#VU122482 Arbitrary file upload in n8n - CVE-2026-25056
Published: February 9, 2026
n8n
n8n
Description
The vulnerability allows a remote user to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload in the Merge node's SQL Query mode. A remote user with permission to create or modify workflows can write arbitrary files to the n8n server's filesystem and execute them on the server.