Evidence · DiggingBeagle record
n8n Docs: Risks of community nodes
n8n documentation warning that npm community nodes are unverified code and can create host, data and workflow risk; the documentation also describes verified nodes and administrative controls for community packages.
- Source role
- vendor statement
Evidence record
n8n documentation warning that npm community nodes are unverified code and can create host, data and workflow risk; the documentation also describes verified nodes and administrative controls for community packages.
Claim-level citations (1)
- supportsMalicious n8n community nodes exfiltrated stored integration credentials: n8n's own documentation warns that community nodes installed from npm are unverified code and can create risks to the host and workflow data, which is the authority boundary the malicious packages abused.
Risks of community nodes; verified community nodes; disabling community nodes
Cite this record
DiggingBeagle. “n8n Docs: Risks of community nodes.” https://diggingbeagle.com/sources/n8n-docs-risks-of-community-nodes/