Path traversal in n8n - #VU139113

 

Path traversal in n8n - #VU139113

Published: July 22, 2026


Vulnerability identifier: #VU139113
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: n8n
Affected software:
n8n

Detailed vulnerability description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the @n8n/computer-use search_files tool when processing a crafted search pattern. A remote user can supply a crafted search pattern to disclose sensitive information.

The issue can expose the names and contents of files outside the intended base directory, limited to files readable by the daemon's OS user.


Remediation

Install security update from vendor's website.

Sources