CVE-2026-77068Patch(n8n / n8n)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without validating path-traversal sequences. An authenticated user with global:member privileges can reference malicious files via path traversal, causing code execution in the n8n main process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-20: 3Patch / Workaround · 2026-08-20: 2Technical Details · 2026-08-20: 308-20
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • HOL@HashgraphOnline
    Patch

    CVE-2026-77068: n8n MCP node schema path traversal lets a member-role user write outside the intended dir and reach RCE. Fix: upgrade n8n to 2.33.4 or 2.34.1 (current stable 2.35.5). Not unauth. Not admin-only. https://hol.org/blog/cve-2026-77068-n8n-mcp-node-schema-path-traversal-rce https://t.co/8CBIVyOgte

    Post summary

    The post announces CVE‑2026‑77068 and provides a patch recommendation, describing how path traversal leads to RCE for member-role users.

    2301811.7K
    19.6K followersView on X
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 20 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📤 Unauthenticated file upload in a page-builder form — a PHP file lands in the uploads directory and runs (Elementor Pro CVE-2026-32475) 📦 Outdated self-hosted automation server — code execution in the workflow engine, plus arbitrary file read and write on its host (n8n CVE-2026-77068, CVE-2026-77080) 🔓 Collaborative editor answering its admin API without a key — read, overwrite and delete every document on the server (Etherpad CVE-2026-55089) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    NewNormal Security’s daily CVE report lists several vulnerabilities with technical details but does not provide any PoC, exploit, patch, or active exploitation evidence.

    0001032
    5 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - n8n Patches 10 Vulnerabilities Across Nodes and Core (CVE-2026-77068 / 77070 / 77071 / 77072 / 77075 / 77076 / 77077 / 77079 / 77080 / 77084) n8n has fixed a batch of vulnerabilities in its workflow-automation platform. The most serious allow code execution: a path traversal to RCE in the MCP node-schema loader (77068), a Code node VM sandbox escape via prototype pollution (77077), and code execution via Git node config values (77084). Others include arbitrary file read/write in the Snowflake node (77080), stored XSS in the Form node (77072), expression injection in the resource-locator preview (77075), a GraphQL node credential leak (77076), an authorization bypass via custom-role deletion (77079), and NoSQL/PostgREST injection in the MongoDB and Supabase nodes (77070, 77071). Most require only a low-privileged authenticated account. 👉Upgrade n8n to 1.123.69, 2.33.4, or 2.34.1 depending on your release line.

    Post summary

    The notice informs users of a batch of high‑severity vulnerabilities in n8n and directs them to specific patch versions, with detailed technical descriptions of each flaw.

    0000098
    292 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.34.0node.js-

Explore more