Improper access control in n8n - #VU140999
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote user to read and overwrite arbitrary local files on the n8n host.
The vulnerability exists due to improper access control in the Snowflake node when processing free-form Execute Query input. A remote user can submit queries containing client-side commands to read and overwrite arbitrary local files on the n8n host.
Exploitation requires usable Snowflake credentials.