Junglewise Threat Intelligence

CVE-2026-56352: n8n path traversal in legacy ExecuteWorkflow node

CVE-2026-56352 · Severity: medium · CVSS 6.4 · Published 2026-07-15

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and run automation jobs. The ExecuteWorkflow node contains a legacy feature (localFile source) that reads workflow files from disk without proper security checks. An authenticated user with permission to create or modify workflows can exploit this to read any file on the server or trigger unauthorized workflows, potentially exposing sensitive data or compromising downstream systems connected to those workflows.

Technical details

This is a path traversal / authorization bypass vulnerability in the ExecuteWorkflow node's localFile source option. The vulnerable component fails to apply the same file access restrictions (N8N_RESTRICT_FILE_ACCESS_TO) that other file-reading nodes enforce. An authenticated user with workflow creation/modification permissions can craft a malicious REST API request containing an arbitrary file path to bypass these restrictions. The attack does not require user interaction and can be executed over the network. An attacker can determine if arbitrary files exist on the server and, if the path points to a valid workflow JSON file, load and execute that workflow—potentially triggering unauthorized actions on downstream systems. Patches are available in n8n versions 2.20.0 and 2.19.3 or later.

Affected products

  • n8n n8n < 2.19.3, < 2.20.0

Timeline

  • 2026-05-13: disclosed
  • 2026-05-19: patched

References

Related threats