Full Report
n8n security advisory (AV26-985)
Analysis Summary
# Vulnerability: Critical Flaws in n8n (AV26-985)
## CVE Details
- **CVE ID:** CVE-2024-47528 (Community Package Bypass), CVE-2024-47530 (Credential Token Leak)
- **CVSS Score:** 8.8 (High) / 7.5 (High)
- **CWE:** CWE-287 (Improper Authentication), CWE-201 (Information Exposure through Sent Data)
## Affected Systems
- **Products:** n8n (Workflow Automation Tool)
- **Versions:**
- Versions prior to 1.123.80
- Versions prior to 2.39.6
- Versions prior to 2.40.1
- **Configurations:** Systems utilizing **Queue Mode** deployments (for CVE-2024-47528) and those using **Dynamic Credentials** (for CVE-2024-47530).
## Vulnerability Description
This advisory covers two primary security flaws:
1. **Community Package Install Validation Bypass:** In Queue Mode deployments, the validation mechanism for community package installations can be bypassed via PubSub. An attacker could potentially trigger the installation of unauthorized packages, leading to remote code execution (RCE) on the worker nodes.
2. **Dynamic Credentials Session Leak:** The authorize endpoint for dynamic credentials improperly handles session tokens. This allows a session token to be leaked to an attacker-controlled resolver when a user interacts with a specially crafted credential configuration.
## Exploitation
- **Status:** PoC Available (Publicly documented in security advisories)
- **Complexity:** Medium
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Session tokens and credential data may be exposed)
- **Integrity:** High (Unauthorized package installation allows for system modification)
- **Availability:** Medium (Potential for service disruption via malicious packages)
## Remediation
### Patches
Update n8n to one of the following patched versions immediately:
- **v1.123.80**
- **v2.39.6**
- **v2.40.1**
### Workarounds
- **For Queue Mode:** Restrict access to the Redis/PubSub infrastructure to trusted internal components only. Disable community package installations if not required for business operations.
- **For Dynamic Credentials:** Avoid interacting with untrusted or third-party dynamic credential templates until the system is patched.
## Detection
- **Indicators of Compromise:**
- Review logs for unauthorized `npm install` commands or community package additions.
- Monitor PubSub traffic for unexpected messages targeting package management functions.
- Check for unusual outbound network connections to unknown resolvers from the n8n instance.
- **Detection methods and tools:** Audit n8n execution logs and inspect the `~/.n8n/nodes` directory for unrecognized community nodes.
## References
- **Vendor Advisories:**
- hxxps[://]github[.]com/n8n-io/n8n/security/advisories/GHSA-fmmv-p585-7c8x
- hxxps[://]github[.]com/n8n-io/n8n/security/advisories/GHSA-rx55-8qhx-4hwx
- **General Security Overview:**
- hxxps[://]github[.]com/n8n-io/n8n/security
- hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/n8n-security-advisory-av26-985