216.73.217.22

CVE-2026-27496

· Published 25/03/2026 18:16 · Modified 26/03/2026 15:13

Labels: CVE-2026-27496 2026-03-25CVE-2026-27496CWE-908[email protected]

Essential information

Published
25/03/2026 18:16
Modified
26/03/2026 15:13
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory buffers. Uninitialized buffers may contain residual data from the same Node.js process — including data from prior requests, tasks, secrets, or tokens — resulting in information disclosure of sensitive in-process data. Task Runners must be enabled using `N8N_RUNNERS_ENABLED=true`. In external runner mode, the impact is limited to data within the external runner process. The issue has been fixed in n8n versions 1.123.22, 2.10.1 , and 2.9.3. Users should upgrade to this version or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only, and/or use external runner mode (`N8N_RUNNERS_MODE=external`) to isolate the runner process. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
n8n / n8n cpe:2.3:a:n8n:n8n:1.123.22:*:*:*:*:*:*:*
n8n / n8n cpe:2.3:a:n8n:n8n:2.9.3:*:*:*:*:*:*:*
n8n / n8n cpe:2.3:a:n8n:n8n:2.10.1:*:*:*:*:*:*:*

References