GHSA-xmc9-4f2h-jf9c
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
Quick fix
GHSA-xmc9-4f2h-jf9c — n8n: upgrade to the fixed version with the command below.
npm install n8n@1.123.67Details
## Impact
The n8n Edit Image node passed its output format to the underlying image library without validation, so a crafted value could write bytes to a location outside the node's working directory. An authenticated user able to run workflows could use this to write arbitrary files in the n8n instance.
## Patches
The issue has been fixed in n8n versions 1.123.67, 2.31.5, and 2.32.1. Users should upgrade to one of these versions or later to remediate the vulnerability.
## Workarounds
If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Disable the Edit Image node by adding `n8n-nodes-base.editImage` to the `NODES_EXCLUDE` environment variable.
These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-xmc9-4f2h-jf9c[WEB]
- https://github.com/n8n-io/n8n/commit/f69dfc6dd2178a14ea1624d2e1d403c2e755042f[WEB]
- https://github.com/n8n-io/n8n[PACKAGE]
- https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.67[WEB]
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.31.5[WEB]
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.32.1[WEB]