Arbitrary file upload in n8n - CVE-2026-25056

 

Arbitrary file upload in n8n - CVE-2026-25056

Published: February 9, 2026


Vulnerability identifier: #VU122482
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25056
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload in the Merge node's SQL Query mode. A remote user with permission to create or modify workflows can write arbitrary files to the n8n server's filesystem and execute them on the server.


Affected software

n8n

How to mitigate CVE-2026-25056

Install updates from vendor's website.

n8n - addressed in versions 1.118.0, 2.4.0

External References

Related Security Bulletins