Path Traversal Vulnerability in n8n Automation Platform
CVE-2026-103254

7HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103254?

A path traversal vulnerability exists in n8n, affecting certain versions, where attackers with workflow creation permissions can generate valid approval URLs that lead to unauthorized access to project gates. By exploiting unresolved traversal sequences in caller-controlled node IDs, these attackers can create approval links for projects they wouldn't normally be allowed to access, thus enabling cross-project approval forgery.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tr4ce-ju
.