Description
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-fvfv-ppw4-7h2w)
https://github.com/n8n-io/n8n/security/advisories/GHSA-fvfv-ppw4-7h2w
Third Party Advisory third-party-advisory
VulnCheck Advisory: n8n - Guardrail Node Bypass via Crafted Input
https://www.vulncheck.com/advisories/n8n-guardrail-node-bypass-via-crafted-input
Scores
CVSS v4
6.3
EPSS
0.0034
EPSS Percentile
27.0%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (2)
n8n/n8n
< 2.10.0
n8n/n8n
2.10.0
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026