CRITICAL🇵🇱 Wersja polska

CVE-2026-25052

CVSS 9.4v4.0pub. 2026-02-04upd. 2026-02-05

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host system. This can be exploited to obtain critical configuration data and user credentials, leading to complete account takeover of any user on the instance. This issue has been patched in versions 1.123.18 and 2.5.0.

🤖 AI Analysis
How it works

The vulnerability results from improper access controls to files (CWE-367 — race condition in access verification, and additional irregularities classified as NVD-CWE-Other). An authenticated user with permissions to create or modify workflows can construct an appropriate workflow that reads arbitrary files from the n8n host file system. Through this, the attacker can gain access to sensitive configuration files and stored user credentials of the instance.

Impact

The attacker can read critical configuration data and user credentials, enabling complete takeover of any account on the given n8n instance (account takeover).

Mitigation & patch

Update n8n to version 1.123.18 or newer (1.x branch) or to version 2.5.0 or newer (2.x branch). Details available in the official security advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-gfvg-qv54-r4pc

Who is affected

n8n in versions prior to 1.123.18 (1.x branch) and prior to 2.5.0 (2.x branch)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • N8n

    APP
    N8N
    < 1.123.182.0.0 – 2.5.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-68613CRITICAL9.9⚠ KEVPL ✓same product

RCE w systemie ewaluacji wyrażeń n8n — krytyczna podatność

CVE-2026-44791CRITICAL9.4PL ✓same product

RCE w n8n poprzez ominięcie łatki CVE-2026-42232 w węźle XML

CVE-2026-44789CRITICAL9.4PL ✓same product

n8n: prototype pollution w HTTP Request node prowadzący do RCE

CVE-2026-44790CRITICAL9.4PL ✓same product

Wstrzyknięcie flag CLI w węźle Git platformy n8n — odczyt dowolnych plików

CVE-2026-42231CRITICAL9.4PL ✓same product

Prototype Pollution w n8n prowadzące do RCE przez webhook handler