Junglewise Threat Intelligence

CVE-2026-25052: n8n arbitrary file read in file access controls

CVE-2026-25052 · Severity: medium · CVSS 4 · Published 2026-02-04

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows organizations to build and execute automated business processes. A flaw in its file access controls allows authenticated workflow creators to read sensitive files from the server, potentially exposing configuration data and user credentials that could lead to complete takeover of user accounts on the instance.

Technical details

The vulnerability stems from improper file access controls in n8n's file handling mechanism. Authenticated users with permission to create or modify workflows can exploit this to read arbitrary files from the n8n host system, including sensitive configuration and credential files. The attack requires authentication and workflow creation/modification privileges, but no user interaction. The vulnerability was introduced in version 2.0.0 and affects all versions prior to 1.123.18 and 2.5.0, which contain the fix. Workarounds include restricting workflow permissions and disabling file system interaction nodes like "Read/Write Files from Disk" and "Git".

Affected products

  • n8n n8n < 1.123.18, 2.0.0 to < 2.5.0

Timeline

  • 2026-02-04: disclosed
  • 2026-02-04: patched: Fixed in n8n versions 1.123.18 and 2.5.0

References

Related threats