This is your bi-weekly security update from n8n. The following security advisories have been published since our last update:
- Severity: High | Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint — GHSA-hh89-3r9w-qj3j
- Severity: High | Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution — GHSA-hw8v-xxg5-vvvx
- Severity: High | Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path — GHSA-j535-v25q-vx3q
- Severity: High | Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node — GHSA-34ff-336r-5q23
- Severity: High | Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution — GHSA-6xcw-7xm6-48c6
- Severity: Medium | Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions — GHSA-pf83-w3f9-8m37
- Severity: Medium | Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket — GHSA-35jj-42hp-8gmq
- Severity: Medium | Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check — GHSA-pq6c-vh67-xpm3
- Severity: Medium | Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints — GHSA-cqr2-h44g-v75v
- Severity: Medium | Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter — GHSA-65xw-2v52-jhxc
- Severity: Medium | Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service — GHSA-679f-58pq-4v2c
- Severity: Medium | Git Node branch..remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read — GHSA-qgpw-8g46-w95v
- Severity: Medium | Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers — GHSA-f2cp-m7mv-8jpv
- Severity: Medium | Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content — GHSA-q5wm-mgqx-fv2f
- Severity: Medium | GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open — GHSA-5m98-cgcr-xx3q
- Severity: Medium | Agent Workflow Tool Bypasses Sub-Workflow Caller Policy — GHSA-7hgx-277f-7vmg
- Severity: Medium | Improper Authorization in Source Control Push Allows Cross-Project Workflow and Credential Deletion — GHSA-hvrx-jc5j-pg3w
- Severity: Medium | Git Node File Sandbox Escape via Relative Remote URL Base-Directory Mismatch — GHSA-fm93-2x43-6676
These vulnerabilities have been fixed in the following n8n versions:
- v1 patched in v1.123.76
- beta patched in v2.38.2
- stable patched in v2.37.7
What you need to do
If you are running a cloud version of n8n, your instance is patched automatically, and no action is required.
If you are running a self-hosted n8n instance on a version below the fixed versions listed above, we recommend upgrading at your earliest convenience.
- Upgrade guide: Update n8n | Deploy | n8n Docs
- Full advisory details: Security Advisories · n8n-io/n8n · GitHub
If you are already running the latest patch version for your release branch, no action is needed.
Staying up to date
These updates are part of our regular security communication cadence. If you don’t already, you can also opt in to receive these updates via email here.
Learn more about our security approach: How n8n Handles Vulnerability Disclosure - and Why We Do It This Way – n8n Blog
Best regards,
The n8n Security Team