Security Advisory

CVE-2026-77080

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-20 11:21:12
Last updated 2026-08-21 11:21:20
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.