Upgrade Path

n8n 1.108.0 → 1.109.0

2 versions, 1 with breaking changes, 0 required stops

Version by version, oldest first

1.108.1: no action items (1 version)

1.108.2: released after 1.109.0; not on this route

1.109.0 2025-08-25

Breaking

What changed?

Webhook HTML responses were sandboxed to an iframe starting from 1.103.1 due to security. The sandboxing mechanism is now changed to use Content-Security-Policy header instead of an iframe. The security guarantees stay the same, but the mechanism is less breaking.

When is action necessary?

If you have workflows that return HTML responses from Webhook Trigger node or Respond to Webhook node.

From github.com/n8n-io/n8n/blob/master/packages/cli/BREAKING-CHANGES.md

Full release notes for 1.109.0

Release notes from github.com/n8n-io/n8n/releases, and packages/cli/BREAKING-CHANGES.md, and CHANGELOG.md, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. n8n keeps its breaking changes in packages/cli/BREAKING-CHANGES.md, one section per version (“What changed?”, “When is action necessary?”); each section is quoted whole as “Breaking” on its version. The “BREAKING CHANGES” sections of CHANGELOG.md (0.198.0, 1.0.0, 1.27.0) are quoted too, and each section of the docs page “n8n 2.0 breaking changes” is quoted as “Upgrade guide” on 2.0.0. GitHub release notes are commit lists and are not quoted. Versions come from npm (package n8n). No required stop is recorded: neither file nor the 2.0 page names a version to install first.