CVE-2026-103257High· 7.7▾ Twilightn8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can craft malicious resource IDs to redir…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can craft malicious resource IDs to redirect API calls to unintended resources, allowing unauthorized access to workflows, executions, and credential secrets within the API key's scope.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103254Medium· 6.3n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals
CVE-2026-86079Medium· 6.5n8n is an open source workflow automation platform
GHSA-gf29-4f56-r2jfHighn8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-pf2q-pxhf-hgmwMediumn8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
CVE-2026-49465Medium· 7.7n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-103260Medium· 4.0n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode