PT-2026-6261 · N8N · N8N

Theolelasseux

·

Published

2026-02-04

·

Updated

2026-02-05

·

CVE-2026-25052

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.18 n8n versions prior to 2.5.0
Description n8n is a workflow automation platform. A flaw in the file access controls allows authenticated users with appropriate permissions to read sensitive files from the n8n host system. This could lead to the exposure of critical configuration data and user credentials, potentially resulting in complete account takeover. The issue affects instances where users have the ability to create or modify workflows.
Recommendations Update n8n to version 1.123.18 or later. Update n8n to version 2.5.0 or later.

Exploit

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2026-02167
CVE-2026-25052
GHSA-GFVG-QV54-R4PC

Affected Products

N8N