VDB
CVE-2026-56349
CVE-2026-56349
PUBLISHED
CVSS 6.3 MEDIUM
Reported by VulnCheck · Published July 15, 2026
n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft malicious inputs to circumvent guardrail protections and compromise workflow integrity.
Risk Scores
CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n8n | n8n | 0, 2.10.0 |
| n8n | n8n | 0, 2.10.0, 0 |
Timeline
- Jul 15, 2026 CVE Published
- Jul 15, 2026 CVE Updated
References
- GitHub Security Advisory (GHSA-fvfv-ppw4-7h2w) vendor-advisory
- VulnCheck Advisory: n8n - Guardrail Node Bypass via Crafted Input third-party-advisory