n8n security advisory (AV26-916)

Published September 11, 2026

n8n, a tool that connects apps and services to automate workflows, has a bug that lets attackers send a special request to crash the program. This affects older versions of n8n, but the company has fixed it in newer releases.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 2.37.7
Affects
n8n-io/n8n
Exploited
Not confirmedNo confirmation recorded

How it works

  • An attacker sends a specially crafted request to n8n's web interface.
  • The tool tries to process it but crashes instead.
  • This happens because the software does not properly handle certain inputs, causing it to fail and stop working.

What to do

If you use n8n on your computer or server, check your installed version by opening the app and looking for the version number in the settings or version screen. Compare it against 2.37.7, 2.38.2, or 1.123.76.

Update to version 2.37.7 or later, 2.38.2 or later, or 1.123.76 or later. Check the n8n website or your package manager for the latest update instructions. If you can't update, contact the n8n support team for help.

Technical details

Affected software: n8n-io/n8n

Serial Number: AV26-916 Date: September 11, 2026 As of September 8, 2026, n8n is affected by a vulnerability in the following product: n8n Prior to 2.37.7 Prior to 2.38.2 Prior to 1.123.76 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

References