{"api_version":"v1","generated_at":"2026-10-08T21:35:00+00:00","product":{"cve_count":23,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-n8n-n8n-2a72930efe9b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/n8n","name":"n8n","next_cursor":null,"observations":[{"affected":"< 1.123.61; < 2.28.1; < 2.27.4","affected_versions_present":true,"cve_id":"CVE-2026-59259","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59259","fixed":"1.123.61; 2.28.1; 2.27.4","last_modified":"2026-07-15T18:47:38.895Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-jp7m-xcgx-57qm","primary_source":"","published":"2026-07-15T11:25:35.530Z"},{"affected":"< 2.28.1; < 2.27.4","affected_versions_present":true,"cve_id":"CVE-2026-59254","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59254","fixed":"2.28.1; 2.27.4","last_modified":"2026-07-15T13:25:43.797Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-2434-3x6q-8r99","primary_source":"","published":"2026-07-15T11:25:34.866Z"},{"affected":"< 1.123.22; 2.0.0 < 2.9.3; 2.10.0 < 2.10.1","affected_versions_present":true,"cve_id":"CVE-2026-56353","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56353","fixed":"1.123.22; 2.9.3; 2.10.1","last_modified":"2026-07-16T15:14:09.641Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-jh8h-6c9q-7gmw","primary_source":"","published":"2026-07-15T11:25:29.334Z"},{"affected":"< 2.19.3","affected_versions_present":true,"cve_id":"CVE-2026-56352","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56352","fixed":"2.19.3","last_modified":"2026-07-15T13:49:30.931Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-2vx9-7wpg-88jq","primary_source":"","published":"2026-07-15T11:25:28.663Z"},{"affected":"< 2.10.0","affected_versions_present":true,"cve_id":"CVE-2026-56349","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56349","fixed":"2.10.0","last_modified":"2026-07-15T12:42:58.824Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-fvfv-ppw4-7h2w","primary_source":"","published":"2026-07-15T11:25:27.992Z"},{"affected":"< 2.28.0; < 1.123.58","affected_versions_present":true,"cve_id":"CVE-2026-58661","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58661","fixed":"2.28.0; 1.123.58","last_modified":"2026-07-10T16:43:29.322Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-w867-jm58-p9pv","primary_source":"","published":"2026-07-10T13:58:01.635Z"},{"affected":"< 1.123.24; 2.0.0-rc.0 < 2.10.4; 2.11.0 < 2.12.0; < 2.10.4","affected_versions_present":true,"cve_id":"CVE-2026-56354","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56354","fixed":"1.123.24; 2.10.4; 2.12.0","last_modified":"2026-07-10T16:42:43.575Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-w673-8fjw-457c","primary_source":"","published":"2026-07-10T13:57:57.614Z"},{"affected":"< 1.123.61; < 2.28.1; < 2.27.4","affected_versions_present":true,"cve_id":"CVE-2026-59257","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59257","fixed":"1.123.61; 2.28.1; 2.27.4","last_modified":"2026-07-09T13:39:51.132Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-hwmj-qg4v-cvg9","primary_source":"","published":"2026-07-08T13:49:13.618Z"},{"affected":"< 2.28.0","affected_versions_present":true,"cve_id":"CVE-2026-59253","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59253","fixed":"2.28.0","last_modified":"2026-07-08T14:31:44.900Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-2xgm-wc4g-5jvg","primary_source":"","published":"2026-07-08T13:49:12.902Z"},{"affected":"< 2.26.2; < 2.25.7","affected_versions_present":true,"cve_id":"CVE-2026-56778","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56778","fixed":"2.26.2; 2.25.7","last_modified":"2026-07-08T14:25:29.900Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-h3jj-5f3v-3685","primary_source":"","published":"2026-07-08T13:49:07.670Z"},{"affected":"< 1.123.55; < 2.26.2; < 2.25.7","affected_versions_present":true,"cve_id":"CVE-2026-56776","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56776","fixed":"1.123.55; 2.26.2; 2.25.7","last_modified":"2026-07-09T14:55:45.087Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-hv7x-3x78-gx53","primary_source":"","published":"2026-07-08T13:49:06.971Z"},{"affected":"< 1.123.55; < 2.26.2; < 2.25.7","affected_versions_present":true,"cve_id":"CVE-2026-56775","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56775","fixed":"1.123.55; 2.26.2; 2.25.7","last_modified":"2026-07-08T14:31:22.470Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-664h-gpgq-h6xx","primary_source":"","published":"2026-07-08T13:49:06.267Z"},{"affected":"< 1.123.18; 2.0.0 < 2.6.2","affected_versions_present":true,"cve_id":"CVE-2026-56360","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56360","fixed":"1.123.18; 2.6.2","last_modified":"2026-07-08T14:26:33.242Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-38c7-23hj-2wgq","primary_source":"","published":"2026-07-08T13:49:03.453Z"},{"affected":"< 2.8.0; < 2.6.4","affected_versions_present":true,"cve_id":"CVE-2026-56359","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56359","fixed":"2.8.0; 2.6.4","last_modified":"2026-07-09T13:37:23.855Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-364x-8g5j-x2pr","primary_source":"","published":"2026-07-08T13:49:02.746Z"},{"affected":"n8n: \u2264 1.114.4","affected_versions_present":true,"cve_id":"CVE-2025-71380","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71380","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-06T13:13:11.151Z","patch_url":"","primary_source":"","published":"2026-07-04T01:23:42.800Z"},{"affected":"< 2.26.2; < 2.25.7","affected_versions_present":true,"cve_id":"CVE-2026-56777","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56777","fixed":"2.26.2; 2.25.7","last_modified":"2026-07-01T13:49:32.546Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-jwm3-qcfw-c5pp","primary_source":"","published":"2026-06-30T22:08:41.624Z"},{"affected":"< 1.123.27; 2.0.0-rc.0 < 2.13.3; 2.14.0 < 2.14.1; < 2.14.1; < 2.13.3","affected_versions_present":true,"cve_id":"CVE-2026-56356","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56356","fixed":"1.123.27; 2.13.3; 2.14.1","last_modified":"2026-07-01T13:24:34.456Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-3c7f-5hgj-h279","primary_source":"","published":"2026-06-30T22:08:35.484Z"},{"affected":"< 2.8.0","affected_versions_present":true,"cve_id":"CVE-2026-56350","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56350","fixed":"2.8.0","last_modified":"2026-07-01T15:04:03.216Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-vjf3-2gpj-233v","primary_source":"","published":"2026-06-30T22:08:34.810Z"},{"affected":"< 1.123.25; 2.0.0-rc.0 < 2.11.2; < 2.11.2","affected_versions_present":true,"cve_id":"CVE-2026-56358","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56358","fixed":"1.123.25; 2.11.2","last_modified":"2026-06-24T16:01:44.567Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-q4fm-pjq6-m63g","primary_source":"","published":"2026-06-24T11:53:19.735Z"},{"affected":"< 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-56351","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56351","fixed":"2.4.0","last_modified":"2026-06-24T12:42:36.248Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-f3f2-mcxc-pwjx","primary_source":"","published":"2026-06-24T11:53:19.047Z"},{"affected":"< 1.123.15; 2.0.0 < 2.5.0","affected_versions_present":true,"cve_id":"CVE-2026-56357","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56357","fixed":"1.123.15; 2.5.0","last_modified":"2026-06-23T14:25:03.009Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-mqpr-49jj-32rc","primary_source":"","published":"2026-06-22T21:04:52.333Z"},{"affected":"< 2.20.0","affected_versions_present":true,"cve_id":"CVE-2026-56348","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56348","fixed":"2.20.0","last_modified":"2026-06-23T12:27:54.827Z","patch_url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-3875-8gcx-7v46","primary_source":"","published":"2026-06-22T21:04:51.642Z"},{"affected":"n8n: >= 0.211.0, < 1.120.4, = 1.121.0","affected_versions_present":true,"cve_id":"CVE-2025-68613","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68613","fixed":"The Cyber Centre recommends that organizations upgrade affected instances of n8n to the latest supported version. The table below shows affected and patched versions for each CVE: Affected product CVE Affected versions Patched versions n8n CVE-2025-68613 version 0.211.0 to versions prior to 1.120.4, 1.121.1 and 1.122.0 1.120.4, 1.121.1, and 1.122.0 n8n CVE-2026-21858 version 1.65.0 to versions prior to 1.121.0 1.121.0 n8n CVE-2026-21877 versions prior to 0.121.2 1.121.3 Note: n8n 1.X version will reach end of life (EOL) by beginning of March 2026 Footnote 9 . If patching is not immediately possible, the vendor suggests that users may restrict or disable publicly accessible webhook and form endpoints until upgrading is complete Footnote 10 . In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions with an emphasis on the following topics Footnote 11 . Patch operating systems and applications Harden operating systems and applications Isolate web-facing applications Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal , or email contact@cyber.gc.ca .","last_modified":"2026-03-12T03:55:15.270Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/al26-001-vulnerabilities-affecting-n8n-cve-2026-21858-cve-2026-21877-cve-2025-68613","primary_source":"","published":"2025-12-19T22:23:47.777Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"n8n"}}
