npm package intelligence

n8n Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the npm package n8n, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting n8n
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
n8n KEV with sensor-observed exploitation activity

Review n8n exploitation against the versions you run

One of the two exploited n8n vulnerabilities tracked here are not in CISA KEV.

50%
Covered by CISA
50%
Beyond CISA

Attested n8n vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2026-21858

n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling

Beyond CISA 07 Feb 2026
CVE-2025-68613

n8n Vulnerable to Remote Code Execution via Expression Injection

In CISA 01 Jun 2026

Recurring weakness patterns

Improper Input Validation and Improper Control of Dynamically-Managed Code Resources account for mapped occurrences across this n8n KEV portfolio.

Browse all KEVs →