CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

n8n security advisory (AV26-836)

unknown
Serial Number: AV26-836 Date: August 20, 2026 As of August 20, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.69 Prior to 2.33.4 Prior to 2.34.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading Snowflake Node Arbitrary File Read and Write via Client-Side Commands n8n Security

CSIRTS triage

What
Remote code execution via path traversal in MCP node-schema loading and arbitrary file read/write in Snowflake node.
Who is affected
n8n workflow automation users on versions before 1.123.69, 2.33.4, and 2.34.1.
Urgency
Critical; RCE and arbitrary file access represent severe compromise risk.
Action
Upgrade n8n to versions 1.123.69, 2.33.4, or 2.34.1 depending on deployment branch.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch n8n

Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/n8n-security-advisory-av26-836

More from Canadian Centre for Cyber Security