VDB
EN

package

npm / n8n

pkg:npm/n8n

MEDIUM 6.4 npm
GHSA-2vx9-7wpg-88jq

n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions

수정: 2026. 5. 19.

HIGH 8.8 npm
GHSA-365g-vjw2-grx8

n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host

수정: 2025. 10. 9.

CRITICAL 9.1 npm
GHSA-3875-8gcx-7v46

n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass

수정: 2026. 5. 19.

MEDIUM 4.0 npm
GHSA-38c7-23hj-2wgq

n8n has Webhook Forgery on Zendesk Trigger Node

수정: 2026. 2. 26.

MEDIUM 5.4 npm
GHSA-3c7f-5hgj-h279

n8n has XSS in Chat Trigger Node through Custom CSS

수정: 2026. 4. 3.

HIGH 8.2 npm
GHSA-f3f2-mcxc-pwjx

n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes

수정: 2026. 2. 26.

HIGH 7.4 npm
GHSA-hv7x-3x78-gx53

n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint

수정: 2026. 6. 16.

MEDIUM 4.8 npm
GHSA-jh8h-6c9q-7gmw

n8n has an Authentication Bypass in its Chat Trigger Node

수정: 2026. 2. 26.

MEDIUM 5.4 npm
GHSA-q4fm-pjq6-m63g

n8n has a Stored XSS Vulnerability in its Form Trigger

수정: 2026. 3. 27.

MEDIUM 6.3 npm
GHSA-vjf3-2gpj-233v

n8n has an SSO Enforcement Bypass in its Self-Service Settings API

수정: 2026. 2. 26.

MEDIUM 4.1 npm
GHSA-w673-8fjw-457c

n8n: Authenticated XSS and Open Redirect via Form Node

수정: 2026. 3. 27.