Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-65596: Incorrect Authorization in n8n-io n8nCVE-2026-65596
0

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit workflows can point the node's endpoint at a server they control and exfiltrate restricted credentials. Only instances where a credential has "Allowed HTTP Request Domains" configured and is usable by non-owner users are affected.

Join the discussion
CVE-2026-65595: Improper Privilege Management in n8n-io n8nCVE-2026-65595
0

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privileged user who can obtain a valid external JWT trusted by a configured issuer can use the resulting access token to invoke administrator-only Public API operations such as role escalation, user creation, and user deletion (role escalation requires an Advanced Permissions license), and, when unverified Community Package installation is enabled, achieve remote code execution.

Join the discussion
CVE-2026-65593: Server-Side Request Forgery (SSRF) in n8n-io n8nCVE-2026-65593
0

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL restrictions and make the n8n server issue HTTP requests to arbitrary internal targets when SSRF protection is disabled.

Join the discussion
CVE-2026-65591: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') in n8n-io n8nCVE-2026-65591
0

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

Join the discussion
n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the… (CVE-2026-56354)CVE-2026-56354
0

n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions can inject malicious scripts or redirect parameters to perform stored XSS attacks or phishing redirects against end users.

Join the discussion
N8n: Duplicate Advisory: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File UploadsCVE-2026-58661
0

n8n versions before 2.28.0 and before 1.123.58 on the 1.x branch have a vulnerability where authenticated users can exhaust disk space by repeatedly uploading files via the data-table file upload endpoint. The vulnerability arises because the quota check per request does not consider files already stored in the shared temporary directory, allowing accumulation until periodic cleanup occurs. This can lead to exhaustion of available disk space on the host system.

Join the discussion
CVE-2026-59209: CWE-522: Insufficiently Protected Credentials in n8n-io n8nCVE-2026-59209
0

n8n versions prior to 1.123.61, 2.27.4, and 2.28.1 contain a vulnerability where an authenticated user with editor access to a shared workflow can access credential-populated headers via the $request object in an HTTP Request node's pagination expression. This exposure allows the user to read and exfiltrate sensitive credentials. The issue is addressed in versions 1.123.61, 2.27.4, and 2.28.1.

Join the discussion
CVE-2026-59208: CWE-287: Improper Authentication in n8n-io n8nCVE-2026-59208
0

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1.

Join the discussion
CVE-2026-59207: CWE-693: Protection Mechanism Failure in n8n-io n8nCVE-2026-59207
0

n8n versions prior to 2.27.4 and 2.28.1 contain a vulnerability in the AI Agents feature where the Allowed HTTP Request Domains restriction was not enforced on credentials. This flaw allowed a member-level user with use-only access to a shared credential to send the credential's secret to an external server they control. The issue is fixed in versions 2.27.4 and 2.28.1.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/n8n-io/n8n
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses