Signal is active with 3 mentions in latest observed window
Immediate actions
Patch n8n n8n systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without validating path-traversal sequences. An authenticated user with global:member privileges can reference malicious files via path traversal, causing code execution in the n8n main process.
CVE-2026-77068: n8n MCP node schema path traversal lets a member-role user write outside the intended dir and reach RCE.
Fix: upgrade n8n to 2.33.4 or 2.34.1 (current stable 2.35.5).
Not unauth. Not admin-only.
https://hol.org/blog/cve-2026-77068-n8n-mcp-node-schema-path-traversal-rce https://t.co/8CBIVyOgte
Post summary
The post announces CVE‑2026‑77068 and provides a patch recommendation, describing how path traversal leads to RCE for member-role users.
NewNormal Security turns the last 24 hours of CVEs into new detections, every day.
𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 20 Aug 2026
𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆:
📤 Unauthenticated file upload in a page-builder form — a PHP file lands in the uploads directory and runs (Elementor Pro CVE-2026-32475)
📦 Outdated self-hosted automation server — code execution in the workflow engine, plus arbitrary file read and write on its host (n8n CVE-2026-77068, CVE-2026-77080)
🔓 Collaborative editor answering its admin API without a key — read, overwrite and delete every document on the server (Etherpad CVE-2026-55089)
Test your stack with NewScan — free, self-hosted:
https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve
#infosec#AppSec#RCE#CSO#REDTEAM
Post summary
NewNormal Security’s daily CVE report lists several vulnerabilities with technical details but does not provide any PoC, exploit, patch, or active exploitation evidence.
🚨High - n8n Patches 10 Vulnerabilities Across Nodes and Core (CVE-2026-77068 / 77070 / 77071 / 77072 / 77075 / 77076 / 77077 / 77079 / 77080 / 77084)
n8n has fixed a batch of vulnerabilities in its workflow-automation platform. The most serious allow code execution: a path traversal to RCE in the MCP node-schema loader (77068), a Code node VM sandbox escape via prototype pollution (77077), and code execution via Git node config values (77084). Others include arbitrary file read/write in the Snowflake node (77080), stored XSS in the Form node (77072), expression injection in the resource-locator preview (77075), a GraphQL node credential leak (77076), an authorization bypass via custom-role deletion (77079), and NoSQL/PostgREST injection in the MongoDB and Supabase nodes (77070, 77071).
Most require only a low-privileged authenticated account.
👉Upgrade n8n to 1.123.69, 2.33.4, or 2.34.1 depending on your release line.
Post summary
The notice informs users of a batch of high‑severity vulnerabilities in n8n and directs them to specific patch versions, with detailed technical descriptions of each flaw.