Description
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity.
Severity (CVSS)
| Base score | 6.3 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-20 — Improper Input Validation
Affected products
| Vendor | Product | Versions |
|---|---|---|
| n8n | n8n | 0 to <2.10.0; 2.10.0 |
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-fvfv-ppw4-7h2w (vendor-advisory)
- https://www.vulncheck.com/advisories/n8n-guardrail-node-bypass-via-crafted-input (third-party-advisory)
Generated from the official CVE List on 16 Jul 2026 07:01 UTC.