Impact
n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) allows an authenticated user to upload arbitrary files to a temporary directory without checking if quota is already exhausted accumulate until the space on the host. This vulnerability satisfies CWE-770, as the application fails to enforce resource limits, and the impact is denial of service due to loss of disk capacity.
Affected Systems
n8n versions older than 2.28.0 on the 2.x branch or older than 1.123.58 on the 1.x branch are affected. The vulnerability exists in both the 1.x and 2.x product lines of n8n.
Risk and Exploitability
Moderate severity. The EPSS score is less than 1% and the vulnerability is not listed in KEV. It is inferred that the attack vector is via the web interface. The vulnerability does not allow remote code execution or privilege escalation.
OpenCVE Enrichment
Github GHSA