Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: n8n

Found 68 matching suggestions

View:
Compact
Detailed
Published
Permalink CVE-2025-61917
7.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 4 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package n8n-nodes-carbonejs
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
n8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buffers could contain residual data from within the same Node.js process (for example, data from prior requests, tasks, secrets, or tokens), resulting in potential information disclosure. This issue has been patched in version 1.114.3.

Affected products

n8n
  • ==>= 1.65.0, < 1.114.3

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Ignored packages (1)

Package maintainers

Current stable branch was never impacted.
Published
updated 4 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package n8n-nodes-carbonejs
  • @LeSuisse deleted
    2 maintainers
    • @gepbird
    • @sweenu
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
n8n Arbitrary File Write leading to RCE in n8n Merge Node

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files to the n8n server's filesystem potentially leading to remote code execution. This issue has been patched in versions 1.118.0 and 2.4.0.

Affected products

n8n
  • ==< 1.118.0
  • ==< 2.4.0

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Fixed in https://github.com/NixOS/nixpkgs/pull/482177 (unstable), stable was never impacted
Published
updated 4 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse deleted
    2 maintainers
    • @gepbird
    • @sweenu
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse ignored package n8n-nodes-carbonejs
  • @LeSuisse published on GitHub
n8n is Vulnerable to Stored Cross-Site Scripting via Markdown Rendering in Workflow UI

n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface, including workflow sticky notes and other areas that support markdown content. An authenticated user with permission to create or modify workflows could abuse this to execute scripts with same-origin privileges when other users interact with a maliciously crafted workflow. This could lead to session hijacking and account takeover. This issue has been patched in versions 1.123.9 and 2.2.1.

Affected products

n8n
  • ==< 2.2.1
  • ==< 1.123.9

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Fixed in https://github.com/NixOS/nixpkgs/pull/477990 (25.11) and https://github.com/NixOS/nixpkgs/pull/477422 (unstable)
Published
updated 4 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package n8n-nodes-carbonejs
  • @LeSuisse deleted
    2 maintainers
    • @sweenu
    • @gepbird
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
n8n Improper CSP Enforcement in Webhook Responses May Allow Stored XSS

n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP endpoints. Under certain conditions, the Content Security Policy (CSP) sandbox protection intended to isolate HTML responses may not be applied correctly. An authenticated user with permission to create or modify workflows could abuse this to execute malicious scripts with same-origin privileges when other users interact with the crafted workflow. This could lead to session hijacking and account takeover. This issue has been patched in version 1.123.2.

Affected products

n8n
  • ==< 1.123.2

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Fixed in https://github.com/NixOS/nixpkgs/pull/477990 (25.11) and https://github.com/NixOS/nixpkgs/pull/477422 (unstable)
Published
updated 4 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package n8n-nodes-carbonejs
  • @LeSuisse deleted
    2 maintainers
    • @sweenu
    • @gepbird
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
n8n Vulnerable to Command Injection in Community Package Installation

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute arbitrary system commands on the n8n host under specific conditions. This issue has been patched in version 1.120.3.

Affected products

n8n
  • ==>= 0.187.0, < 1.120.3

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Fixed in https://github.com/NixOS/nixpkgs/pull/477990 (25.11) and https://github.com/NixOS/nixpkgs/pull/477422 (unstable)
Published
updated 4 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package n8n-nodes-carbonejs
  • @LeSuisse deleted
    2 maintainers
    • @gepbird
    • @sweenu
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
n8n Has an Expression Escape Vulnerability Leading to RCE

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n. This issue has been patched in versions 1.123.17 and 2.5.2.

Affected products

n8n
  • ==< 2.5.2
  • ==< 1.123.17

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Fixed in https://github.com/NixOS/nixpkgs/pull/477990 (25.11) and https://github.com/NixOS/nixpkgs/pull/477422 (unstable)
Published
updated 4 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package n8n-nodes-carbonejs
  • @LeSuisse deleted
    2 maintainers
    • @gepbird
    • @sweenu
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
n8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Users

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host system. This can be exploited to obtain critical configuration data and user credentials, leading to complete account takeover of any user on the instance. This issue has been patched in versions 1.123.18 and 2.5.0.

Affected products

n8n
  • ==< 2.5.0
  • ==< 1.123.18

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Fixed in https://github.com/NixOS/nixpkgs/pull/477990 (25.11) and https://github.com/NixOS/nixpkgs/pull/477422 (unstable)
Published
Permalink CVE-2026-0863
8.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 5 months ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub
Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via the Code block by an authenticated user with basic permissions and can lead to a full n8n instance takeover on instances operating under "Internal" execution mode. If the instance is operating under the "External" execution mode (ex. n8n's official Docker image) - arbitrary code execution occurs inside a Sidecar container and not the main node, which significantly reduces the vulnerability impact.

Affected products

n8n
  • <2.4.2
  • <2.3.5
  • <1.123.14

Matching in nixpkgs

pkgs.n8n

Free and source-available fair-code licensed workflow automation tool

Package maintainers