CVE-2026-58661Medium▾ Sunlitn8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.4%
An authenticated user can repeatedly upload files to the data-table upload endpoint, bypassing the per-request quota check, which does not account for files already written to the shared temporary directory. This causes temporary files to accumulate on disk until the periodic cleanup runs, potentially exhausting available disk space on the host.
Users should upgrade to the patched version once available to remediate the vulnerability.
If upgrading is not immediately possible, administrators should consider the following temporary mitigations:
uploadMaxFileSize to a low value to limit individual upload size.These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
n8n >= 2.0.0, < 2.28.0n8n < 1.123.58Upgrade to a patched release:
n8n 2.28.0n8n 1.123.58Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86075High· 7.5n8n is an open source workflow automation platform
CVE-2026-59253Mediumn8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
CVE-2026-65014Mediumn8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform