#VU122482 Arbitrary file upload in n8n - CVE-2026-25056

 

#VU122482 Arbitrary file upload in n8n - CVE-2026-25056

Published: February 9, 2026


Vulnerability identifier: #VU122482
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-25056
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
n8n
Software vendor:
n8n

Description

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload in the Merge node's SQL Query mode. A remote user with permission to create or modify workflows can write arbitrary files to the n8n server's filesystem and execute them on the server.


Remediation

Install updates from vendor's website.

External links