n8n security advisory (AV26-836)
Serial Number: AV26-836 Date: August 20, 2026 As of August 20, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.69 Prior to 2.33.4 Prior to 2.34.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading Snowflake Node Arbitrary File Read and Write via Client-Side Commands n8n Security
CSIRTS triage
- What
- Remote code execution via path traversal in MCP node-schema loading and arbitrary file read/write in Snowflake node.
- Who is affected
- n8n workflow automation users on versions before 1.123.69, 2.33.4, and 2.34.1.
- Urgency
- Critical; RCE and arbitrary file access represent severe compromise risk.
- Action
- Upgrade n8n to versions 1.123.69, 2.33.4, or 2.34.1 depending on deployment branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/n8n-security-advisory-av26-836
More from Canadian Centre for Cyber Security
- unknownIvanti security advisory (AV26-897)2026-09-08
- unknownMicrosoft security advisory – September 2026 monthly rollup (AV26-896) – Update 12026-09-08
- unknownAdobe security advisory (AV26-888) – Update 12026-09-08
- unknownN-able security advisory (AV26-885) – Update 12026-09-08
- unknownCommvault security advisory (AV26-895)2026-09-08