This is your bi-weekly security update from n8n. The following security advisories have been published since our last update:
- Severity: High | Shared-Workflow Credential Check Misses Nested and Tool Inline Sub-Workflows — GHSA-r6g9-5cpp-ppwr
- Severity: High | Unauthenticated Unbounded OAuth Client Persistence via the Authorize Endpoint — GHSA-3qcw-p65v-c7vq
- Severity: High | Stored XSS via Same-Origin Blob URL in the Binary-Data File Preview — GHSA-29xw-66fq-4xc3
- Severity: High | SQL Injection in the Microsoft SQL Node via Expression Interpolation into the Query Field — GHSA-5qpp-pqww-h7fp
- Severity: High | Shared-Workflow Credential Check Misses Agent Node Parameter Credentials — GHSA-x25p-9mr6-cwgp
- Severity: High | Send-and-Wait HMAC Bypass Allows Unauthenticated Approval of Waiting Executions — GHSA-728h-pmr2-7cgh
- Severity: High | Shared Prototype Mutation Through the MCP Workflow-Validation Interpreter Allows Owner Account Takeover — GHSA-5jr4-xmvf-frmj
- Severity: High | Execute Sub-workflow Inline JSON Allows Member to Spoof Workflow Identity for Credential Authorization, Static Data, and Error-Workflow Dispatch — GHSA-866p-xg8v-g2q7
- Severity: High | n8n Chat Trigger Stored XSS via customCss Parameter on Hosted-Chat Page — GHSA-x5cw-hm7v-q7mj
- Severity: High | Code Execution in the Git Node Log Operation via Unneutralized Repository Configuration — GHSA-x8wx-g24x-3549
- Severity: Medium | Cross-User Agent Chat Resume Allows Hijacking Another User’s Pending Tool Approval — GHSA-p3pg-xw4f-m72c
- Severity: Medium | Unauthenticated Cross-Project Workflow Execution via Webhook Path-Only Resolution — GHSA-4c7j-qff5-r9cx
- Severity: Medium | Prototype Pollution in the AI Workflow Builder Connection Merge — GHSA-3p2g-2wpm-8h3g
- Severity: Medium | Cross-Project Agent Ownership Transfer via Client-Supplied Agent ID — GHSA-2r5r-xgvc-rj4p
These vulnerabilities have been fixed in the following n8n versions:
- v1 patched in v1.123.83
- beta patched in v2.42.1
- stable patched in v2.41.4
What you need to do
If you are running a cloud version of n8n, your instance is patched automatically, and no action is required.
If you are running a self-hosted n8n instance on a version below the fixed versions listed above, we recommend upgrading at your earliest convenience.
- Upgrade guide: Update n8n | Deploy | n8n Docs
- Full advisory details: Security Advisories · n8n-io/n8n · GitHub
If you are already running the latest patch version for your release branch, no action is needed.
Staying up to date
These updates are part of our regular security communication cadence. If you don’t already, you can also opt in to receive these updates via email here.
Learn more about our security approach: How n8n Handles Vulnerability Disclosure - and Why We Do It This Way – n8n Blog
Best regards,
The n8n Security Team