CORTEXFLOW · FREE FOREVER
Automation
n8n Security Advisory Triage
↓ Download workflow JSON
Import in n8n: Workflows → ⋯ → Import from file, then add your credentials. Free download with a free account.
How it works
Your daily security guard for self-hosted n8n. In October 2026 GitHub published the largest single batch of n8n security advisories to date — 10 High + 4 Medium GHSA items, fixed in n8n 2.41.4 / 2.42.1. Miss those and your instance stays exposed. This workflow watches the GitHub Advisory Database and tells you within hours whether YOUR version is affected:
- STEP 1 — Daily trigger + fetch GitHub advisories — a 7 AM schedule trigger pulls the latest n8n advisories from the GitHub Advisory Database (npm ecosystem). No auth needed.
- STEP 2 — Dedupe vs seen IDs + log NEW — the workflow reads the GHSA IDs already in your Google Sheet, keeps only genuinely fresh advisories, and appends them with status
NEW. On quiet days you just get a short all-clear Telegram message. - STEP 3 — AI impact assessment vs YOUR version — an AI Agent compares each advisory’s vulnerable version range against your configured n8n version and returns a structured verdict (
severity,is_my_version_affected,patch_action, one-line summary) via a Structured Output Parser. The sheet flips toASSESSED. - STEP 4 — Urgent alerts + daily digest — advisories that affect your version AND are high or critical severity fire an instant 🚨 Telegram alert with the patch action and advisory link, and the sheet flips to
NOTIFIED_URGENT. Both branches then merge into one daily digest on Telegram: new advisories triaged plus the urgent ones worth patching now.
Status flow in Sheets: NEW → ASSESSED → NOTIFIED_URGENT
Set up steps
You’ll need:
- n8n (self-hosted or cloud)
- An OpenAI API key — platform.openai.com → API keys
- A Google Sheets OAuth2 credential — n8n Credentials → New → Google Sheets OAuth2 (Google account sign-in)
- A Telegram bot — message @BotFather, send
/newbot, copy the token; get your chat ID from @userinfobot - Your n8n version — in n8n: Settings → About
Steps:
- Import the workflow — in n8n, Workflows → Import from File → select
n8n-security-advisory-triage.json. - CONFIG — Instance — open the Set node and fill in:
n8n_version— e.g.2.41.6(find it in n8n under Settings → About). This is what the AI compares against every advisory’s vulnerable range.github_token— optional, leave empty. Only add a token (generate one at github.com/settings/tokens) if you ever hit GitHub’s unauthenticated rate limit.
- CONFIG — Google Sheets — create a Google Sheet with a tab named
Advisoriesand headers:GHSA ID | Published | Severity | Affected Versions | My Version Affected | Patch Action | Status. Paste the spreadsheet ID intospreadsheet_id. Then select your Google Sheets credential in the four Sheets nodes. - OpenAI — select your OpenAI credential in the
OpenAI Chat Model — Assessmentnode (gpt-4o-miniis the default; plenty for this task). - CONFIG — Notifications — paste your Telegram chat ID, select your Telegram credential, and activate the workflow. The first run fires at 7 AM the next morning (use “Execute workflow” to test immediately).
Customize it
- Watch more than n8n — change the
affectsquery param in theFetch n8n AdvisoriesHTTP node (e.g.affects=langchain, or drop the filter and post-filter by ecosystem in theFilter New Advisoriescode node). - Lower the urgency bar — in
Compute Urgency, add"moderate"to the severity list so medium advisories affecting your version also fire instant alerts. - Add Slack alongside Telegram — clone the
Telegram — URGENT Security Alertnode, swap in an n8n-nodes-base.slack node, and connect it to the same TRUE branch ofIF — Urgent?. - Run hourly during active incident windows — change the Schedule Trigger from daily 7 AM to hourly; the GHSA-ID dedupe keeps it safe at any cadence (GitHub allows 60 unauthenticated requests/hour, plenty for hourly polling).
- Track patching — add a
Patchedcolumn to the sheet and flipNOTIFIED_URGENTrows manually after upgrading, so your history doubles as a patch log.