VDB
Sign up
MEDIUM

GHSA-f2cp-m7mv-8jpv

n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

Quick fix

GHSA-f2cp-m7mv-8jpv — n8n: upgrade to the fixed version with the command below.

npm install n8n@1.123.76

Details

## Impact

The Elasticsearch and ElasticSecurity nodes built REST endpoints by interpolating user-provided identifiers straight into the request path. A value containing path separators or dot segments changed which endpoint the request actually reached, so an operation intended for one document could hit another index or a cluster administration endpoint instead, under the stored Elasticsearch credential. The patch encodes each identifier as a single URL path segment and rejects values that normalise away.

## Patches

The issue has been fixed in n8n versions 1.123.76, 2.37.7, and 2.38.2. Users should upgrade to one of these versions or later to remediate the vulnerability.

## Workarounds

If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Disable the affected nodes by adding `n8n-nodes-base.elasticsearch` and `n8n-nodes-base.elasticSecurity` to the `NODES_EXCLUDE` environment variable if they are not required. - Audit existing workflows that use these nodes and ensure that index and document identifier fields do not accept externally-controlled input.

These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/n8n
Introduced in: 0Fixed in: 1.123.76
Fixnpm install n8n@1.123.76
npm/n8n
Introduced in: 2.38.0Fixed in: 2.38.2
Fixnpm install n8n@2.38.2
npm/n8n
Introduced in: 2.0.0Fixed in: 2.37.7
Fixnpm install n8n@2.37.7

References