n8n vulnerabilities found - tl;dr: upgrade now
n8n critical vulnerabilities — update NOW
Multiple critical flaws (CVSS 9.9–10.0) with public exploits are being actively scanned. One requires zero authentication — just a crafted webhook request gives attackers access to your stored credentials and full server control.
Fix:
  1. Update to n8n 1.123.17 or 2.5.2
  2. Rotate your N8N_ENCRYPTION_KEY
  3. Rotate ALL stored credentials (API keys, OAuth tokens, everything)
  4. Review workflows for expressions you didn't create
  5. Stop exposing n8n directly to the internet
Your n8n instance holds every API key and token your automations touch. One compromise = keys to everything.
Don't wait on this.
Cheers
1
1 comment
Kawika Ohumukini
5
n8n vulnerabilities found - tl;dr: upgrade now
Self-Host Hub
skool.com/selfhosthub
Replace costly automation services for your business using SaaS and AI.
Powered by