Missing Authorization in n8n - #VU150763

 

Missing Authorization in n8n - #VU150763

Published: September 17, 2026


Vulnerability identifier: #VU150763
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to install and load arbitrary npm packages on every instance in an n8n cluster.

The vulnerability exists due to improper authorization in the internal community package installation handler when processing PubSub messages through Redis in queue mode. A remote user can write a crafted message to the Redis instance to install and load an arbitrary npm package.

No n8n account is required.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.80, 2.39.6, 2.40.1

External References

Related Security Bulletins