n8n security advisory (AV26-985)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial number: AV26-985Date: October 1, 2026 As of October 1, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.80 Prior to 2.39.6 Prior to 2.40.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Community Package Install Validation Bypass via PubSub in Queue Mode Deployments Dynamic Credentials Authorize Endpoint Leaks Session Token to Attacker-Controlled Resolver Overview - n8n-io/n8n - GitHub

This version

Version
1 of 1
Recorded
October 01, 2026 19:00
Change
Initial
Content hash
3eccfd8a919bd9f64987fadff9fcc681
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.