n8n security advisory (AV26-916)
Canadian Cyber Centre advisory AV26-916 warns n8n before versions 2.37.7, 2.38.2, and 1.123.76 is affected by an undisclosed vulnerability; patch required.
The Canadian Centre for Cyber Security issued advisory AV26-916 on September 11, 2026, stating that n8n is affected by a vulnerability in versions prior to 2.37.7, 2.38.2, and 1.123.76. Fixed releases [email protected], [email protected], and [email protected] are available via GitHub. No CVE identifier or exploitation details are provided; administrators are urged to review linked resources and apply updates.
- Advisory AV26-916 dated September 11, 2026
- Affected: n8n versions before 2.37.7, 2.38.2, 1.123.76
- Fixed releases published on GitHub
- No CVE id or exploitation details disclosed
Full article65 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-916
Date: September 11, 2026
As of September 8, 2026, n8n is affected by a vulnerability in the following product:
- n8n
- Prior to 2.37.7
- Prior to 2.38.2
- Prior to 1.123.76
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/n8n-security-advisory-av26-916