Description
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can craft malicious resource IDs to redirect API calls to unintended resources, allowing unauthorized access to workflows, executions, and credential secrets within the API key's scope.
Published: 2026-10-01
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access to Sensitive Data
Action: Immediate Patch
AI Analysis

Impact

A path traversal vulnerability exists in the n8n node of n8n versions before 1.123.80, 2.39.6, and 2.40.1 because resource identifiers are not properly validated. Attackers can construct malicious resource IDs that redirect API calls to unintended resources, giving the attacker unauthorized visibility into workflows, executions, and credential secrets that fall within the scope of the credentialed API key used for the request. The flaw therefore allows an attacker to read, modify, or delete sensitive automation data and secrets that were otherwise protected by the API key’s access controls.

Affected Systems

The vulnerability affects n8n-io’s n8n product. It is present in every release prior to 1.123.80, prior to 2.39.6, and prior to 2.40.1, inclusive of all earlier 2.x versions.

Risk and Exploitability

The CVSS score of 8.1 indicates a high impact, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote delivery of crafted API requests that include the vulnerable node; the attacker must have an API key with permissions that cover the target workflow or credential resources. The likely attack vector is over the network, leveraging the exposed n8n API. Because the flaw permits access to sensitive data within the key’s privilege set, it can lead to data exfiltration or compromise of automation logic while targeting a single n8n deployment.

Generated by OpenCVE AI on October 1, 2026 at 14:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the n8n installation to at least version 1.123.80, 2.39.6, or 2.40.1 on all affected nodes.
  • Revoke or regenerate any API keys that may have been exposed, and apply the principle of least privilege, restricting keys to only the workflow and credential access they truly require.
  • Audit and monitor API usage logs for anomalous access patterns, and consider implementing IP whitelisting or rate limiting on the n8n API endpoints to reduce the attack surface while remediation is in progress.

Generated by OpenCVE AI on October 1, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can craft malicious resource IDs to redirect API calls to unintended resources, allowing unauthorized access to workflows, executions, and credential secrets within the API key's scope.
Title n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node
First Time appeared N8n
N8n n8n
Weaknesses CWE-22
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T14:53:57.023Z

Reserved: 2026-09-30T10:55:39.869Z

Link: CVE-2026-103257

cve-icon Vulnrichment

Updated: 2026-10-01T14:45:49.335Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:20.100

Modified: 2026-10-01T15:17:26.453

Link: CVE-2026-103257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T00:45:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')