VulnCity

n8n Internal Helper Abuse

  • شناسه CVE: CVE-2025-68697
  • شدت: بالا
  • امتیاز CVSS: 8
  • فروشنده/سازنده: n8n
Privilege Escalationn8nFile Read/WriteInternal API
An access control vulnerability in n8n that allows authenticated users to access internal helper functions for arbitrary file read/write operations on the server filesystem.

## Vulnerability Overview
In n8n versions before 2.0.0, the workflow expression context exposes internal helper functions that are intended only for internal use. An authenticated user with workflow edit permissions can invoke these helpers to read and write arbitrary files on the server filesystem.

## Technical Details
- **Type:** Improper Access Control (CWE-284)
- **Root Cause:** The expression evaluation context includes references to internal helper modules (fs operations, environment access) that should not be accessible to user-defined expressions.
- **Exposed Functions:** File read, file write, directory listing, environment variable access

## Impact
- Read sensitive configuration files (/etc/shadow, n8n config, credentials)
- Write files to arbitrary locations (webshells, cron jobs, SSH keys)
- Access environment variables containing API keys and secrets

نرم‌افزارهای تحت تأثیر

  • n8n < 2.0.0