Automation

n8n: what changed

In the last 90 days, 28 summarized changes: 18 security advisories, 5 releases, 5 fixes. Stackdiff reads n8n's own feeds (n8n.io) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

2.37.7Securityhigh
GHSA-hh89-3r9w-qj3j: n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
1.123.64Securityhigh
GHSA-g3r5-9h93-4j2c: n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
2.37.7Securitymedium
GHSA-cw9w-vv67-hf73: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
2.37.7Securitymedium
GHSA-q5wm-mgqx-fv2f: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
1.123.76Securitymedium
GHSA-qgpw-8g46-w95v: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
2.37.7Securitymedium
GHSA-cqr2-h44g-v75v: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
1.123.76Securitymedium
GHSA-pq6c-vh67-xpm3: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
1.123.76Securitymedium
GHSA-pf83-w3f9-8m37: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
1.123.76Securitymedium
GHSA-5m98-cgcr-xx3q: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
1.123.76Securitymedium
GHSA-f2cp-m7mv-8jpv: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
2.37.7Securitymedium
GHSA-679f-58pq-4v2c: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
1.123.76Securitymedium
GHSA-65xw-2v52-jhxc: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

2.39.4Fix
n8n@2.39.4
Release
beta
2.38.7Fix
n8n@2.38.7
Release
stable
2.39.3Fix
n8n@2.39.3
News
Nine coding harnesses vs. your laptop
2.37.7Securitymedium
GHSA-cw9w-vv67-hf73: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
2.37.7Securitymedium
GHSA-q5wm-mgqx-fv2f: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
1.123.76Securitymedium
GHSA-qgpw-8g46-w95v: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
2.37.7Securitymedium
GHSA-cqr2-h44g-v75v: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
1.123.76Securitymedium
GHSA-pq6c-vh67-xpm3: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
1.123.76Securitymedium
GHSA-pf83-w3f9-8m37: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
1.123.76Securitymedium
GHSA-5m98-cgcr-xx3q: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
1.123.76Securitymedium
GHSA-f2cp-m7mv-8jpv: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
2.37.7Securitymedium
GHSA-679f-58pq-4v2c: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
1.123.76Securitymedium
GHSA-65xw-2v52-jhxc: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
1.123.76Securitymedium
GHSA-6xcw-7xm6-48c6: n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
2.37.7Securitymedium
GHSA-35jj-42hp-8gmq: n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
1.123.76Securitymedium
GHSA-34ff-336r-5q23: n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
1.123.76Securitymedium
GHSA-j535-v25q-vx3q: n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
2.37.7Securityhigh
GHSA-hh89-3r9w-qj3j: n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
1.123.76Securitymedium
GHSA-hw8v-xxg5-vvvx: n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
News
The same nine streaming subscriptions cost $702/year more than in 2021
2.38.6Release
n8n@2.38.6
2.39.2Fix
n8n@2.39.2
1.123.79Release
n8n@1.123.79
1.123.79Release
v1: :rocket: Release 1.123.79 (#38268)
2.39.1Fix
n8n@2.39.1
2.37.7Securitymedium
GHSA-7hgx-277f-7vmg: n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
News
Tao: Open math problems being non-renewably mined by AI

Where Stackdiff reads n8n

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get n8n changes in your Monday brief

Add n8n and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief