Security update — 20 August 2026

This is your bi-weekly security update from n8n. The following security advisories have been published since our last update:

  • Severity: High | Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCE — GHSA-9x83-43r8-5hwc
  • Severity: High | Expression Sandbox SpreadElement Bypass Enables Persistent Cross-Evaluation Native Object Mutation — GHSA-fg85-4wv2-p98j
  • Severity: High | Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error Data — GHSA-vrv8-j27g-g7cr
  • Severity: High | Gmail and Brevo nodes accept non-string content, enabling local file read and SSRF — GHSA-95ph-833c-4wrp
  • Severity: High | Git Node Remote Code Execution via Incomplete Repository-Local Configuration Neutralization — GHSA-mwp5-2m32-r54h
  • Severity: High | Shared-Workflow Editor Can Exfiltrate Credentials via Workflow Tool Node Inline Sub-Workflow — GHSA-4r56-g65c-fm83
  • Severity: Medium | Query Injection in Elasticsearch and Google Cloud Firestore Nodes via Unescaped Expression Interpolation — GHSA-wxwj-8wv6-vpw2
  • Severity: Medium | Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across Projects — GHSA-jmmj-93rg-6j39
  • Severity: Medium | Legacy Request Helper SSRF Check Validates uri While Axios Dispatches url — GHSA-jp9j-jr97-w9pj

These vulnerabilities have been fixed in the following n8n versions:

  • v1 patched in v1.123.73
  • beta patched in v2.36.2
  • stable patched in v2.35.4

What you need to do

If you are running a cloud version of n8n, your instance is patched automatically, and no action is required.

If you are running a self-hosted n8n instance on a version below the fixed versions listed above, we recommend upgrading at your earliest convenience.

If you are already running the latest patch version for your release branch, no action is needed.

Staying up to date

These updates are part of our regular security communication cadence. If you don’t already, you can also opt in to receive these updates via email here.

Learn more about our security approach: How n8n Handles Vulnerability Disclosure - and Why We Do It This Way – n8n Blog

Best regards,
The n8n Security Team

1 „Gefällt mir“