Validation Bypass Vulnerability in n8n Community Package Installation by n8n
CVE-2026-103251
7.5HIGH
What is CVE-2026-103251?
A validation bypass vulnerability exists in n8n's community package installation handler for queue mode deployments. This issue affects versions of n8n prior to 1.123.80, as well as those between 2.0.0 and 2.39.6 and those from 2.40.0 to 2.40.1. Attackers with the ability to write to Redis can exploit this flaw, circumventing critical validation checks such as name validation, permission verifications, checksum validation, and npm safety checks. This allows for the installation of arbitrary npm packages across all cluster instances without requiring authentication.
Affected Version(s)
n8n 0 < 1.123.80
n8n 2.0.0 < 2.39.6
n8n 2.40.0 < 2.40.1
