Security update — 16 September 2026

This is your bi-weekly security update from n8n. The following security advisories have been published since our last update:

  • Severity: High | Community Package Install Validation Bypass via PubSub in Queue Mode Deployments — GHSA-fmmv-p585-7c8x
  • Severity: High | SQL Injection in Oracle Database Node Delete Table Drop Operation — GHSA-4wf3-rgqr-xcp3
  • Severity: High | Duplicate Node IDs Bypass Workflow Credential Tamper Guard, Exposing Credentials to a Shared Workflow Editor — GHSA-7gjv-rcf8-x5qc
  • Severity: High | Supabase Node Filters (String) Mode Allows PostgREST Filter Injection — GHSA-xrqg-3xcp-h45x
  • Severity: High | Path Traversal in Signed Resume URL Generation Enables Cross-Project Approval Forgery — GHSA-597w-c3jh-g8fg
  • Severity: High | Inline Agent Node-Tool Introspection Decrypts Any Instance Credential Without Ownership Check — GHSA-9rhv-fhr8-7q5r
  • Severity: High | NoSQL Injection in MongoDB Chat Memory Node Allows Unauthenticated Cross-Session Chat History Disclosure — GHSA-w24g-6454-7w7f
  • Severity: High | Credential Test Endpoint Resolves Project-Scoped Variables from Attacker-Controlled Project ID — GHSA-7gvh-q9w3-wqqx
  • Severity: High | Dynamic Credentials Authorize Endpoint Leaks Session Token to Attacker-Controlled Resolver — GHSA-rx55-8qhx-4hwx
  • Severity: High | Wekan and Baserow Credentials Leak Account Password to Unvalidated Host via preAuthentication Hook — GHSA-gx6g-2hm7-c4xf
  • Severity: High | Path Traversal and Query Injection via the Supabase Node Table Name — GHSA-rqch-9jrh-cr8w
  • Severity: High | Path Traversal in the n8n Node Redirects Public API Calls to Unintended Resources — GHSA-89p4-6h98-c7xm
  • Severity: Medium | Missing Webhook Signature Verification in Webflow Trigger Node Allows Forged Event Injection — GHSA-hwv9-jhc7-f7c4
  • Severity: Medium | Stored DOM XSS via Resource Locator Dropdown Link Handling — GHSA-c2wp-6fgc-xjq4
  • Severity: Medium | Unescaped Parameter Interpolation into Third-Party Query Languages Enables Filter Bypass and Bulk Data Disclosure — GHSA-5pg9-2vqx-r6jm
  • Severity: Medium | Approval Bypass in the Send and Wait Node’s Approve Within Chat Mode — GHSA-342v-gmh6-738j

These vulnerabilities have been fixed in the following n8n versions:

  • v1 patched in v1.123.80
  • Beta patched in v2.40.1
  • Stable patched in v2.39.6

What you need to do

If you are running a cloud version of n8n, your instance is patched automatically, and no action is required.

If you are running a self-hosted n8n instance on a version below the fixed versions listed above, we recommend upgrading at your earliest convenience.

If you are already running the latest patch version for your release branch, no action is needed.

Staying up to date

These updates are part of our regular security communication cadence. If you don’t already, you can also opt in to receive these updates via email here.

Learn more about our security approach: How n8n Handles Vulnerability Disclosure - and Why We Do It This Way – n8n Blog

Best regards,
The n8n Security Team

2 Likes