Aller au contenu

Fiche vulnérabilité

CVE-2026-77080 : faille élevée n8n n8n (CVSS 8.8)

Description

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 août 2026
Dernière mise à jour
1 sept. 2026

Produits concernés

  • n8n n8n

Références

Rechercher une autre vulnérabilité dans la base CVE