n8n security advisory (AV26-880)
Canada's Cyber Centre flagged multiple n8n vulnerabilities in versions prior to 1.123.76 and several 2.x releases, urging users to update.
The Canadian Centre for Cyber Security issued advisory AV26-880 stating that n8n is affected by vulnerabilities in versions prior to 1.123.76 and prior to 2.35.4, 2.36.2, 2.37.7, and 2.38.2. The advisory links to the n8n-io GitHub repository for details. Users and administrators are encouraged to review the advisory and apply the necessary updates.
- Affects n8n versions prior to 1.123.76 and multiple 2.x releases
- Advisory references the n8n-io GitHub repository for remediation details
Full article64 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-880
Date: September 3, 2026
As of September 3, 2026, n8n is affected by vulnerabilities in the following product:
- n8n
- Prior to 1.123.76
- Prior to 2.35.4
- Prior to 2.36.2
- Prior to 2.37.7
- Prior to 2.38.2
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/n8n-security-advisory-av26-880