CVE-2026-54311: CWE-488: Exposure of Data Element to Wrong Session in n8n-io n8n
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox context was cached and reused across all workflow executions on the instance, prototype mutations introduced by one user's workflow persist into subsequent Merge SQL executions belonging to other users or projects. This allowed a low-privileged attacker to intercept workflow data processed by other users on the same instance. This issue only affects multi-user n8n instances where more than one user has permission to create and execute workflows containing the Merge node in SQL Query mode. This vulnerability is fixed in 2.25.7 and 2.26.2.
AI Analysis
Technical Summary
In n8n versions prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows can introduce prototype mutations into the sandbox context used by the Merge node's SQL Query mode. Because this sandbox context is cached and reused across all workflow executions on the instance, these mutations persist and affect subsequent executions by other users or projects. This leads to exposure of workflow data processed by other users on the same instance. The vulnerability is specific to multi-user instances where more than one user can create and execute workflows containing the Merge node in SQL Query mode. The issue is resolved in n8n versions 2.25.7 and 2.26.2.
Potential Impact
A low-privileged authenticated user on a multi-user n8n instance can exploit this vulnerability to intercept workflow data belonging to other users by polluting the shared sandbox context used by the Merge node's SQL Query mode. This results in unauthorized data exposure between sessions. The vulnerability does not affect single-user instances or users without workflow creation and execution permissions involving the Merge node in SQL Query mode.
Mitigation Recommendations
This vulnerability is fixed in n8n versions 2.25.7 and 2.26.2. Users should upgrade to at least one of these versions to remediate the issue. Since the product is not a cloud service, remediation requires applying the official fixes by upgrading the affected software. Patch status is confirmed by the vendor advisory information embedded in the description.
CVE-2026-54311: CWE-488: Exposure of Data Element to Wrong Session in n8n-io n8n
Description
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox context was cached and reused across all workflow executions on the instance, prototype mutations introduced by one user's workflow persist into subsequent Merge SQL executions belonging to other users or projects. This allowed a low-privileged attacker to intercept workflow data processed by other users on the same instance. This issue only affects multi-user n8n instances where more than one user has permission to create and execute workflows containing the Merge node in SQL Query mode. This vulnerability is fixed in 2.25.7 and 2.26.2.
CVSS v4.0
Score 6.0medium
Affected software
pkg:github/n8n-io/n8nRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In n8n versions prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows can introduce prototype mutations into the sandbox context used by the Merge node's SQL Query mode. Because this sandbox context is cached and reused across all workflow executions on the instance, these mutations persist and affect subsequent executions by other users or projects. This leads to exposure of workflow data processed by other users on the same instance. The vulnerability is specific to multi-user instances where more than one user can create and execute workflows containing the Merge node in SQL Query mode. The issue is resolved in n8n versions 2.25.7 and 2.26.2.
Potential Impact
A low-privileged authenticated user on a multi-user n8n instance can exploit this vulnerability to intercept workflow data belonging to other users by polluting the shared sandbox context used by the Merge node's SQL Query mode. This results in unauthorized data exposure between sessions. The vulnerability does not affect single-user instances or users without workflow creation and execution permissions involving the Merge node in SQL Query mode.
Mitigation Recommendations
This vulnerability is fixed in n8n versions 2.25.7 and 2.26.2. Users should upgrade to at least one of these versions to remediate the issue. Since the product is not a cloud service, remediation requires applying the official fixes by upgrading the affected software. Patch status is confirmed by the vendor advisory information embedded in the description.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-12T18:42:02.222Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a3aafb0eed863c81e44dd5d
Added to database: 06/23/2026, 16:09:20 UTC
Last enriched: 06/24/2026, 14:57:21 UTC
Last updated: 08/07/2026, 12:41:12 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.