Validation Bypass Vulnerability in n8n Community Package Installation by n8n
CVE-2026-103251

7.5HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103251?

A validation bypass vulnerability exists in n8n's community package installation handler for queue mode deployments. This issue affects versions of n8n prior to 1.123.80, as well as those between 2.0.0 and 2.39.6 and those from 2.40.0 to 2.40.1. Attackers with the ability to write to Redis can exploit this flaw, circumventing critical validation checks such as name validation, permission verifications, checksum validation, and npm safety checks. This allows for the installation of arbitrary npm packages across all cluster instances without requiring authentication.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AyushParkara
.