CVE-2026-25056Patch(n8n / n8n)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files to the n8n server's filesystem potentially leading to remote code execution. This issue has been patched in versions 1.118.0 and 2.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-05); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-02-04: 2Mentions · 2026-02-05: 3Mentions · 2026-03-03: 1Mentions · 2026-06-18: 1Patch / Workaround · 2026-02-05: 3Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 3Technical Details · 2026-03-03: 1Technical Details · 2026-06-18: 102-0402-0503-0306-18
Signal classification3 categories
Patch
342.9%
Disclosure
228.6%
General
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure2
2026-02-053
Patch3
2026-03-031
General1
2026-06-181
General1
Full discourse7 posts
  • The Shadowserver Foundation@Shadowserver
    General

    We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-68613%2B&tag=cve-2025-68668%2B&tag=cve-2026-21858%2B&tag=cve-2026-21877%2B&tag=cve-2026-25053%2B&tag=cve-2026-25056%2B&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on Top affected: US, Germany & France. https://t.co/mEUZ9Is6bf

    Post summary

    The post announces expanded scanning for n8n RCE vulnerabilities, adding CVE‑2026‑27495 with a CVSS score, and provides a dashboard link for tracking results, but does not mention PoC, exploit code, active exploitation, or patches.

    112032154.3K
    21.6K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-25056: n8n Merge Node Arbitrary File Write Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04lRVfR0

    Post summary

    The headline announces CVE-2026-25056, an arbitrary file write vulnerability in n8n's Merge Node, but lacks details on PoC, exploit, or remediation.

    0000036
    31 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-25056 - High n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to crea... https://www.thehackerwire.com/vulnerability/CVE-2026-25056/ https://t.co/9b0eTS3JAJ

    Post summary

    CVE-2026-25056 is a high‑severity SQL query vulnerability in n8n’s Merge node, patched in versions 1.118.0 and 2.4.0.

    0000072
    113 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    n8n Merge Node is vulnerable to Arbitrary File Write, leading to RCE (CVE-2026-25056). Update affected deployments to 1.118.0. #n8n #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-25056-n8n-merge-node-rce

    Post summary

    The post informs that CVE-2026-25056 in n8n Merge Node allows arbitrary file writes leading to RCE, and recommends upgrading to version 1.118.0.

    0000060
    1 followersView on X
  • MR.HOLMES👾@AhammodOvi69
    Patch

    🚨 CRITICAL n8n VULNERABILITY ALERT CVE-2026-25049 (CVSS 9.4) allows authenticated users to execute system commands via malicious workflows, potentially leading to full server compromise. Affected: <1.123.17, <2.5.2 Patch immediately. If you can create a workflow, you can potentially own the server. Thread reply: Additional critical n8n flaws: • CVE-2026-25053 – OS command injection • CVE-2026-25054 – Stored XSS • CVE-2026-25055 – Path traversal • CVE-2026-25056 – Arbitrary file write → RCE Restrict workflow permissions and update ASAP.

    Post summary

    The tweet announces a critical n8n vulnerability (CVE‑2026‑25049) that allows authenticated users to execute system commands, cites a high CVSS score, and urges users to patch or update immediately to mitigate the risk.

    0000097
    345 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25056 Authenticated File Write Vulnerability in n8n Workflow Automation Platform https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25056

    Post summary

    The text refers to a newly disclosed authenticated file‑write vulnerability in n8n, linking to a vulnerability database entry, but offers no further technical details or exploitation information.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25056 n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated user… https://www.cve.org/CVERecord?id=CVE-2026-25056

    Post summary

    The CVE refers to an authentication‑bound SQL vulnerability in n8n’s Merge node that existed prior to specific releases, but no PoC, exploit, or patch details are given in the excerpt.

    00000178
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more