CVE-2026-77080: n8n

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.

Affected products

  • n8n n8n: before 1.123.69 (fixed in 1.123.69); from 2.0.0, before 2.33.4 (fixed in 2.33.4); version 2.34.0 only

Published 2026-08-20. Last modified 2026-09-01.