Where
-Infinity
0

npm/n8nn8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK

Risk 27
Severity
6.3
EPSS
0.01%
First published (updated )

npm/n8nn8n Has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode

Risk 59
Severity
9.4
EPSS
0.11%
First published (updated )

n8n CVE-2025-68613 and CVE-2026-25049: Critical RCE Vulnerabilities

First published (updated )
Social
reddit

2026: New N8N RCE Deep Dive into CVE-2026-25049

First published (updated )
Social
reddit

npm/n8nn8n Vulnerable to Command Injection in Community Package Installation

Risk 75
Severity
9.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/n8nn8n Arbitrary File Write leading to RCE in n8n Merge Node

Risk 58
Severity
9.4
EPSS
0.14%
First published (updated )

npm/n8nn8n is Vulnerable to Stored Cross-Site Scripting via Markdown Rendering in Workflow UI

Risk 43
Severity
8.5
EPSS
0.01%
First published (updated )

npm/n8nn8n is Vulnerable to OS Command Injection in Git Node

Risk 58
Severity
9.9
EPSS
0.02%
First published (updated )

npm/n8nn8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Users

Risk 58
Severity
9.9
EPSS
0.02%
First published (updated )

npm/n8nn8n Improper CSP Enforcement in Webhook Responses May Allow Stored XSS

Risk 43
Severity
8.5
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/n8nn8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

Risk 44
Severity
7.7
First published (updated )

Ni8mare  -  Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)

First published (updated )
Social
reddit

CVE-2025-68613 — n8n Workflow Automation Expression Engine Isolation Failure

First published (updated )
Social
reddit

n8n and new agentic automation is showing security cracks

First published (updated )
Social
reddit

npm/n8nn8n Improper Control of Dynamically-Managed Code Resources Vulnerability

Risk 100
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203