Skip to content

n8n data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On n8n, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the n8n connector needs.

Checks (3)

severity: medium n8n Workflow Agent Database Access fix difficulty: medium #

Review database access scope of the workflow

  1. Open the workflow editor
  2. Check database node queries for data scope
  3. Apply read-only credentials where possible

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: medium n8n Workflow Agent File Access fix difficulty: medium #

Review file access scope of the workflow

  1. Open the workflow editor
  2. Check file/FTP/cloud storage node configurations
  3. Restrict paths and permissions

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

severity: high n8n Workflow Agent Code Execution fix difficulty: medium #

Review code and command execution nodes

  1. Open the workflow editor
  2. Audit Code and Execute Command node contents
  3. Replace with safer alternatives where possible

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12

More n8n checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial