Path traversal in n8n - #VU146796

 

Path traversal in n8n - #VU146796

Published: September 2, 2026


Vulnerability identifier: #VU146796
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access unintended Elasticsearch endpoints.

The vulnerability exists due to improper input validation in Elasticsearch and ElasticSecurity nodes when building REST request paths from user-provided identifiers. A remote user can supply a specially crafted identifier containing path separators or dot segments to access unintended Elasticsearch endpoints.

Requests are sent under the stored Elasticsearch credential.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.76, 2.37.7, 2.38.2

External References

Related Security Bulletins