Path Traversal Vulnerability in n8n Automation Platform
CVE-2026-103254
7HIGH
What is CVE-2026-103254?
A path traversal vulnerability exists in n8n, affecting certain versions, where attackers with workflow creation permissions can generate valid approval URLs that lead to unauthorized access to project gates. By exploiting unresolved traversal sequences in caller-controlled node IDs, these attackers can create approval links for projects they wouldn't normally be allowed to access, thus enabling cross-project approval forgery.
Affected Version(s)
n8n 0 < 1.123.80
n8n 2.0.0 < 2.39.6
n8n 2.40.0 < 2.40.1
