30,437 Entries 2,235 Sources 5 Verticals Last sync 14 minutes Live
Self-hosted apps

n8n

n8n
n8n@2.26.8 fresh latest release
19.06.2026

fresh — released < 7 days ago · 0 open bugs, 0 Regressions

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

46 CVE(s) zuletzt, höchste Schwere: kritisch

Derived automatically from release, repo and CVE data — no judgment by a language model.

StreamWhat this means for this app
REL n8n@2.26.2 10.06.2026

n8n 2.26.2 is a maintenance release without critical changes. The only addition is telemetry for instance settings via environment variables. No breaking changes, migrations, or security updates are included. The update can be applied routinely without requiring adjustments to existing workflows.

New Features

  • Add instance settings env telemetry
Timelineall entries
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps High

A vulnerability in n8n workflow software allows authenticated users with editing permissions to inject malicious JavaScript code into Chat Trigger pages, which then executes in other users' sessions.

CVE-2026-54302
10.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in the n8n workflow automation software allows cross-site scripting attacks when logged-in users visit specially crafted URLs, enabling attackers to execute malicious code in the user's browser.

CVE-2026-54303
10.06.2026
CVE
Self-hosted apps High

A vulnerability in n8n allows authenticated users to cause global prototype pollution through the Microsoft SQL node, rendering the entire n8n server non-functional until restart.

CVE-2026-54312
10.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow software allows authenticated users to access other users' workflow data through the Merge node's SQL mode, because the sandbox context is shared and reused across different workflow executions.

CVE-2026-54311
10.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow software allows attackers to inject malicious data through public webhooks into workflows, potentially causing downstream actions to execute with incorrect data or credentials.

CVE-2026-54306
10.06.2026
CVE
Self-hosted apps High

A security vulnerability in the n8n workflow software allows authenticated users to inject malicious JavaScript code into other users' browsers through webhook nodes, potentially stealing their session data.

CVE-2026-54301
10.06.2026
CVE
Self-hosted apps Medium

A vulnerability in n8n workflow software allows attackers to send fake data to certain webhook nodes and execute workflows with manipulated content without requiring authentication.

CVE-2026-54308
10.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow automation software allows users with only read permissions to execute workflows despite lacking execution permissions. This can result in unintended API calls and data modifications in connected systems.

Advisory
10.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in the n8n workflow software allows authenticated users with editing permissions to inject malicious filter queries through the MongoDB node, potentially overwriting unintended database documents with attacker-controlled content.

CVE-2026-54313
10.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow software allows authenticated users to inject malicious SQL commands through TimescaleDB and Postgres nodes and execute them on the connected database.

CVE-2026-54310
10.06.2026
CVE
Self-hosted apps High

A vulnerability in the n8n workflow software allows authenticated users to send SecurityScorecard API tokens to attacker-controlled servers, potentially exposing sensitive credentials to unauthorized parties.

CVE-2026-54304
10.06.2026
CVE
Self-hosted apps High

A security flaw in n8n's browser control component allows unauthenticated attackers to control browser functions when HTTP transport is used. This enables strangers to access cookies, website data, and execute JavaScript in the user's browser.

CVE-2026-54309
10.06.2026
CVE
Self-hosted apps High

A security flaw in n8n Enterprise software allows authenticated users to access and hijack other users' credentials, potentially leading to data theft or workflow disruption.

CVE-2026-54305
10.06.2026
CVE
Self-hosted apps High

In the n8n workflow automation software, users with editor access to shared workflows can access credentials they don't own through specific API endpoints due to incomplete ownership verification checks.

CVE-2026-54307
10.06.2026
CVE
Self-hosted apps Medium

A vulnerability in n8n allows users with limited read permissions to start, cancel, and delete workflow test runs even though they should only have read access.

Advisory
10.06.2026
CVE
Self-hosted apps Medium

A vulnerability in n8n's Compression node allows attackers to cause memory exhaustion and crash all workflows by sending small compressed archives to public webhooks, as the decompression operation lacks size limits.

CVE-2026-54314
10.06.2026
CVE
Self-hosted apps High

A vulnerability in the n8n workflow automation software allows authenticated users to inject malicious scripts into web pages that then execute in other users' browsers, potentially enabling account takeovers.

CVE-2026-27578
07.06.2026
CVE
Self-hosted apps Critical

A vulnerability in the n8n workflow software allows authenticated users with workflow permissions to execute system commands on the server through crafted expressions.

CVE-2026-27577
07.06.2026
CVE
Self-hosted apps Critical

A security vulnerability in the n8n workflow software allows authenticated users with workflow permissions to execute arbitrary code and write files on the server through the Merge node.

CVE-2026-27497
07.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in the n8n workflow software allows SQL injection attacks through crafted table or column names in MySQL, PostgreSQL, and Microsoft SQL database nodes, enabling attackers to execute arbitrary SQL commands.

Advisory
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow automation software allows attackers to redirect users to external websites through malicious OAuth links when users deny permission requests.

CVE-2026-42230
07.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in the n8n workflow software allows authenticated users to inject malicious JavaScript code through the Custom CSS field, leading to stored cross-site scripting attacks on public chat pages.

Advisory
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in n8n allows authenticated users with workflow permissions to inject malicious scripts into Form Trigger nodes, which then execute for every visitor of published forms, enabling phishing attacks and form hijacking.

Advisory
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in the n8n workflow software allows authenticated users who can create Python Code nodes to escape the sandbox and execute arbitrary code on the server.

CVE-2026-42234
07.06.2026
CVE
Self-hosted apps Critical

A critical security vulnerability in the n8n workflow software allows authenticated users to execute malicious code on the server through the GSuiteAdmin node by using specially crafted parameters.

CVE-2026-33696
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow software allows authenticated users to create malicious HTML content that executes in other users' browsers, potentially granting access to workflows, credentials, or administrator privileges.

CVE-2026-33749
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in n8n's Oracle Database node allows SQL injection attacks through the Limit field when external user input is processed without validation, enabling attackers to steal data from the connected Oracle database.

CVE-2026-42233
07.06.2026
CVE
Self-hosted apps High

A vulnerability in the n8n workflow automation software allows authenticated users with limited privileges to steal HTTP credentials from other users and access their passwords in plaintext.

CVE-2026-33663
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in n8n workflow software allows authenticated users to read variables from projects they shouldn't have access to by manipulating the project ID in API requests.

CVE-2026-42227
07.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in n8n workflow software allows SQL injection attacks through Snowflake and MySQL v1 nodes when user input is unsafely incorporated into database queries. Attackers could steal, modify, or delete data from connected databases.

CVE-2026-42237
07.06.2026
CVE
Self-hosted apps High

A vulnerability in the n8n workflow automation software allows attackers to send large amounts of data to an OAuth registration endpoint without authentication, exhausting server memory and causing the application to become unavailable.

CVE-2026-42236
07.06.2026
CVE
Self-hosted apps Medium

A SQL injection vulnerability in n8n's SeaTable node allows attackers to gain unauthorized access to database rows and bypass security filters by manipulating user input passed through workflow expressions.

CVE-2026-42229
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow software allows authenticated users to access and read local files outside configured security restrictions through Git operations.

CVE-2026-49465
07.06.2026
CVE
Self-hosted apps High

A vulnerability in the n8n workflow automation software allows authenticated users to steal other users' API keys by tricking the system into sending foreign credentials to attacker-controlled servers.

CVE-2026-42226
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in n8n workflow software allows attackers to hijack chat connections without authorization and intercept or manipulate messages when certain conditions are met.

CVE-2026-42228
07.06.2026
CVE
Self-hosted apps High

A vulnerability in the n8n workflow automation software allows attackers to inject malicious JavaScript code through OAuth client names, which executes when notifications are displayed and can steal credentials or manipulate workflows.

CVE-2026-42235
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in the n8n workflow software allows authenticated users who can create Python Code nodes to escape the sandbox and execute arbitrary code on the server.

CVE-2026-49444
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in the n8n workflow automation software allowed authenticated users to bypass security restrictions and send HTTP requests with credentials to unauthorized servers.

Advisory
07.06.2026
CVE
Self-hosted apps Critical

A vulnerability in n8n's XML processing allows authenticated users to manipulate JavaScript object structures through crafted XML data and thereby execute arbitrary code on the server.

CVE-2026-42231
07.06.2026
CVE
Self-hosted apps Critical

A vulnerability in the n8n workflow software allows authenticated users to read local files and execute malicious code through the Merge node due to insufficient restrictions on SQL statements.

CVE-2026-33660
07.06.2026
CVE
Self-hosted apps Critical

A vulnerability in the n8n workflow software allows authenticated users to execute malicious code by manipulating JavaScript prototypes through the XML node component.

CVE-2026-42232
07.06.2026
CVE
Self-hosted apps Critical

A vulnerability in the n8n workflow software allows authenticated users to read arbitrary files from the server and potentially achieve full system compromise through the Git functionality.

CVE-2026-44790
07.06.2026
CVE
Self-hosted apps Critical

A vulnerability in the n8n workflow software allows authenticated users to execute malicious code and compromise the entire system through an unvalidated parameter in the HTTP Request node.

CVE-2026-44789
07.06.2026
CVE
Self-hosted apps High

A security flaw in n8n allows users with read-only access to shared OAuth credentials to replace them with their own tokens, enabling them to control workflows and potentially steal data.

CVE-2026-45732
07.06.2026
CVE
Self-hosted apps High

A vulnerability in n8n workflow software allows SQL injection attacks when an attacker plants malicious files in a connected Git repository and an administrator imports them through the Source Control feature.

CVE-2026-44792
07.06.2026
CVE
Self-hosted apps Critical

A security vulnerability in the n8n workflow software allows authenticated users with workflow permissions to bypass a previous security fix in the XML node and execute malicious code on the server.

CVE-2026-44791
07.06.2026
REL
Self-hosted apps fresh

Release 2026-06-19

n8n@2.26.8
19.06.2026
REL
Self-hosted apps fresh

Release 2026-06-19

n8n@2.27.3
19.06.2026
REL
Self-hosted apps fresh

Release 2026-06-19

n8n@1.123.59
19.06.2026
REL
Self-hosted apps fresh

Release 2026-06-19

beta
19.06.2026
REL
Self-hosted apps fresh

Release 2026-06-19

stable
19.06.2026
REL
Self-hosted apps fresh

Release 2026-06-18

n8n@2.27.2
18.06.2026
REL
Self-hosted apps fresh

Release 2026-06-18

n8n@2.26.7
18.06.2026
REL
Self-hosted apps fresh

Release 2026-06-18

n8n@1.123.58
18.06.2026
REL
Self-hosted apps fresh

Release 2026-06-17

n8n@2.27.1
17.06.2026
REL
Self-hosted apps fresh

Release 2026-06-17

n8n@2.26.6
17.06.2026
REL
Self-hosted apps fresh

Release 2026-06-17

n8n@2.26.5
17.06.2026
REL
Self-hosted apps fresh

Release 2026-06-17

n8n@1.123.57
17.06.2026
REL
Self-hosted apps fresh

Release 2026-06-16

n8n@2.27.0
16.06.2026
REL
Self-hosted apps fresh

Release 2026-06-15

n8n@2.26.4
15.06.2026
REL
Self-hosted apps fresh

Release 2026-06-15

n8n@1.123.56
15.06.2026
REL
Self-hosted apps proven

Release 2026-06-11

n8n@2.26.3
11.06.2026
REL
Self-hosted apps proven

Release 2026-06-10

n8n@2.26.2
10.06.2026
REL
Self-hosted apps proven

Release 2026-06-10

n8n@1.123.55
10.06.2026
REL
Self-hosted apps proven

Release 2026-06-10

n8n@2.25.7
10.06.2026
REL
Self-hosted apps proven

Release 2026-06-09

n8n@2.26.1
09.06.2026
REL
Self-hosted apps proven

Release 2026-06-09

n8n@2.26.0
09.06.2026
REL
Self-hosted apps proven

Release 2026-06-08

n8n@2.25.6
08.06.2026
REL
Self-hosted apps proven

Release 2026-06-08

n8n@1.123.54
08.06.2026
REL
Self-hosted apps proven

Release 2026-06-05

n8n@2.25.4
05.06.2026
REL
Self-hosted apps proven

Release 2026-06-05

n8n@2.25.5
05.06.2026
REL
Self-hosted apps proven

Release 2026-06-05

n8n@1.123.53
05.06.2026
REL
Self-hosted apps proven

Release 2026-06-05

n8n@2.23.4
05.06.2026
REL
Self-hosted apps proven

Release 2026-06-04

n8n@2.25.3
04.06.2026
REL
Self-hosted apps proven

Release 2026-06-04

n8n@1.123.52
04.06.2026
REL
Self-hosted apps proven

Release 2026-06-04

n8n@2.23.3
04.06.2026
REL
Self-hosted apps proven

Release 2026-06-03

n8n@2.25.2
03.06.2026
REL
Self-hosted apps proven

Release 2026-06-03

n8n@1.123.51
03.06.2026
REL
Self-hosted apps proven

Release 2026-06-02

n8n@2.25.1
02.06.2026
REL
Self-hosted apps proven

Release 2026-06-01

n8n@2.22.5-exp.0
01.06.2026
REL
Self-hosted apps proven

Release 2026-06-01

n8n@1.123.50
01.06.2026
REL
Self-hosted apps proven

Release 2026-06-01

n8n@2.22.6
01.06.2026
REL
Self-hosted apps proven

Release 2026-06-01

n8n@2.23.2
01.06.2026
REL
Self-hosted apps proven

Release 2026-05-28

n8n@2.23.1
28.05.2026
REL
Self-hosted apps proven

Release 2026-05-28

n8n@1.123.49
28.05.2026
REL
Self-hosted apps proven

Release 2026-05-28

n8n@2.22.5
28.05.2026
REL
Self-hosted apps proven

Release 2026-05-27

n8n@2.22.4-exp.0
27.05.2026
REL
Self-hosted apps proven

Release 2026-05-27

n8n@2.23.0
27.05.2026
REL
Self-hosted apps proven

Release 2026-05-27

n8n@1.123.48
27.05.2026
REL
Self-hosted apps proven

Release 2026-05-27

n8n@2.21.8
27.05.2026
REL
Self-hosted apps proven

Release 2026-05-27

n8n@2.22.4
27.05.2026
REL
Self-hosted apps proven

Release 2026-05-25

n8n@2.22.3
25.05.2026
REL
Self-hosted apps proven

Release 2026-05-25

n8n@1.123.47
25.05.2026
REL
Self-hosted apps proven

Release 2026-05-22

n8n@2.22.2
22.05.2026
REL
Self-hosted apps proven

Release 2026-05-21

n8n@2.21.6
21.05.2026
REL
Self-hosted apps proven

Release 2026-05-21

n8n@2.21.6-exp.0
21.05.2026
REL
Self-hosted apps proven

Release 2026-05-21

n8n@2.21.7
21.05.2026