{"id":"CVE-2025-55526","title":"n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py","summary":"n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-22"],"vendor":"zie619","product":"n8n_workflow_collection","affected":["n8n_workflow_collection = 2025-06-29"],"published":"2025-08-26","updated":"2026-08-20","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-55526","references":[{"url":"https://github.com/Zie619/n8n-workflows/issues/48","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00809,"epssPercentile":0.55404,"ingestedAt":"2026-08-20T17:59:03.464Z","slug":"CVE-2025-55526","body":"## Overview\n\nn8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py\n\n## Affected\n\n- `n8n_workflow_collection = 2025-06-29`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}