n8n File Access Vulnerability Allowing Arbitrary File Read by Authenticated Users

Vulnerability

A vulnerability exists in n8n, an open-source workflow automation platform, prior to versions 1.123.18 and 2.5.0. The issue arises from improper file access controls, allowing authenticated users with the ability to create or modify workflows to read sensitive files from the host system. This vulnerability can be exploited to access critical configuration data and user credentials, potentially leading to a complete account takeover of any user on the instance.

Impact

Exploitation of this vulnerability allows for arbitrary file read from the host system, with potential access to sensitive configuration data and user credentials, leading to account takeover.

Remediation

Users should upgrade to n8n version 1.123.18 or 2.5.0. If an immediate upgrade is not possible, consider limiting workflow creation and editing permissions to trusted users and restricting access to nodes that interact with the file system, such as the 'Read/Write Files from Disk' and 'Git' nodes.

Added: Feb 4, 2026, 5:24 PM
Updated: Feb 4, 2026, 5:24 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
5.8
exploitability
4.5
remediation
7.9
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.