<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3an8nn8n/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 15:09:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3an8nn8n/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerability in n8n Allows Remote File Manipulation and Data Disclosure</title><link>https://feed.craftedsignal.io/briefs/2026-08-n8n-vulnerability/</link><pubDate>Fri, 28 Aug 2026 15:09:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-n8n-vulnerability/</guid><description>A vulnerability in n8n allows a remote, unauthenticated attacker to manipulate files and disclose sensitive information on the platform, identified as CVE-2024-51746.</description><content:encoded><![CDATA[<p>The BSI has released an advisory regarding a security vulnerability in n8n, a workflow automation platform. The flaw enables a remote, unauthenticated attacker to perform unauthorized file manipulation and potentially disclose sensitive information from the host environment. This vulnerability, identified as CVE-2024-51746, poses a risk to any organization utilizing n8n instances, particularly those exposed to the internet. Because n8n often integrates with various SaaS applications, databases, and internal services, successful exploitation could provide an attacker with access to highly sensitive credentials, workflow definitions, and data processed by these automations. Defenders should verify their n8n instance versions and ensure they are patched to the latest version to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthorized attacker to interact with the underlying filesystem of the n8n server. This could lead to the exposure of environment variables, API keys, and configuration files, or the overwriting of files to facilitate persistent access or further code execution within the workflow environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of n8n within the enterprise network and verify their version against vendor patches for CVE-2024-51746.</li>
<li>Patch all affected n8n installations to the latest secure version immediately.</li>
<li>Audit logs for unauthorized access or unexpected file system modifications originating from the n8n process.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>