Intel

AIKIDO-2024-10327

n8n is vulnerable to Relative path traversal

Relative path traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 10, 2024

90

Critical Risk

This Affects:

jsn8n
1.0.0 - 1.62.3
Fixed in 1.63.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to relative path traversal, allowing access to files outside the source control working directory.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

n8n is vulnerable to Relative path traversal in versions 1.0.0 - 1.62.3.

How to fix this

Upgrade the n8n library to the patch version.