Path traversal in n8n - #VU150766
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to forge approval decisions across projects.
The vulnerability exists due to path traversal in signed resume URL generation when resolving caller-controlled node IDs. A remote user can save a workflow containing traversal sequences in a node ID to forge approval decisions across projects.
Generated approval URLs remain valid for future workflow executions.