Path Traversal Vulnerability in n8n Workflow Automation Tool
CVE-2026-72773

4.9MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72773?

The n8n workflow automation tool prior to version 2.31.5 and version 2.32.x prior to 2.32.1 has a vulnerability that allows attackers to execute crafted search patterns. This flaw enables bypassing of base-directory confinement checks, potentially exposing local files that are accessible by the daemon's operating system user. Any scenario where an actor can manipulate the search input is at risk, making it crucial for users to upgrade and secure their installations.

Affected Version(s)

n8n 0 < 2.32.1

n8n 0 < 2.31.5

n8n 2.32.1

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.