Missing Authorization in n8n - #VU150763
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to install and load arbitrary npm packages on every instance in an n8n cluster.
The vulnerability exists due to improper authorization in the internal community package installation handler when processing PubSub messages through Redis in queue mode. A remote user can write a crafted message to the Redis instance to install and load an arbitrary npm package.
No n8n account is required.