Intel

AIKIDO-2024-10554

n8n-core is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

35

Low Risk

This Affects:

JSn8n-core
1.58.0 - 1.72.1
Fixed in 1.73.0

TL;DR

Affected versions of this package's AI tool process multiple tasks concurrently with an asynchronous function handling that could use the same runIndex for various items. An attacker might be able to manipulate the timing of concurrent tasks to exploit the race condition, leading to misbehaviors, such as outages or data corruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

n8n-core is vulnerable to Race Condition in versions 1.58.0 - 1.72.1.

How to fix this

Upgrade the n8n-core library to the patch version.