n8n security advisory (AV26-836)
Serial Number: AV26-836 Date: August 20, 2026 As of August 20, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.69 Prior to 2.33.4 Prior to 2.34.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading Snowflake Node Arbitrary File Read and Write via Client-Side Commands n8n Security
CSIRTS triage
- What
- Remote code execution via path traversal in MCP node-schema loading and arbitrary file read/write in Snowflake node.
- Who is affected
- n8n workflow automation users on versions before 1.123.69, 2.33.4, and 2.34.1.
- Urgency
- Critical; RCE and arbitrary file access represent severe compromise risk.
- Action
- Upgrade n8n to versions 1.123.69, 2.33.4, or 2.34.1 depending on deployment branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/n8n-security-advisory-av26-836
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24