PT-2026-5931 · N8N · N8N

Published

2026-02-04

·

Updated

2026-02-18

·

CVE-2025-61917

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions n8n versions 1.65.0 through 1.114.2
Description n8n is a workflow automation platform. The use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. This could result in information disclosure, as uninitialized buffers might contain residual data from the Node.js process, such as prior requests, tasks, secrets, or tokens.
Recommendations Update to version 1.114.3 or later.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-02183
CVE-2025-61917
GHSA-49MX-FJ45-Q3P6

Affected Products

N8N