CVE-2026-103254: n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals. Attackers with workflow creation permissions can mint valid approval URLs for gates in projects they cannot access by exploiting unresolved traversal sequences in caller-controlled node IDs, enabling cross-project approval forgery.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 1.123.80 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.39.6 - Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 2.40.1
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs permission to create workflows. The issue enables such users to generate valid approval URLs for Send-and-Wait approval gates in projects they otherwise cannot access.
Are all affected n8n deployments exposed by default?
The vulnerability is in signed resume URL generation for Send-and-Wait approvals. Exposure therefore depends on use of Send-and-Wait approval gates and whether users with workflow creation permissions can supply the relevant node IDs.
What is the impact of successful exploitation?
A successful attacker can forge cross-project approval URLs, allowing approvals for gates in projects outside the attacker's authorized access.
Which releases contain the fix?
The issue is fixed in n8n 1.123.80, 2.39.6, and 2.40.1. Affected releases are versions before 1.123.80, versions from 2.0.0 before 2.39.6, and versions from 2.40.0 before 2.40.1.