Path Traversal Vulnerability in n8n by n8n.io
CVE-2026-103257

8.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103257?

A path traversal vulnerability exists in n8n due to improper validation of resource identifiers in the n8n node. This flaw allows attackers to craft malicious resource IDs, redirecting API calls to unintended resources. Consequently, this can lead to unauthorized access to sensitive workflows, executions, and credential secrets associated with the API key. Users of affected versions are advised to update their installations promptly to mitigate this vulnerability.

Affected Version(s)

n8n 0 < 1.123.80

n8n 2.0.0 < 2.39.6

n8n 2.40.0 < 2.40.1

References

CVSS V4

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nlgbao1340
.