Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0118

NIXPKGS-2026-0118
published on 5 Feb 2026
updated 2 weeks, 2 days ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package n8n-nodes-carbonejs
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
n8n Arbitrary File Write on Remote Systems via SSH Node

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating their metadata the vulnerability can lead to files being written to unintended locations on those remote systems potentially leading to remote code execution on those systems. As a prerequisites an unauthenticated attacker needs knowledge of such workflows existing and the endpoints for file uploads need to be unauthenticated. This issue has been patched in versions 1.123.12 and 2.4.0.

Affected products

n8n
  • ==< 1.123.12
  • ==< 2.4.0

Matching in nixpkgs

Package maintainers

Upstream advisory: https://github.com/n8n-io/n8n/security/advisories/GHSA-m82q-59gv-mcr9