n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host system. This can be exploited to obtain critical configuration data and user credentials, leading to complete account takeover of any user on the instance. This issue has been patched in versions 1.123.18 and 2.5.0.
The vulnerability results from improper access controls to files (CWE-367 — race condition in access verification, and additional irregularities classified as NVD-CWE-Other). An authenticated user with permissions to create or modify workflows can construct an appropriate workflow that reads arbitrary files from the n8n host file system. Through this, the attacker can gain access to sensitive configuration files and stored user credentials of the instance.
The attacker can read critical configuration data and user credentials, enabling complete takeover of any account on the given n8n instance (account takeover).
Update n8n to version 1.123.18 or newer (1.x branch) or to version 2.5.0 or newer (2.x branch). Details available in the official security advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-gfvg-qv54-r4pc
n8n in versions prior to 1.123.18 (1.x branch) and prior to 2.5.0 (2.x branch)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XN8n
APPN8N< 1.123.182.0.0 – 2.5.0 (excl.)
Related vulnerabilities
RCE w systemie ewaluacji wyrażeń n8n — krytyczna podatność
RCE w n8n poprzez ominięcie łatki CVE-2026-42232 w węźle XML
n8n: prototype pollution w HTTP Request node prowadzący do RCE
Wstrzyknięcie flag CLI w węźle Git platformy n8n — odczyt dowolnych plików
Prototype Pollution w n8n prowadzące do RCE przez webhook handler