PatchSiren

n8n-io CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM n8n-io CVE published 2026-06-23

CVE-2026-54313

CVE-2026-54313 is a medium-severity vulnerability in n8n, an open-source workflow automation platform. An authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before being passed to MongoDB as a query filter, allowing unintended documents to be matched and overwritten with attacker-controlled conten [truncated]

MEDIUM n8n-io CVE published 2026-06-23

CVE-2026-54310

CVE-2026-54310 is a SQL injection vulnerability in n8n, an open-source workflow automation platform. Authenticated users with workflow creation or modification permissions could inject and execute arbitrary SQL against the connected database within the privileges of the configured database account. This issue affects n8n versions prior to 2.25.7 and 2.26.2. The vulnerability has been fixed in versions 2.2 [truncated]

HIGH n8n-io CVE published 2026-06-23

CVE-2026-54309

The n8n workflow automation platform has a high-severity vulnerability, CVE-2026-54309, with a CVSS score of 8.8. The vulnerability exists in the @n8n/mcp-browser component when run in HTTP transport mode, allowing unauthenticated access to browser-control capabilities. This could enable an attacker to navigate, evaluate JavaScript, and access cookies and storage against the user's real browser profile. T [truncated]

MEDIUM n8n-io CVE published 2026-06-23

CVE-2026-54303

CVE-2026-54303 is a reflected Cross-Site Scripting (XSS) vulnerability in the n8n workflow automation platform. An endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without proper sanitization or Content-Security-Policy headers. This allows an attacker to inject malicious scripts when a logged-in user visits a crafted URL. The vulnerability has a CVSS [truncated]

CRITICAL n8n-io CVE published 2026-02-25

CVE-2026-27577

CVE-2026-27577 is a critical vulnerability in the n8n workflow automation platform that allows authenticated users to execute system commands on the host. The issue was patched in n8n versions 2.10.1, 2.9.3, and 1.123.22. Users should upgrade to one of these versions or later to remediate all known vulnerabilities. This vulnerability has a high impact on the confidentiality, integrity, and availability of [truncated]