Cyber Resilience
← All news
Confirmed3

n8n security advisory (AV26-733)

n8n fixed vulnerabilities in versions prior to 1.123.67, 2.32.1, and 2.31.5. Update now if you self-host, whether you are a small team or run an enterprise fleet; most cloud users are already on a safe version.
Sources (1)
What this means for you — CISO:Inventory self-hosted or vendor-managed n8n in your automation estate and patch to 1.123.67, 2.32.1, or 2.31.5 as applicable. Prioritize instances whose workflows touch identity, finance, or production systems.
What this means for you — Lean IT orgs:If you run n8n yourself, update to one of the fixed versions in the advisory now. If you only use a hosted automation service, ask that provider whether they have applied the fix.
What this means for you — MSP:Scan client environments for self-hosted n8n below the fixed versions and schedule updates; confirm any automation platforms you resell or operate have patched. Note which clients run workflows that reach sensitive SaaS or on-prem systems.
What this means for you — Researcher:CCCS AV26-733 tracks n8n fixes for builds prior to 1.123.67, 2.32.1, and 2.31.5 — pull the upstream advisories for CVE IDs, auth requirements, and affected components.