Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals. Attackers with workflow creation permissions can mint valid approval URLs for gates in projects they cannot access by exploiting unresolved traversal sequences in caller-controlled node IDs, enabling cross-project approval forgery.
Published: 2026-10-01
Score: 7 High
EPSS: n/a
KEV: No
Impact: Unauthorized workflow approval forging via path traversal
Action: Patch Now
AI Analysis

Impact

This vulnerability arises from a path‑traversal flaw in the generation of signed resume URLs used by Send‑and‑Wait approval gates in n8n. Because node identifiers can be supplied by a workflow creator, the signed URL can reference folders outside the intended project, enabling an attacker with workflow creation rights to craft a URL that targets an approval step in a project that the attacker otherwise cannot access. This bypasses normal access controls and leads to unauthorized approval of workflow steps, constituting a form of privilege escalation or workflow forgery.

Affected Systems

The issue affects n8n and all releases before 1.123.80, 2.39.6, and 2.40.1, as issued by n8n‑io. The vulnerability is tied to the CVE-2026-103254 ID and is documented by n8n’s advisory. Versions from 1.123.80 onward, 2.39.6 onward, and 2.40.1 onward include the fixed signed URL handling logic and are not impacted.

Risk and Exploitability

With a CVSS score of 7 the flaw is classified as high severity, yet its Exploit Prediction Scoring System (EPSS) score is not published, and it is not currently listed in the CISA KEV catalog. The exploit requires an attacker to possess workflow‑creation permissions and to manipulate node identifiers, prerequisites that limit the attack surface. Nonetheless, for organizations that delegate workflow creation to users who are not fully trusted, the vulnerability presents a medium‑to‑high risk of cross‑project approval forgery and related workflow execution misconduct.

Generated by OpenCVE AI on October 1, 2026 at 14:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update n8n to version 1.123.80 or later, or 2.39.6 or 2.40.1, to apply the signed URL handling fix.
  • Limit workflow creation rights to trusted users to avoid attackers with that capability from forging approval URLs.
  • Disable or tightly monitor the Send‑and‑Wait approval feature to reduce exposure.

Generated by OpenCVE AI on October 1, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals. Attackers with workflow creation permissions can mint valid approval URLs for gates in projects they cannot access by exploiting unresolved traversal sequences in caller-controlled node IDs, enabling cross-project approval forgery.
Title n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation
First Time appeared N8n
N8n n8n
Weaknesses CWE-22
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:41:59.325Z

Reserved: 2026-09-30T10:55:39.868Z

Link: CVE-2026-103254

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:19.537

Modified: 2026-10-01T11:17:19.660

Link: CVE-2026-103254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:30:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')