Description
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.
Published: 2026-08-20
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Read/Write
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an arbitrary file read and write flaw in the Snowflake node of n8n. The node passes free‑form Execute Query input, including client‑side commands, directly to the Snowflake SDK without applying n8n's file‑access restrictions. The result is that an authenticated user who can supply valid Snowflake credentials can upload a local file from the n8n host or overwrite an existing file that has been staged in Snowflake. This creates a confidentiality risk by allowing disclosure of arbitrary host files and a integrity risk by permitting modification of files that should be protected.

Affected Systems

vulnerable versions are n8n‑io:n8n before 1.123.69, n8n‑io:n8n before 2.33.4 for 2.x releases, and n8n‑io:n8n before 2.34.1 for 2.34.x releases. Systems running any of these versions are at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, but the EPSS score is not available, so the estimated likelihood of exploitation cannot be quantified from publicly available data. The vulnerability is listed in CISA KEV as not listed, meaning no confirmed exploit is widely reported yet. The typical attack vector is a legitimate authenticated user who has Snowflake credentials and uses the Snowflake node in a workflow; the user can then submit arbitrary queries that result in file read/write operations on the n8n host. Because the flaw requires authentication, the attack is limited to users with valid Snowflake access, but once that access is granted, the attacker can read or modify arbitrary files on the host system.

Generated by OpenCVE AI on August 20, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update n8n to version 1.123.69 or later, or 2.33.4 or later, or 2.34.1 or later, depending on the installation branch.
  • Re‑evaluate the Snowflake credentials used in workflows and restrict them to the minimal set of permissions required; avoid granting generic or elevated rights that allow file staging or access to host paths.
  • If an upgrade cannot be performed immediately, limit the use of the Snowflake node to trusted users only and monitor workflow logs for suspicious file read or write activity.

Generated by OpenCVE AI on August 20, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:2.34.0:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.
Title n8n before 1.123.69 Arbitrary File Read and Write via Snowflake
First Time appeared N8n
N8n n8n
Weaknesses CWE-78
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-21T11:21:20.831Z

Reserved: 2026-08-20T10:55:09.093Z

Link: CVE-2026-77080

cve-icon Vulnrichment

Updated: 2026-08-20T15:41:10.000Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T12:16:39.430

Modified: 2026-09-01T19:45:49.450

Link: CVE-2026-77080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:30:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')