SQL Query Vulnerability in n8n Workflow Automation Platform by n8n
CVE-2026-25056

9.4CRITICAL

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-25056?

The n8n workflow automation platform has a vulnerability in the Merge node's SQL Query mode, which could allow authenticated users with the appropriate permissions to create or modify workflows. This flaw enables these users to write arbitrary files to the n8n server's filesystem, posing a risk for remote code execution. It is imperative to upgrade to versions 1.118.0 and 2.4.0, where this issue has been resolved, to protect your system from potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

n8n < 1.118.0 < 1.118.0

n8n < 2.4.0 < 2.4.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.