Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. N8N
  3. Important Security Patch: 2.13.3 and 1.123.27

Important Security Patch: 2.13.3 and 1.123.27

Scheduled Pinned Locked Moved N8N
3 Posts 2 Posters 20 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • U Offline
    U Offline
    umnz
    wrote last edited by
    #1

    Just a warning to those who follow this forum, make sure you update.

    "Action required: update to the latest patch version of n8n

    We recently informed you about upcoming patches and security advisories for high- or critical-severity security vulnerabilities in n8n.

    These vulnerabilities have been fixed in the following n8n versions:

    1.x: Versions < 1.123.27 are patched in 1.123.27
    Stable: Versions >= 2.0.0 < 2.13.3 are patched in 2.13.3
    Beta: Versions >= 2.14.0 < 2.14.1 are patched in 2.14.1
    If you are running a version below the fixed version for your release branch, please upgrade to the applicable fixed version (or later) as soon as possible to protect your instance. For guidance on how to update your self-hosted instance, please refer to our updating documentation.

    The related security advisories have been published. You can find links to the advisories below:

    Critical | RCE via SQL Mode of Merge Node (CVE-2026-33660)
    Critical | Prototype Pollution in GSuiteAdmin node parameters leads to RCE (CVE-2026-33696)
    High | Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition (CVE-2026-33663)
    High | In-Process Memory Disclosure in Task Runner (CVE-2026-27496)
    High | LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover (CVE-2026-33665)
    High | SQL Injection in Data Table Node via orderByColumn Expression (CVE-2026-33713)
    High | External Secrets Authorization Bypass in Credential Saving (CVE-2026-33722)
    The information shared here is based on our current knowledge, and we will update you as soon as possible if our guidance changes.

    Best regards,
    The n8n Security Team"

    1 Reply Last reply
    0
    • nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote last edited by
      #2

      the new patched version of n8n is packaged and released by now.

      1 Reply Last reply
      1
      • U Offline
        U Offline
        umnz
        wrote last edited by
        #3

        Glad to hear it! Thanks @nebulon.

        1 Reply Last reply
        0

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search