N8n security advisory (AV26-836)
Brief
Serial Number: AV26-836
Date: August 20, 2026
As of August 20, 2026, n8n is affected by vulnerabilities in the following product:
- n8n
- Prior to 1.123.69
- Prior to 2.33.4
- Prior to 2.34.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading
- Snowflake Node Arbitrary File Read and Write via Client-Side Commands
- n8n Security
n8n security advisory (AV26-836) - Canadian Centre for Cyber Security
