Skip to content
n8nGHSA-f2cp-m7mv-8jpv

n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

MediumCVE-2026-86079 · Published Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
n8n
npm
< 1.123.761.123.76
>= 2.38.0, < 2.38.22.38.2
>= 2.0.0, < 2.37.72.37.7
Details and references

## Impact The Elasticsearch and ElasticSecurity nodes built REST endpoints by interpolating user-provided identifiers straight into the request path. A value containing path separators or dot segments changed which endpoint the request actually reached, so an operation intended for one document could hit another index or a cluster administration endpoint instead, under the stored Elasticsearch credential. The patch encodes each identifier as a single URL path segment and rejects values that normalise away. ## Patches The issue has been fixed in n8n versions 1.123.76, 2.37.7, and 2.38.2. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Disable the affected nodes by adding `n8n-nodes-base.elasticsearch` and `n8n-nodes-base.elasticSecurity` to the `NODES_EXCLUDE` environment variable if they are not required. - Audit existing workflows that use these nodes and ensure that index and document identifier fields do not accept externally-controlled input. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2026-86079

More n8n advisories

All n8n
DateAdvisory
Sep 10n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
CVE-2026-86076Highfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
CVE-2026-86075Highfixed in 2.37.7, 2.38.2
Sep 10n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
CVE-2026-86081Highfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
CVE-2026-86082Highfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
CVE-2026-86077Mediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
CVE-2026-86083Highfixed in 1.123.76, 2.37.7, 2.38.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.