CVE-2026-25055Patch(n8n / n8n)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating their metadata the vulnerability can lead to files being written to unintended locations on those remote systems potentially leading to remote code execution on those systems. As a prerequisites an unauthenticated attacker needs knowledge of such workflows existing and the endpoints for file uploads need to be unauthenticated. This issue has been patched in versions 1.123.12 and 2.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-04); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-02-04: 2Mentions · 2026-02-05: 2Patch / Workaround · 2026-02-05: 2Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 102-0402-05
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure1General1
2026-02-052
Patch2
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-25055 n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers vi… https://www.cve.org/CVERecord?id=CVE-2026-25055

    Post summary

    The snippet mentions a CVE for n8n with affected versions but offers no technical, exploit, or remediation details.

    00010183
    56.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-25055 - High n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without va... https://www.thehackerwire.com/vulnerability/CVE-2026-25055/ https://t.co/DKLx70wSUl

    Post summary

    The post announces CVE‑2026‑25055 as a high‑severity flaw in n8n’s SSH node, noting that newer releases fix the issue, but it lacks exploit details or evidence of active exploitation.

    0000083
    113 followersView on X
  • MR.HOLMES👾@AhammodOvi69
    Patch

    🚨 CRITICAL n8n VULNERABILITY ALERT CVE-2026-25049 (CVSS 9.4) allows authenticated users to execute system commands via malicious workflows, potentially leading to full server compromise. Affected: <1.123.17, <2.5.2 Patch immediately. If you can create a workflow, you can potentially own the server. Thread reply: Additional critical n8n flaws: • CVE-2026-25053 – OS command injection • CVE-2026-25054 – Stored XSS • CVE-2026-25055 – Path traversal • CVE-2026-25056 – Arbitrary file write → RCE Restrict workflow permissions and update ASAP.

    Post summary

    The post alerts on critical n8n vulnerabilities (CVE-2026-25049 and related flaws), supplies technical details, and urges immediate patching to prevent potential full server compromise.

    0000097
    345 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25055 n8n Workflow Automation Platform Remote Code Execution via Unvalidated File Transfers https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25055

    Post summary

    A brief announcement of a new RCE vulnerability in the n8n Workflow Automation Platform triggered by unvalidated file transfers.

    0000059
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more