Junglewise Threat Intelligence

CVE-2025-57749: n8n symlink traversal in Read/Write File node

CVE-2025-57749 · Severity: low · CVSS 3.1 · Published 2025-08-20

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and execute automated processes. The Read/Write File node in n8n attempts to restrict access to sensitive directories, but fails to account for symbolic links, allowing authenticated attackers to bypass these restrictions and access files outside the intended boundaries. This could expose sensitive data or permit unauthorized file modifications.

Technical details

The vulnerability is a symlink traversal (CWE-59, CWE-61) in n8n's Read/Write File node. While the node implements directory restrictions to prevent access to sensitive files, it does not properly validate or resolve symbolic links before performing file operations. An authenticated attacker who can create symlinks (e.g., via the Execute Command node) can craft a symlink pointing to a restricted path, allowing the Read/Write File node to read from or write to files outside the intended directory restrictions. The vulnerability requires network access and valid credentials (PR:L). Patch available in version 1.106.0 and later.

Affected products

  • n8n n8n before 1.106.0

Timeline

  • 2025-08-20: disclosed
  • 2025-08-20: patched: Patch available in version 1.106.0

References

Related threats