Executive brief
n8n is a workflow automation platform that allows organizations to build and execute automated business processes. A flaw in its file access controls allows authenticated workflow creators to read sensitive files from the server, potentially exposing configuration data and user credentials that could lead to complete takeover of user accounts on the instance.
Technical details
The vulnerability stems from improper file access controls in n8n's file handling mechanism. Authenticated users with permission to create or modify workflows can exploit this to read arbitrary files from the n8n host system, including sensitive configuration and credential files. The attack requires authentication and workflow creation/modification privileges, but no user interaction. The vulnerability was introduced in version 2.0.0 and affects all versions prior to 1.123.18 and 2.5.0, which contain the fix. Workarounds include restricting workflow permissions and disabling file system interaction nodes like "Read/Write Files from Disk" and "Git".
Affected products
- n8n n8n < 1.123.18, 2.0.0 to < 2.5.0
Timeline
- 2026-02-04: disclosed
- 2026-02-04: patched: Fixed in n8n versions 1.123.18 and 2.5.0