Workflow Automation in 2026: n8n Published 196 Advisories in Nine Months, 59,558 Hosts Sat Exposed, and the Code Alternative Raised at $12.55B
I run n8n. Not for anything that touches a customer, but it is the fastest way I know to wire one SaaS webhook into another, and I have a half-finished project of my own, PandaFlow, in the same category, so I watch this market closely. What I watched this year was a category change its mind about what it is. Zapier, Make and n8n sold integration catalogues with a canvas on top. In 2026 they sell agents, and the agents run inside the same process that holds every API key the business owns. This is the ledger: the money, the licences, the vulnerability record, what it takes to self-host one properly, and the code-first alternative that quietly raised more than the no-code vendors combined. Where PandaStack or PandaFlow come up, I built them, and I say so.
The canvas got an agent node and a very different price
n8n, founded in Berlin in October 2019, closed a Series B in March 2025 of EUR 55 million at a EUR 250 million valuation led by Highland Europe, telling TechCrunch it had more than 3,000 enterprise customers, around 200,000 active users and 70,000 GitHub stars. Seven months later it raised a $180 million Series C led by Accel at $2.5 billion, and in May 2026 SAP took roughly 1.3 percent for more than EUR 60 million at a $5.2 billion valuation. Both later figures were reported by Bloomberg, whose articles I could only reach through the citations on Wikipedia's n8n page; n8n's own blog and press page say nothing about either round. Twenty times the valuation in fourteen months, and on 5 October the repository showed 206,679 stars, the largest project in the category and still not open source. The licence is n8n's own Sustainable Use License 1.0, which permits use "only for your own internal business purposes or for non-commercial or personal use" and reserves every file with .ee. in its name for a paid enterprise key. n8n calls this fair-code. The OSI does not call it open source, and neither should your procurement form.
The incumbents moved the same way without the drama. Zapier's MCP server exposes what it says are 9,000-plus apps and 66,000-plus actions to any agent speaking the protocol, bills each tool call at two tasks, and reports 500,000 MCP servers created and 25 million tool calls completed. Zapier Agents are billed in a separate unit, activities: 400 a month free, 1,500 for about $33.33 on an annual plan. Make launched AI Agents in April 2025 and in February 2026 rebuilt them inside the scenario builder with a "Reasoning" panel showing which tools the agent chose and why, on a credit model from $9 a month for 5,000 credits. Gumloop raised a $50 million Series B from Benchmark in March, naming Shopify, Ramp and Instacart among its customers, valuation undisclosed. Lindy's funding I could not source to anything primary and have left out.
Then the two enterprise platforms whose numbers dwarf all of this. Microsoft's Copilot Studio pricing page claims 90 percent of the Fortune 500 has used it and sells 25,000 Copilot Credits for $200 a month; the billing table charges one credit for a scripted answer, two for a generative one, five for an agent action, ten for tenant-graph grounding and 13 per hundred agent-flow actions, with agents disabled at 125 percent of prepaid capacity. Microsoft reported 30 million paid Microsoft 365 Copilot seats in its FY26 Q4 release and publishes no count of Copilot Studio agents anywhere I could find. Salesforce's Q2 FY27 release puts Agentforce ARR above $1.5 billion, up more than 240 percent, after redefining the metric to include Slackbot and Headless 360, which I covered with the wider app-builder story in September's post.
The tools, with the fields procurement actually asks about
| Tool | Licence | Entry price | Latest version (date) | Security record | Source |
|---|---|---|---|---|---|
| n8n | Sustainable Use License 1.0, .ee files commercial |
Cloud Starter EUR 20/mo annual, 2,500 executions | 2.41.6 (2 Oct 2026) | 196 GitHub advisories in 2026, 19 critical; CVE-2025-68613 in CISA KEV | GitHub, pricing |
| Zapier | Proprietary SaaS | Free 100 tasks; Pro from $19.99/mo annual | n/a | No public CVE record | pricing |
| Make | Proprietary SaaS | Free 1,000 credits; $9/mo for 5,000 | n/a | No public CVE record | pricing |
| Gumloop | Proprietary SaaS | Not verified | n/a | None public | TechCrunch |
| Dify | Apache-2.0 plus no-multi-tenant and logo clauses | Self-host free | 1.17.1 (10 Sep 2026) | 21 advisories, 13 in 2026, none critical, none in KEV | licence |
| Langflow (IBM) | MIT | Self-host free | 1.12.4 (29 Sep 2026) | 37 advisories, 16 critical in 2026; 6 CVEs in CISA KEV | GitHub |
| Flowise | Apache-2.0, archived 13 Aug 2026 | n/a | 3.1.4 (29 Jul 2026, final) | Unmaintained | GitHub |
| Activepieces | MIT core, packages/ee commercial |
Self-host free | 0.92.1 (30 Sep 2026) | No KEV entries | licence |
| Copilot Studio | Proprietary | $200/mo per 25,000 credits | n/a | Microsoft MSRC process | pricing |
| Temporal | MIT server; Cloud paid | Self-host free | 1.32.0 (11 Sep 2026) | No KEV entries | GitHub |
| Inngest | SSPL with Apache-2.0 future licence | Self-host free | 1.45.1 (17 Sep 2026) | No KEV entries | licence |
| Trigger.dev | Apache-2.0 | Self-host free | 4.7.2 (2 Oct 2026) | No KEV entries | GitHub |
| Restate | BSL 1.1, no public hosted Restate service | Self-host free | 1.7.13 (1 Oct 2026) | No KEV entries | licence |
| DBOS Transact | MIT | Self-host free | 3.2.0 (29 Sep 2026) | No KEV entries | GitHub |
| PandaFlow (mine) | MIT | Self-host free | No tagged release | None reported; 9 stars | GitHub |
Versions and stars are from the GitHub API on 5 October 2026; advisory counts from each repository's GitHub security advisories; KEV status from the CISA catalogue dated 4 October, which I downloaded and filtered. "No public CVE record" for the SaaS vendors means exactly that: a closed product has bugs you never hear about, which is different from having none.
196 advisories in nine months
The n8n record deserves a fair reading, because the raw numbers are alarming and the fair reading is more interesting. Every advisory the project has published through GitHub comes to 210: 14 in 2025 and 196 between 1 January and 5 October 2026, of which 19 are critical, 90 high, 85 medium and two low. The cadence rose through the year, from four in January to 27 in June, 30 in July and 49 in September. Part of that is a company with $180 million in the bank funding a disclosure programme, and researchers looking at a 200,000-star target that holds credentials by design. Part of it is the surface. The titles repeat the same shapes: expression-sandbox escapes, prototype pollution in the XML, Merge and HTTP Request nodes, the Git node executing repository configuration, task-runner escapes, SSRF bypasses through the MCP client node, and a long tail of shared-workflow editors reading credentials they should not. The platform's job is to evaluate user-supplied expressions and call user-configured endpoints with stored secrets, and each of those is a vulnerability class waiting for a bypass.
Three holes matter more than the rest. CVE-2025-68613, published 19 December 2025, let any user who could edit a workflow run code with the n8n process's privileges through the expression evaluator, in every version from 0.211.0 to the fixes in 1.120.4, 1.121.1 and 1.122.0; GitHub scored it 9.9, NVD 8.8. CISA added it to the Known Exploited Vulnerabilities catalogue on 11 March 2026 after Akamai caught Zerobot, a Mirai-derived botnet, exploiting it against honeypots from mid-January. A botnet that normally eats routers decided an automation server was worth the effort, which tells you what is on the box. Then CVE-2026-21858, "Ni8mare", CVSS 10.0, needing no account: a content-type confusion in webhook parsing that let anyone read files off any instance running a public form with a file field, versions 1.65.0 to 1.121.0. Cyera reported it on 9 November 2025, the fix shipped on 18 November, and when the advisory went public on 7 January the Shadowserver Foundation counted 59,558 still-exposed instances, more than 28,000 of them in the United States, seven weeks after the patch. And CVE-2026-25049, CVSS 9.9, another expression escape found by three teams independently and fixed in 1.123.17 and 2.5.2, which BleepingComputer summarised with Pillar Security's line that if you can create a workflow you can own the server. That has been true of every workflow engine ever built; what changed in 2026 is that the things creating workflows are, by design, language models reading untrusted input.
n8n's response was structural, and I respect it. Version 2.0, released 8 December 2025, turned task runners on by default so Code nodes stop executing in the main process, removed the runner from the main image so external mode means a separate n8nio/runners sidecar, replaced the Pyodide Python node with native Python that only works through that sidecar, flipped N8N_BLOCK_ENV_ACCESS_IN_NODE to true, and dropped MySQL and MariaDB for Postgres. The docs now call internal-mode runners "insecure by design". Ten of the 19 critical advisories in 2026 are still expression-sandbox, runner or prototype-pollution escapes, because a sandbox inside a Node.js process is a sandbox made of JavaScript; I argued why that is not a boundary in the isolation post, and n8n's changelog is now the better argument.
Langflow, Dify and the one that gave up
If n8n's record is a well-funded project discovering its surface, Langflow's is the surface discovered first by attackers. CVE-2025-3248, CVSS 9.8, was an unauthenticated /api/v1/validate/code endpoint that passed request bodies to Python's exec(); Horizon3 reported that the code had been there since the earliest versions and that Censys saw more than 500 exposed instances. The fix shipped in 1.3.0 on 31 March 2025, CISA added it to KEV on 5 May and later flagged ransomware use. This year five more Langflow CVEs joined it: CVE-2026-33017 in March, a second unauthenticated exec() path through the public flow-build endpoint which Sysdig saw exploited 20 hours after the advisory, with no public proof of concept because the advisory was the proof of concept; CVE-2025-34291 in May, a CORS chain to token theft; CVE-2026-55255 and CVE-2026-0770 in July, an IDOR to run other users' flows and unauthenticated code execution as root; and CVE-2026-9198 in August, filed by IBM, which owns Langflow through DataStax, chaining an auto_login endpoint that minted superuser tokens with the same validate/code endpoint in every release from 1.0.0 to 1.10.0. Thirty-seven advisories, 16 critical in 2026, MIT-licensed, 155,000 stars, six entries in the exploited list.
Dify, with 158,000 stars, is the quieter case: 21 advisories since 2025, 13 this year, none critical, none in KEV. The worst were a plaintext model-provider API key exposure in January, an unauthenticated SSRF scored 8.3 in May, and cross-tenant disclosures in July. Its licence is Apache 2.0 with riders, no multi-tenant operation without permission and no removing the logo, plus a clause reserving the right to make the terms "more strict or relaxed as deemed necessary", a sentence to read twice before building on it. And Flowise, 55,000 stars, Apache 2.0, archived itself on 13 August after a final 3.1.4 release; its maintainer's reasoning, that visual agent builders hit a complexity wall as coding agents improve, I quoted in September. It was right about the canvas and silent about the credentials.
Running n8n like a service rather than a toy
Most of those 59,558 hosts are the one-container SQLite deployment from a tutorial. The production shape in n8n's own documentation, which I read end to end for this, is different. EXECUTIONS_MODE=queue puts jobs in Redis for separate worker processes; a webhook tier takes HTTP off the main process, which you switch off for production webhooks with N8N_DISABLE_PRODUCTION_MAIN_PROCESS. Manual test runs stay on main unless OFFLOAD_MANUAL_EXECUTIONS_TO_WORKERS=true, which the docs say is the only production configuration. Every worker needs its own runners sidecar at the same version, reaching the broker on port 5679 with a shared N8N_RUNNERS_AUTH_TOKEN. Credentials are encrypted with N8N_ENCRYPTION_KEY, which n8n generates on first boot if you do not and which you must back up or lose every stored secret on a rebuild; any variable takes a _FILE suffix for Docker or Kubernetes secrets. Execution data prunes after 336 hours and 10,000 records by default, and it contains the full input and output of every node, meaning every API response and every prompt. Multi-main for high availability needs an enterprise licence.
# docker-compose.yml: n8n 2.41.6 in queue mode, hardened. Postgres 16, Redis 7,
# one main, one webhook processor, two workers, one runners sidecar per worker.
# Secrets come from ./secrets/* via the _FILE suffix, never from this file.
x-n8n-env: &n8n-env
DB_TYPE: postgresdb
DB_POSTGRESDB_HOST: postgres
DB_POSTGRESDB_PORT: "5432"
DB_POSTGRESDB_DATABASE: n8n
DB_POSTGRESDB_USER: n8n
DB_POSTGRESDB_PASSWORD_FILE: /run/secrets/pg_password
N8N_ENCRYPTION_KEY_FILE: /run/secrets/n8n_encryption_key # back this up; it decrypts every credential
EXECUTIONS_MODE: queue
QUEUE_BULL_REDIS_HOST: redis
QUEUE_HEALTH_CHECK_ACTIVE: "true"
OFFLOAD_MANUAL_EXECUTIONS_TO_WORKERS: "true" # main never runs user code
N8N_RUNNERS_MODE: external # Code node runs in the sidecar, not here
N8N_RUNNERS_AUTH_TOKEN_FILE: /run/secrets/runners_token
N8N_BLOCK_ENV_ACCESS_IN_NODE: "true" # 2.0 default; set anyway
N8N_BLOCK_FILE_ACCESS_TO_N8N_FILES: "true"
N8N_RESTRICT_FILE_ACCESS_TO: /files
N8N_GIT_NODE_DISABLE_BARE_REPOS: "true"
NODES_EXCLUDE: '["n8n-nodes-base.executeCommand","n8n-nodes-base.localFileTrigger","n8n-nodes-base.ssh"]'
N8N_PUBLIC_API_DISABLED: "true"
N8N_DIAGNOSTICS_ENABLED: "false"
N8N_SECURE_COOKIE: "true"
N8N_PROXY_HOPS: "1" # behind one TLS-terminating proxy
EXECUTIONS_DATA_PRUNE: "true"
EXECUTIONS_DATA_MAX_AGE: "168" # execution data holds prompts and API responses
EXECUTIONS_DATA_PRUNE_MAX_COUNT: "50000"
N8N_HOST: flows.example.com
N8N_PROTOCOL: https
WEBHOOK_URL: https://flows.example.com/
GENERIC_TIMEZONE: UTC
services:
postgres:
image: postgres:16-alpine
environment:
POSTGRES_DB: n8n
POSTGRES_USER: n8n
POSTGRES_PASSWORD_FILE: /run/secrets/pg_password
secrets: [pg_password]
volumes: ["pg_data:/var/lib/postgresql/data"]
healthcheck:
test: ["CMD-SHELL", "pg_isready -U n8n -d n8n"]
interval: 5s
retries: 10
redis:
image: redis:7-alpine
command: ["redis-server", "--maxmemory-policy", "noeviction"] # queued jobs must not be evicted
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 5s
retries: 10
n8n-main:
image: n8nio/n8n:2.41.6
environment:
<<: *n8n-env
N8N_DISABLE_PRODUCTION_MAIN_PROCESS: "true" # webhooks go to the webhook tier
secrets: [pg_password, n8n_encryption_key, runners_token]
ports: ["127.0.0.1:5678:5678"] # editor only via the reverse proxy
volumes: ["n8n_data:/home/node/.n8n"]
depends_on:
postgres: {condition: service_healthy}
redis: {condition: service_healthy}
n8n-webhook:
image: n8nio/n8n:2.41.6
command: webhook # receives production webhooks, enqueues
environment: *n8n-env
secrets: [pg_password, n8n_encryption_key, runners_token]
ports: ["127.0.0.1:5679:5678"] # proxy /webhook/* here, behind auth
depends_on: [n8n-main]
n8n-worker:
image: n8nio/n8n:2.41.6
command: worker --concurrency=10
environment:
<<: *n8n-env
N8N_RUNNERS_BROKER_LISTEN_ADDRESS: 0.0.0.0 # sidecar connects over the compose network
secrets: [pg_password, n8n_encryption_key, runners_token]
deploy: {replicas: 2}
depends_on: [n8n-main]
n8n-runners:
image: n8nio/runners:2.41.6 # must match the n8n image version
environment:
N8N_RUNNERS_TASK_BROKER_URI: http://n8n-worker:5679
N8N_RUNNERS_AUTH_TOKEN_FILE: /run/secrets/runners_token
secrets: [runners_token]
deploy: {replicas: 2}
depends_on: [n8n-worker]
secrets:
pg_password: {file: ./secrets/pg_password}
n8n_encryption_key: {file: ./secrets/n8n_encryption_key} # openssl rand -hex 32
runners_token: {file: ./secrets/runners_token}
volumes:
pg_data:
n8n_data:
Two things this file does not fix. The runners sidecar is a Node.js and Python process on the same network as the worker, so a sandbox escape still ends on a box with the encryption key mounted; if the workflows run code an agent wrote, the sidecar belongs in its own VM, which is the design decision behind PandaFlow. And the webhook tier is a public HTTP surface whose authentication is whatever each trigger node says it is; Ni8mare was a webhook bug, and September's advisories include unauthenticated cross-project execution via webhook path resolution, so put an authenticating gateway in front of it. On cost, n8n Cloud's Starter plan is EUR 20 a month for 2,500 executions counted per workflow run, where Zapier's $19.99 buys 750 tasks counted per step and Copilot Studio's $200 buys 25,000 credits at five per agent action. Self-hosting the stack above is a Postgres, a Redis and six containers before the first workflow, which is the operations bill the subscription was hiding.
The code alternative raised more than everyone else combined
The other half of the market has no canvas. Temporal, the durable-execution engine OpenAI, Snap and NVIDIA run on, raised $550 million at $12.55 billion on 14 September, seven months after a $300 million Series D at $5 billion, and disclosed what the no-code vendors do not: 4,300 paying customers up 139 percent, run-rate revenue up more than 200 percent, 1.9 trillion billable actions in August, 43 million open-source installs, OpenAI's usage up sixty-fold in a year. Its AI page lists integrations for the OpenAI Agents SDK, Pydantic AI, Vercel AI SDK, Google ADK, Mastra, Strands and Spring AI and names Replit, Retool and Gorgias as agent customers; the temporalio-openai-agents package reached 1.1.0 on 1 October as Production/Stable, routing each model call through an activity with its own timeout and retry policy while the agent loop lives in a replayable workflow. An agent is a long-running program with hundreds of model calls, waits and approvals, which is what workflow engines were built for twenty years before anyone called it an agent.
# Durable agent on Temporal: model calls become activities with their own retries.
from datetime import timedelta
from temporalio.client import Client
from temporalio.common import RetryPolicy
from temporalio.openai_agents import OpenAIAgentsPlugin, ModelActivityParameters # temporalio-openai-agents 1.1.0
client = await Client.connect(
"localhost:7233",
plugins=[OpenAIAgentsPlugin(model_params=ModelActivityParameters(
start_to_close_timeout=timedelta(seconds=60), # one model call, not the whole agent
retry_policy=RetryPolicy(maximum_attempts=5, initial_interval=timedelta(seconds=2)),
))],
)
# Agent.run(...) inside a @workflow.defn is now replayable; a worker crash resumes at the last completed call.
The rest of the field is smaller and moving the same way. Inngest raised a $21 million Series A in September 2025 under an SSPL licence with an Apache 2.0 conversion clause. Trigger.dev is Apache 2.0 at 4.7.2 on a $16 million Series A. Restate, under the Business Source License, announced a $20 million Series A led by Singular on 30 September, saying Replit moved Replit Agent's execution onto Restate, which sits oddly beside Temporal listing Replit as a customer and tells you both describe different pieces of the same company. DBOS keeps workflow state in Postgres under MIT at 3.2.0; I found no funding announcement and have not guessed one. None of these has a KEV entry, partly because none evaluates user-supplied expressions or ships 400 connectors with stored OAuth tokens. They execute your code, with your credentials, in your process, and the security model is yours: a worse product for a marketing manager, a far better one for an engineer, which is the whole divide.
Where PandaFlow sits, and the disclosure
PandaFlow is my attempt at the obvious synthesis and it is early: an MIT-licensed visual builder with around 160 nodes, every one of which executes inside a PandaStack Firecracker microVM rather than in the orchestrator's process. It has nine GitHub stars, no tagged release, and no advisories because nobody has looked, which is not the same as being secure. PandaStack is the microVM platform I built and operate, so when I say the runners belong in their own VM I am recommending the product I sell. The honest form of the argument: the no-code vendors proved the canvas is what people buy, the advisory record proved the orchestrator must not be the sandbox, and the durable-execution vendors proved engineers will pay $12.55 billion of attention for a runtime that resumes after a crash. A tool that is all three does not quite exist yet. Mine is a draft of one.
What I take from the year is that workflow automation is now a security product whether its vendors like it or not. Agents turned the canvas into an execution engine for untrusted instructions, the credentials stayed in the same database, and the exploitation gap on Langflow shrank to 20 hours. This quarter I will move the one n8n I run onto the compose file above, webhook tier behind my gateway and runners in a VM, and stop pretending a release train with 49 advisories a month can be patched quarterly. Treat the automation server the way you already treat your CI runner: the machine that holds every key, operated by whoever can push a workflow to it, which now includes a model.
Related: No-Code Didn't Die. It Sold for 2.7x ARR While Its Replacement Raised at 27x, MCP Security in 2026: The Protocol Got Hardened. The Ecosystem Didn't. and It's 2 AM. Do You Know What Your AI Agent Is Doing?.
I'm Ajay Kumar — I build and operate PandaStack, an open-source Firecracker microVM cloud for AI agents. Everything above comes from running it in production.
Need this kind of infrastructure work? See what I do or email hello@ajayk.sh.
Related
AI SOC Agents in 2026: 98% Accuracy Claims, 23 to 34% on the Benchmark, and 0% of Teams Letting Them Act Alone
What the security-operations agents from Microsoft, Google, CrowdStrike, Palo Alto, SentinelOne, Torq and a billion-dollar startup cohort actually do in 2026 and what is measured: a median of 100 alerts a day and 28 percent never investigated, 75-minute mean investigations, Microsoft's $4-an-hour compute units and Google's token meter, CrowdStrike's 98 percent triage claim against Meta's 23 to 34 percent benchmark, Anthropic's and Google's reports of attackers running agents against defenders, and a Sigma rule and CI step that keep a human on the merge button.
14 minOct 5, 2026CI/CD in 2026: Agents Opened 1M PRs in 5 Months, Bots Write 1 in 5 Reviews, and Most Agent PRs Get No Human Look
What the pipeline looks like when AI agents open the pull requests: GitHub's coding agent went GA on 25 September 2025 and opened over a million PRs in five months, Copilot code review passed 60 million reviews and one in five on GitHub, CodeRabbit has reviewed 13 million PRs on $88 million raised, and the first studies find most agent PRs get no human review attention. The gates that still hold: the assigner cannot approve, an extra approval for bot authors, path fences, signed commits, SLSA provenance, and a workflow YAML that gives agent PRs their own lane.
13 minSep 8, 2026AI Found the Bugs: 23,000 Findings in a Month, a 3-Day Patch Mandate, and the End of curl's Bounty
From AIxCC's 18 real bugs in August 2025 to Project Glasswing's 23,019 findings by May 2026 and the first AI-written zero-day exploited in the wild. What the cyber reasoning systems, Big Sleep, Codex Security and Mythos Preview actually did, why bug bounties are drowning, why CISA now wants federal patches in three days, and a workflow for a small team that keeps the humans looking only at validated findings.
13 min