CVE-2026-56349

MEDIUM

n8n - Guardrail Node Bypass via Crafted Input

Title source: cna
STIX 2.1

Description

n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-fvfv-ppw4-7h2w)
https://github.com/n8n-io/n8n/security/advisories/GHSA-fvfv-ppw4-7h2w
Third Party Advisory third-party-advisory
VulnCheck Advisory: n8n - Guardrail Node Bypass via Crafted Input
https://www.vulncheck.com/advisories/n8n-guardrail-node-bypass-via-crafted-input

Scores

CVSS v4 6.3
EPSS 0.0034
EPSS Percentile 27.0%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
n8n/n8n < 2.10.0
n8n/n8n 2.10.0
Published Jul 15, 2026
Tracked Since Jul 15, 2026