n8n security advisory (AV26-916)
n8n, a tool that connects apps and services to automate workflows, has a bug that lets attackers send a special request to crash the program. This affects older versions of n8n, but the company has fixed it in newer releases.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 2.37.7
- Affects
- n8n-io/n8n
- Exploited
- Not confirmedNo confirmation recorded
How it works
- An attacker sends a specially crafted request to n8n's web interface.
- The tool tries to process it but crashes instead.
- This happens because the software does not properly handle certain inputs, causing it to fail and stop working.
What to do
If you use n8n on your computer or server, check your installed version by opening the app and looking for the version number in the settings or version screen. Compare it against 2.37.7, 2.38.2, or 1.123.76.
Update to version 2.37.7 or later, 2.38.2 or later, or 1.123.76 or later. Check the n8n website or your package manager for the latest update instructions. If you can't update, contact the n8n support team for help.
Technical details
Affected software: n8n-io/n8n
Serial Number: AV26-916 Date: September 11, 2026 As of September 8, 2026, n8n is affected by a vulnerability in the following product: n8n Prior to 2.37.7 Prior to 2.38.2 Prior to 1.123.76 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
References
- github.com · n8n@1.123.76 (tag) patch release notes
- github.com · n8n@2.37.7 (tag) patch release notes
- github.com · n8n@2.38.2 (tag) patch release notes
- github.com · security CCCS Canada