n8n
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 187 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 10, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Monitor n8n in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.