n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the tool to return the names and contents of arbitrary local files readable by the daemon's OS user. Any deployment where an actor can influence the tool's search input is affected.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-pf2q-pxhf-hgmw | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/n8n-before-path-traversal-via-computer-use-search-files | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-11 13:19
Updated : 2026-09-01 20:19
NVD link : CVE-2026-72773
Mitre link : CVE-2026-72773
CVE.ORG link : CVE-2026-72773
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
