Path traversal in n8n - #VU139113
Published: July 22, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the @n8n/computer-use search_files tool when processing a crafted search pattern. A remote user can supply a crafted search pattern to disclose sensitive information.
The issue can expose the names and contents of files outside the intended base directory, limited to files readable by the daemon's OS user.