{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/n8n-npm/n8n--2.0.0-rc.0--2.31.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (npm/n8n \u003c 1.123.67)","n8n (npm/n8n \u003e= 2.32.0, \u003c 2.32.1)","n8n (npm/n8n \u003e= 2.0.0-rc.0, \u003c 2.31.5)"],"_cs_severities":["high"],"_cs_tags":["arbitrary-file-write","vulnerability","rce","n8n"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eA high-severity format injection vulnerability, identified as GHSA-xmc9-4f2h-jf9c, exists in the n8n automation platform's Edit Image node, affecting versions prior to 1.123.67, 2.32.0 up to 2.32.1, and 2.0.0-rc.0 up to 2.31.5. This vulnerability allows an authenticated user, with the ability to create or execute workflows, to achieve arbitrary file write on the n8n instance. The flaw stems from the Edit Image node passing user-controlled output format parameters directly to the underlying image processing library without proper validation, enabling directory traversal and placement of malicious files in sensitive locations. Successful exploitation can lead to system compromise, including remote code execution or persistence within the n8n environment. Defenders should prioritize patching to the remediated versions immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated attacker, with privileges to create or modify n8n workflows, logs into the vulnerable n8n instance.\u003c/li\u003e\n\u003cli\u003eThe attacker creates a new workflow or modifies an existing one to incorporate the \u0026quot;Edit Image\u0026quot; node.\u003c/li\u003e\n\u003cli\u003eWithin the \u0026quot;Edit Image\u0026quot; node's configuration, the attacker crafts a malicious value for the \u0026quot;Format\u0026quot; parameter, embedding directory traversal sequences (e.g., \u003ccode\u003e../../\u003c/code\u003e) and a controlled file name (e.g., \u003ccode\u003e../../path/to/webshell.php\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eWhen the workflow is executed, the n8n application passes the unvalidated, maliciously crafted format string directly to the underlying image processing library.\u003c/li\u003e\n\u003cli\u003eThe image processing library, acting on the attacker-supplied path, writes the image output data to an arbitrary location on the server's filesystem, escaping the intended working directory.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages this arbitrary file write to place a malicious file, such as a web shell, a modified application configuration file, or a backdoor script, into a sensitive directory accessible by the n8n application or web server.\u003c/li\u003e\n\u003cli\u003eBy subsequently interacting with the written malicious file (e.g., sending an HTTP request to a web shell) or by triggering n8n to load the modified configuration, the attacker achieves remote code execution.\u003c/li\u003e\n\u003cli\u003eThis exploitation grants the attacker persistent access or full control over the compromised n8n instance and potentially the underlying server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability by an authenticated user leads to arbitrary file write capabilities on the n8n instance. This means an attacker can place any file type, including web shells, modified configuration files, or other malicious executables, into sensitive directories on the server. The direct consequence is potential remote code execution, allowing the attacker to fully compromise the n8n application system and gain control over the underlying server. While no specific victim counts are provided, all n8n instances running vulnerable versions are at risk from any authenticated user, regardless of their intended privilege level.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances immediately to patched versions 1.123.67, 2.31.5, or 2.32.1 or later to remediate the vulnerability.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrade is not feasible, restrict n8n instance access to fully trusted users only as a temporary measure.\u003c/li\u003e\n\u003cli\u003eAs a short-term mitigation, disable the Edit Image node by adding \u003ccode\u003en8n-nodes-base.editImage\u003c/code\u003e to the \u003ccode\u003eNODES_EXCLUDE\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T22:15:19Z","date_published":"2026-07-22T22:15:19Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-arbitrary-file-write/","summary":"An authenticated user can exploit a format injection vulnerability in the n8n Edit Image node to write arbitrary files outside the node's working directory within the n8n instance, potentially leading to remote code execution or other significant impact.","title":"n8n Edit Image Node Format Injection Allows Arbitrary File Write","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-arbitrary-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (Npm/N8n \u003e= 2.0.0-Rc.0, \u003c 2.31.5)","version":"https://jsonfeed.org/version/1.1"}