CVE-2026-103251: n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 1.123.80 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.39.6 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.40.1
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The issue affects n8n deployments running in queue mode on versions before 1.123.80, versions from 2.0.0 before 2.39.6, and versions from 2.40.0 before 2.40.1. Exploitation also requires write access to the Redis instance used by the deployment.
What access does an attacker need to exploit it?
An attacker needs Redis write access. They do not need to authenticate to n8n, because the malicious package-install request can be delivered through PubSub.
What is the potential impact in a cluster?
An attacker can bypass package-name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages. The package installation can affect all instances in the n8n cluster.
What versions address the vulnerability?
Upgrade to n8n 1.123.80, 2.39.6, or 2.40.1 or later, as appropriate for the release line in use.