Executive brief
n8n is a workflow automation platform that allows users to connect and orchestrate data flows across applications. A vulnerability in n8n's node-schema loader allows authenticated users to bypass path validation and execute arbitrary code on the n8n server by providing malicious file paths. This could allow an attacker to read sensitive data, modify workflows, or take control of the entire n8n instance and connected systems.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in the @n8n/workflow-sdk node-schema loader used for MCP (Model Context Protocol) node-schema loading. The loader constructs a module path directly from an attacker-supplied node type string without validating or sanitizing path-traversal sequences (e.g., "../"). An authenticated user with global:member privileges can exploit this by referencing arbitrary files on the filesystem, leading to remote code execution (RCE) in the n8n main process with full server privileges. The attack is network-accessible and requires only low-privilege authentication; no additional user interaction is needed. The vulnerability has been patched in versions 2.33.4 and 2.34.1 or later.
Affected products
- n8n n8n before 2.33.4 and 2.34.x before 2.34.1
Timeline
- 2026-08-05: disclosed
- 2026-08-20: advisory
- 2026-08-05: patched: Patched in versions 2.33.4 and 2.34.1