Vulnerabilities · 77 days ago
n8n’s problem is broader than a single web bug. The platform now has flaws that let authenticated editors reach other users’ credentials and API tokens, and let unauthenticated callers push fake payloads into exposed trigger nodes as if they were trusted input.
NCSC says n8n fixed multiple issues across several branches, including XSS, SQL injection, auth bypass, prototype pollution, and data exposure in versions before 1.123.55, 2.24.0, 2.25.7, 2.26.1, and 2.26.2. The affected paths include Respond to Webhook, Chat Trigger, SecurityScorecard, Dynamic Credentials, and trigger nodes tied to MicrosoftAgent365Trigger and StripeTrigger.
The practical risk is cross-boundary compromise: one editor can expose or overwrite another user’s secrets, and a public trigger can turn malicious data into workflow execution. Partial mitigation leaves different trust breaks in place.
CVEs in this update
10 CVEs
4 critical · 3 high · 3 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-54309 · 10.0 CRITICAL
Highest EPSS: CVE-2026-54309 · 0.55%
1 source covering this story
Kwetsbaarheden verholpen in n8n workflow automation platform
n8n heeft meerdere kwetsbaarheden verholpen in het n8n workflow automation platform, specifiek in versies voor 1.123.55, 2.24.0, 2.25.7, 2.26.1 en 2.26.2.
Part of the PlainSec briefing for 2026-06-29