CVE-2026-103251: n8n-Io n8n
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication.
Affected products
- n8n-Io n8n: before 1.123.80 (fixed in 1.123.80); from 2.0.0, before 2.39.6 (fixed in 2.39.6); from 2.40.0, before 2.40.1 (fixed in 2.40.1)
Published 2026-10-01. Last modified 2026-10-01.