Executive brief
n8n is a workflow automation platform that allows users to create and execute tasks programmatically. When Task Runners are enabled, authenticated users can execute custom code through a Code Node. Due to unsafe buffer allocation in the task runner sandbox, an authenticated attacker can exploit this to read uninitialized memory from the same Node.js process, potentially exposing sensitive data like API tokens, secrets, or data from prior requests, causing information disclosure.
Technical details
The vulnerability exists in n8n's task runner sandbox, which exposes unsafe Node.js Buffer functions (Buffer.allocUnsafe() and Buffer.allocUnsafeSlow()) to untrusted code. These functions allocate uninitialized memory that may contain residual data from previous process operations. An authenticated user can execute arbitrary code through the Code Node when Task Runners are enabled (N8N_RUNNERS_ENABLED=true) to allocate such buffers and read sensitive data including secrets, API tokens, and data from prior requests or tasks. The vulnerability requires both Task Runners to be enabled and the Code Node to be available, and only affects authenticated users. The fix (v1.114.3+) removes access to unsafe Buffer functions and routes all allocations through Buffer.alloc(), which zero-fills memory by default. Regression tests have been added to enforce safe allocation practices.
Affected products
- n8n n8n >=1.65.0, <1.114.3
Timeline
- 2026-02-04: disclosed
- 2026-02-04: patched: Fixed in versions 1.114.3 and 1.115.0