SQL Query Vulnerability in n8n Workflow Automation Platform by n8n
CVE-2026-25056
9.4CRITICAL
What is CVE-2026-25056?
The n8n workflow automation platform has a vulnerability in the Merge node's SQL Query mode, which could allow authenticated users with the appropriate permissions to create or modify workflows. This flaw enables these users to write arbitrary files to the n8n server's filesystem, posing a risk for remote code execution. It is imperative to upgrade to versions 1.118.0 and 2.4.0, where this issue has been resolved, to protect your system from potential exploits.
Affected Version(s)
n8n < 1.118.0 < 1.118.0
n8n < 2.4.0 < 2.4.0
