The automation platform n8n, which includes AI capabilities, has multiple security vulnerabilities that could allow attackers to execute malicious code and fully compromise n8n servers. While there are currently no reports of active attacks exploiting these flaws, administrators are advised to apply available security updates promptly. According to the security section of the n8n GitHub website, developers have addressed 18 vulnerabilities, most of which are classified as 'high' severity. The specific CVE numbers for these issues have not yet been published. Developers claim that the security problems have been resolved in versions 1.123.69, 2.33.4, and 2.34.1 of n8n. Potential risks include executing commands by manipulating certain Git-node configuration values, deleting project roles with specific permissions, stored XSS attacks on form submission pages, sandbox escapes in the JavaScript task runner, and data deletion in the MongoDB node. If administrators cannot immediately install the patches, they can find temporary mitigation steps in the warning messages, such as implementing strict access restrictions.
Bias read (Center): The article discusses technical vulnerabilities in software and provides information on security patches. It does not involve political topics, officials, or public policy. The content is purely technical and neutral in tone.





