Free tool

Is my n8n version affected?

Type in the version of n8n you run. You get every published security advisory that affects it, how severe each one is, and the version that fixes it. It runs in your browser; nothing you type is sent anywhere.

Not sure which version you have? In n8n, open "Help" and then "About n8n". If you run Docker, it is the image tag, for example n8nio/n8n:1.88.0. If your tag is "latest", check inside n8n; "latest" only means whatever was newest when the container was last pulled.

About this data

What this covers, and what it doesn't.

Data last updated 2026-09-22. 200 advisories affecting the core n8n package, 184 of them with a CVE ID.

  • It covers published advisories only. A version with no matches here is not proven safe; it only means nothing published so far lists it. Newer advisories come out often, so the latest release on your line is always the better answer.
  • Advisories and version ranges come from n8n's GitHub security advisories and the GitHub Advisory Database. Titles are the advisory's own wording. Where n8n's advisory had no CVE ID, the ID comes from the NVD record that cites that advisory.
  • CVSS scores are the ones on the advisory (GitHub is the scoring authority for most of these), so NVD sometimes shows a different number. For example, CVE-2025-68613 is 9.9 on the advisory and 8.8 on NVD.
  • The "Known exploited" flag comes from CISA's Known Exploited Vulnerabilities catalog. As of 2026-09-22 one n8n CVE is on it: CVE-2025-68613, added 2026-03-11.
  • Left out: advisories for third-party projects that have "n8n" in the name (community nodes, MCP servers), and one advisory about the "Execute Command" node that has no version range or fix, because it is a configuration question rather than a bug in a version.
  • Version ranges are used exactly as the advisory writes them. Some advisories list "every version below the fix", even when the feature involved arrived later, so older versions can show more matches than they really have. The fixed-in version is still the right target.
  • Many of these need a logged-in user who can edit workflows. Read the advisory for how each one is exploited before deciding how urgent it is for you.

If you found something

Patching is the easy part; keeping up is the job.

n8n has published a lot of advisories this year, and upgrades can break workflows if nobody tests them first. If you would rather not track this yourself, I run a maintenance plan for self-hosted n8n on your own server: updates applied and tested, backups checked, monitoring and alerts. $300–600 a month, depending on the instance.

No pressure either way; happy to just answer a question about what you found.

Ask me about it See the maintenance plan