8n workflow automation tool has an authorization vulnerability in three mutating evaluation test-run endpoints. The vulnerability allows an authenticated user with the project:viewer role to perform state-changing actions on workflows they only have read access to, due to the use of the workflow:read scope instead of the workflow:execute scope. This issue affects n8n instances using Advanced Permissi [truncated]

MEDIUM n8n CVE published 2026-07-08

CVE-2026-56360

The CVE record for CVE-2026-56360 was published on 2026-07-08T14:17:16.757Z. n8n, a workflow automation tool, is vulnerable to webhook forgery in its ZendeskTrigger node due to the failure to verify HMAC-SHA256 signatures on incoming Zendesk webhooks. This oversight allows attackers who know the webhook URL to send unsigned POST requests, potentially triggering workflows with arbitrary malicious data. The [truncated]

MEDIUM n8n CVE published 2026-07-08

CVE-2026-56359

CVE-2026-56359 is a cross-site scripting vulnerability in n8n before 2.8.0. Authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authorization button, executing arbitrary scripts in their browser session with the victim's privileges. This vulnerability can have a signifi [truncated]

HIGH n8n CVE published 2026-07-04

CVE-2025-71380

CVE-2025-71380 is a high-severity vulnerability in the n8n Execute Command node. The vulnerability allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise. The vulnerability has [truncated]

MEDIUM n8n CVE published 2026-06-22

CVE-2026-56357

CVE-2026-56357 is a medium-severity vulnerability in n8n, a workflow automation tool. The vulnerability exists in the GitHub Webhook Trigger node and allows attackers to send unsigned POST requests to trigger workflows with arbitrary data, effectively spoofing GitHub webhook events. This can be done by attackers who know the webhook URL. The vulnerability has a CVSS score of 6.3 and is classified as MEDIU [truncated]

MEDIUM n8n CVE published 2026-06-22

CVE-2026-56348

CVE-2026-56348 is a medium-severity credential exfiltration vulnerability in n8n before 2.20.0. The vulnerability exists in the POST /rest/dynamic-node-parameters/options endpoint and allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue HTTP requests with credentials to unauthorized hosts, exfiltrating sensitive [truncated]

Known exploited n8n CVE published 2026-03-11

CVE-2025-68613

CVE-2025-68613 is a n8n vulnerability described as an improper control of dynamically-managed code resources issue. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2026-03-11, which means defenders should treat it as an urgent remediation item. The supplied corpus does not include affected versions, a CVSS score, or detailed exploit conditions, so the safest response is to identify a [truncated]