Junglewise Threat Intelligence

CVE-2026-25056: n8n Merge Node arbitrary file write leading to RCE

CVE-2026-25056 · Severity: medium · CVSS 4 · Published 2026-02-04

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and manage data processing workflows. A vulnerability in the Merge node's SQL Query mode allows authenticated workflow creators to write arbitrary files to the server filesystem, potentially leading to remote code execution and complete system compromise.

Technical details

The vulnerability exists in the Merge node's SQL Query mode, which improperly validates or sanitizes file paths, enabling authenticated users to write arbitrary files to the n8n server's filesystem (CWE-434: Unrestricted Upload of File with Dangerous Type, CWE-693: Protection Mechanism Failure). An attacker with workflow creation or modification permissions can exploit this via the network to write malicious files—such as executable scripts or configuration files—that execute code with n8n process privileges. The attack requires authentication and workflow editing privileges but no user interaction. The vulnerability affects n8n versions prior to 1.118.0 and 2.0.0 through 2.3.x; patches are available in versions 1.118.0 and 2.4.0.

Affected products

  • n8n n8n < 1.118.0 and >= 2.0.0, < 2.4.0

Timeline

  • 2026-02-04: disclosed: GHSA-hv53-3329-vmrm published
  • 2026-02-04: patched: Patches released in versions 1.118.0 and 2.4.0

References

Related threats